AIDE: How to Detect Unauthorized File Changes on Your Linux Server
A properly configured firewall and active Fail2ban daemon reduce the probability of someone penetrating your server, but they don't answer the question that matters most after an incident: did anyone alter a system file without my knowledge? That is why File Integrity Monitoring (FIM) exists. Within a comprehensive VPS hardening strategy, it is a crucial layer that is often overlooked due to lack of familiarity rather than complexity.
In this tutorial, we install and configure AIDE (Advanced Intrusion Detection Environment), a lightweight, classic tool that creates a cryptographic snapshot of your filesystem and alerts you the moment anything changes.
1. What problem does AIDE solve?
An attacker who gains access to your server almost always modifies something: replaces a system binary with a trojanized version, adds an SSH key to authorized_keys, inserts a rogue task in cron, or installs a backdoor in a startup script.
AIDE builds a database containing cryptographic hashes (MD5, SHA256...), permissions, ownership, and sizes of the files you specify. Each time it runs, it compares the live state against that baseline database and reports any discrepancy: added, deleted, or modified files.
2. Installation
On Debian/Ubuntu systems:
sudo apt update
sudo apt install aide aide-common
3. Configuring monitored directories
Configuration is located in /etc/aide/aide.conf (and /etc/aide/aide.conf.d/ on Debian/Ubuntu). Each rule specifies a path and inspection depth:
# Strict inspection: permissions, owner, size, and hash
/etc NORMAL
/bin NORMAL
/sbin NORMAL
/usr/bin NORMAL
# Frequently changing directories: monitor existence only
/var/log LOG
It is good practice to explicitly exclude volatile paths that create noise (rotated logs, package caches, /tmp):
!/var/log/journal
!/var/cache/apt
!/tmp
4. Generating the baseline database
This step must be performed immediately after provisioning and securing the server, ensuring the baseline represents a clean system:
sudo aideinit
On some distributions, the command is:
sudo aide --init
sudo mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
5. Running a manual integrity check
To compare the current filesystem state against the baseline database:
sudo aide --check
The output clearly details added, removed, or modified files, along with the altered attributes (permissions, hash, size...).
6. Automating daily checks
AIDE is only valuable if its reports are monitored. Add a scheduled cron job to run daily checks and send an email report:
sudo crontab -e
0 5 * * * /usr/bin/aide --check | mail -s "AIDE Report $(hostname)" you@email.com
After each legitimate server change (system upgrade, new application deployment), regenerate the baseline database using aideinit; otherwise, you will receive daily false positives and start ignoring alerts.
7. The inherent limitation of AIDE
AIDE is only as reliable as its baseline database. If an attacker compromises root and alters /var/lib/aide/aide.db, the check is no longer trustworthy. For maximum security, the database file should be backed up to a read-only or external system after generation.
8. Centralize alerts with SecuryBlack
An email alert from AIDE at 5 AM is easily missed if you manage multiple servers. With SecuryBlack and the FerroSentry agent, file integrity, open ports, and SSH configurations are continuously monitored, and actionable alerts arrive in one centralized place without relying on manually checking every VPS mailbox.