---
title: 'Tripwire HIDS'
url: 'https://mo.homelinux.net/home/tipwire'
markdown: 'https://mo.homelinux.net/home/tipwire.md'
date: '2024-12-15'
description: 'How to Install Tripwire Intrusion Detection System on Debian Tripwi'
taxonomy:
  category:
    - blog
  tag:
    - debian
    - security
  archives_month:
    - dec_2024
  archives_year:
    - '2024'
---

[ Home ](https://mo.homelinux.net/)      Tripwire HIDS    

## [Tripwire HIDS](https://mo.homelinux.net/home/tipwire)

    15th Dec 2024   [debian](https://mo.homelinux.net/tag:debian#body-wrapper) [security](https://mo.homelinux.net/tag:security#body-wrapper)  

How to Install Tripwire Intrusion Detection System on Debian

Tripwire is an Host Intrusion Detection System. Like [AIDE](https://aide.github.io/) it monitors the local filesystem and detects unauthorized changes.

#### Install Tripwire

Install

```
# apt update
# apt install tripwire
```

You are asked to create site and local keys. Select No at both prompts; you will generate the keys manually in the next step.

#### Generate Keys

The policy, database and configuration files are signed with site and local keys.

Generate the local key.

```
# twadmin --generate-keys -L /etc/tripwire/tripwire-local.key
```

Generate the site key.

```
# twadmin --generate-keys -S /etc/tripwire/tripwire-site.key
```

#### Configure Tripwire

Edit the configuration file

Open the config `/etc/tripwire/twcfg.txt` and edit the following lines to include your site and local keys:

```
SITEKEYFILE   =/etc/tripwire/tripwire-site.key
LOCALKEYFILE  =/etc/tripwire/tripwire-local.key
```

Sign the config.

```
# sudo twadmin --create-cfgfile -S /etc/tripwire/tripwire-site.key /etc/tripwire/twcfg.txt 
```

The configuration file is saved to `/etc/tripwire/tw.cfg`.

#### Create a Policy File

The default policy is provided with Tripwire and shoukld be adapted to your needs Sign the policy file with the site key.

```
# sudo twadmin --create-polfile -S /etc/tripwire/tripwire-site.key /etc/tripwire/twpol.txt 
```

The signed policy file is saved to `/etc/tripwire/tw.pol`.

#### Initialize Tripwire

When the policy is changed, generate the database.

```
# sudo tripwire --init
```

Tripwire prompts you to enter the local key's passphrase.

#### Run a Tripwire Check

Run a filesystem check.

```
# sudo tripwire --check -r report.twr 
```

The filesystem report is saved as report.twr in CWD. Plain text version ouput to terminal.

#### Update the Tripwire database to include any filesystem changes.

```
# sudo tripwire --update -a -r report.twr
```

 [ Previous Post](https://mo.homelinux.net/home/rename-user) [Next Post ](https://mo.homelinux.net/home/bash-prompt)

#### Random Article

 [ I'm Feeling Lucky!](https://mo.homelinux.net/random)

#### Popular Tags

#### Archives

- [ 1 June 2006  ](https://mo.homelinux.net/archives_month:jun_2006)
- [ 1 August 2007  ](https://mo.homelinux.net/archives_month:aug_2007)
- [ 1 November 2007  ](https://mo.homelinux.net/archives_month:nov_2007)
- [ 2 February 2008  ](https://mo.homelinux.net/archives_month:feb_2008)
- [ 1 March 2008  ](https://mo.homelinux.net/archives_month:mar_2008)
- [ 1 July 2008  ](https://mo.homelinux.net/archives_month:jul_2008)
- [ 2 August 2008  ](https://mo.homelinux.net/archives_month:aug_2008)
- [ 1 September 2008  ](https://mo.homelinux.net/archives_month:sep_2008)
- [ 1 November 2008  ](https://mo.homelinux.net/archives_month:nov_2008)
- [ 1 February 2009  ](https://mo.homelinux.net/archives_month:feb_2009)
- [ 1 October 2009  ](https://mo.homelinux.net/archives_month:oct_2009)
- [ 1 August 2013  ](https://mo.homelinux.net/archives_month:aug_2013)
- [ 1 November 2014  ](https://mo.homelinux.net/archives_month:nov_2014)
- [ 2 March 2015  ](https://mo.homelinux.net/archives_month:mar_2015)
- [ 1 October 2015  ](https://mo.homelinux.net/archives_month:oct_2015)
- [ 1 December 2015  ](https://mo.homelinux.net/archives_month:dec_2015)
- [ 1 January 2016  ](https://mo.homelinux.net/archives_month:jan_2016)
- [ 1 March 2017  ](https://mo.homelinux.net/archives_month:mar_2017)
- [ 1 August 2017  ](https://mo.homelinux.net/archives_month:aug_2017)
- [ 2 June 2020  ](https://mo.homelinux.net/archives_month:jun_2020)
- [ 1 November 2020  ](https://mo.homelinux.net/archives_month:nov_2020)
- [ 1 December 2020  ](https://mo.homelinux.net/archives_month:dec_2020)
- [ 1 January 2021  ](https://mo.homelinux.net/archives_month:jan_2021)
- [ 1 February 2021  ](https://mo.homelinux.net/archives_month:feb_2021)
- [ 1 March 2021  ](https://mo.homelinux.net/archives_month:mar_2021)
- [ 1 April 2021  ](https://mo.homelinux.net/archives_month:apr_2021)
- [ 1 May 2021  ](https://mo.homelinux.net/archives_month:may_2021)
- [ 1 October 2021  ](https://mo.homelinux.net/archives_month:oct_2021)
- [ 1 February 2022  ](https://mo.homelinux.net/archives_month:feb_2022)
- [ 1 March 2022  ](https://mo.homelinux.net/archives_month:mar_2022)
- [ 1 May 2023  ](https://mo.homelinux.net/archives_month:may_2023)
- [ 1 December 2024  ](https://mo.homelinux.net/archives_month:dec_2024)
- [ 1 March 2025  ](https://mo.homelinux.net/archives_month:mar_2025)
- [ 1 March 2026  ](https://mo.homelinux.net/archives_month:mar_2026)

---

## Navigation

- Parent: [Home](https://mo.homelinux.net/index.md)
- Previous: [Add powerline to your terminal](https://mo.homelinux.net/home/bash-prompt.md)
- Next: [Rename unix user](https://mo.homelinux.net/home/rename-user.md)
