AIDE — file integrity

Changed files
1
Changes detected
Added files
0
Database: Initialized
Removed files
0
Last check: 11.10.2026 04:02
Database
Initialized
11.10.2026 04:02
Check results 1
TypeCheck results
changed /etc/aide/aide.conf

File integrity monitoring you can actually read

AIDE takes a cryptographic snapshot of your filesystem and tells you what has changed since. It is the tool that answers the question every other tool dodges after an incident: what did they touch? This page shows the last check as three lists — files added, files changed, files removed — with the attributes that differ.

Two things decide whether AIDE is worth anything on your server. The first is where the database lives: if it sits on the same filesystem it is checking, anyone with root can update it after making changes and the report will be clean. Keep a copy somewhere the server cannot write to. The second is discipline about the baseline. After every legitimate package upgrade the database must be re-initialised, or the next report drowns in expected changes and stops being read.

The noisy directories on a normal server are /var/log, /var/lib and anything under /tmp. Excluding them from the check is not cheating — it is what makes the remaining output short enough to actually look at.

The commonest AIDE report of all comes from exactly this: unattended-upgrades ran overnight, dozens of binaries changed hash, and the list of modifications reads like a break-in when it is a scheduled update. The drill is simple — compare the time of the report with the time of the upgrade and, if they line up, rebuild the baseline. When the question is no longer what changed but who changed it, auditd answers: AIDE records the result, the audit log records the hand.