Host-Based Security & Auditing

Strengthen host security with AIDE for file integrity monitoring and auditd for low-level system auditing. Learn to parse system logs to detect brute-force attacks and privilege escalation.

Cybersecurity EngineerCybersecurityHydraKali Linux

Introduction

Host-Based Security & Auditing teaches you to build and interpret evidence from a Linux host. Three guided labs cover AIDE file integrity monitoring, auditd event tracking, and authentication-log analysis; a final challenge combines these controls to investigate simulated insider access and file tampering.

You work in isolated Ubuntu 22.04 virtual machines where sensitive directories, sample logs, and security events are prepared for repeatable analysis. The course emphasizes the trust and scope of a baseline, targeted auditing instead of indiscriminate logging, and evidence-driven conclusions rather than treating every change as an attack.

What You Will Learn

  • Configure AIDE to monitor a defined path and initialize a cryptographic known-good database
  • Activate and protect an integrity baseline, then distinguish added, removed, and changed files in AIDE reports
  • Verify auditd operation and create keyed auditctl watches for file and directory access
  • Use ausearch to connect audit events with paths, commands, executables, login identities, and effective users
  • Filter authentication logs for failed SSH attempts and count potentially suspicious activity
  • Extract sudo commands and build grep, awk, sort, and uniq pipelines for host evidence
  • Combine AIDE reports and audit records to identify a simulated unauthorized reader and modified sensitive file

Who This Course Is For

This course is for SOC learners, Linux administrators, security analysts, and incident responders who want hands-on host telemetry and integrity-monitoring practice. It suits learners who understand basic Linux administration and are ready to investigate system evidence with elevated privileges.

Prerequisites: Basic Linux shell pipelines, files and permissions, sudo, systemd service checks, and familiarity with authentication logs. No prior AIDE or auditd experience is required.

Learning environment: Four independent activities in browser-accessible Ubuntu 22.04 virtual machines: three guided labs and one challenge. AIDE, auditd, sensitive practice paths, sample auth.log/syslog files, and simulated access and tampering events are provided inside the environment.

Frequently Asked Questions

Does AIDE prevent unauthorized changes?

No. AIDE compares current files with a trusted baseline and reports differences; it does not block writes or decide whether a change is malicious. The analyst must validate the baseline and interpret each result.

Are the auditd rules permanent?

The course uses auditctl to apply immediate runtime watches and then searches them by key. It does not teach persistence through /etc/audit/rules.d, so production rule deployment remains outside this course’s scope.

Does the challenge involve a real insider or production server?

No. A verifier triggers simulated access and tampering against /opt/secure_data inside a disposable training VM. You identify the executable from audit evidence and the changed file from an AIDE report.

Do I need to supply system logs or an external log platform?

No. Sample authentication and system logs are staged locally, while auditd produces events inside the VM. The course uses command-line analysis and does not require a SIEM or external account.

Teacher

labby
Labby
Labby is the LabEx teacher.