Andrew Mercer
on this page

Tripwire is a file integrity monitoring (FIM) tool: it takes a cryptographic snapshot of a defined set of files and directories, then reports anything that changed — added, removed, or modified — on later checks. It is one of the original tools in this space (commercial and open-source editions both exist); AIDE is a common lighter-weight open-source alternative with a similar purpose.

Install

sudo apt-get install tripwire       # Debian/Ubuntu; installer prompts to generate site/local keys interactively
sudo dnf install tripwire           # RHEL family (may need EPEL)

The package installer walks through creating a site key (protects the policy and config files) and a local key (protects the database and reports) with passphrases — write these passphrases down somewhere safe; losing them means rebuilding the whole setup.

Policy and configuration

  • /etc/tripwire/twpol.txt — the policy: which files/directories to watch and which properties matter for each (permissions, size, hashes, timestamps).
  • /etc/tripwire/twcfg.txt — general configuration (database/report locations, mail settings for alerts).

Both plain-text sources are compiled into signed binary files (tw.pol, tw.cfg) so they cannot be silently edited by an attacker:

sudo twadmin --create-polfile -S site.key /etc/tripwire/twpol.txt
sudo twadmin --create-cfgfile -S site.key /etc/tripwire/twcfg.txt

After hand-editing the plain-text policy, recompile it the same way and reinitialize the database (below) so the new rules take effect.

Initialize the baseline database

sudo tripwire --init
# prompts for the local passphrase; produces /var/lib/tripwire/<hostname>.twd

This is the trusted snapshot everything else is compared against. Do this right after installing the OS and hardening it — a baseline taken after a system is already compromised is worthless.

Run a check

sudo tripwire --check                          # full check against the policy, prints a report
sudo tripwire --check --interactive             # lets you accept/reject each change as you go
sudo tripwire --check | mail -s "Tripwire report: $(hostname)" [email protected]

Schedule this via cron, typically nightly, and mail or forward the report somewhere it will actually be read.

Updating the database after a legitimate change

Every real change (a patched binary, an intended config edit) needs to be accepted into the database, or every future check will keep flagging it:

sudo tripwire --update --twrfile /var/lib/tripwire/report/<hostname>-<date>.twr

This opens the report in an editor; leave the checkbox next to entries you want accepted, remove the checkbox (comment out with x in the box) for ones you don't, save, and Tripwire updates the database accordingly.

What it is (and isn't) good for

Tripwire tells you that something under policy changed and roughly what, checked at whatever interval you run it — it is not real-time, and it does not stop the change from happening. Pair it with auditd for real-time, syscall-level tracking of who made a change, and fail2ban or AppArmor for prevention rather than detection.