<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Debian &#8211; wiki</title>
	<atom:link href="https://wiki.benoitvandevoorde.be/tag/debian/feed/" rel="self" type="application/rss+xml" />
	<link>https://wiki.benoitvandevoorde.be</link>
	<description>For things you forget</description>
	<lastBuildDate>Tue, 24 Mar 2026 12:56:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>aide-monitor: Context-Aware Integrity Monitoring for Debian Systems</title>
		<link>https://wiki.benoitvandevoorde.be/aide-monitor-context-aware-integrity-monitoring/</link>
		
		<dc:creator><![CDATA[ebola]]></dc:creator>
		<pubDate>Tue, 24 Mar 2026 11:44:24 +0000</pubDate>
				<category><![CDATA[Config]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AIDE]]></category>
		<category><![CDATA[Debian]]></category>
		<guid isPermaLink="false">https://example.com/?p=1</guid>

					<description><![CDATA[Lightweight, context-aware integrity monitoring for Debian systems, built on top of AIDE.]]></description>
										<content:encoded><![CDATA[
<div style="padding:40px 24px;border-radius:18px;background:linear-gradient(135deg,#0f172a,#1e293b);color:#e2e8f0;text-align:center;box-shadow:0 12px 32px rgba(0,0,0,0.24);margin-bottom:36px;">
  <h1 style="font-size:2.5em;margin:0 0 10px;color:#ffffff">aide-monitor</h1>
  <p style="font-size:1.15em;opacity:0.92;margin:0 0 18px;">Context-aware integrity monitoring for Debian systems, built on top of AIDE.</p>
  <div style="margin:18px 0 14px;">
    <span style="background:#111827;padding:7px 14px;border-radius:999px;margin:4px;display:inline-block;">AIDE</span>
    <span style="background:#111827;padding:7px 14px;border-radius:999px;margin:4px;display:inline-block;">Debian 13</span>
    <span style="background:#111827;padding:7px 14px;border-radius:999px;margin:4px;display:inline-block;">systemd</span>
    <span style="background:#111827;padding:7px 14px;border-radius:999px;margin:4px;display:inline-block;">Pi-hole</span>
    <span style="background:#111827;padding:7px 14px;border-radius:999px;margin:4px;display:inline-block;">Privoxy</span>
  </div>
  <p style="margin:10px 0 0;font-style:italic;opacity:0.84;">Only alert when something actually matters.</p>
</div>



<h2 class="wp-block-heading">Why aide-monitor?</h2>



<p>AIDE is powerful, but on a living Debian system it quickly becomes noisy. Normal package upgrades, expected runtime state, and recurring operational churn can drown out the one change you actually care about. <strong>aide-monitor</strong> solves that by adding context, package verification, and a lightweight learning layer on top of AIDE.</p>



<div style="padding:16px 18px;border-left:4px solid #3b82f6;background:#f8fafc;margin:24px 0;">
  💡 <strong>Key idea:</strong> AIDE continues to detect filesystem changes, while aide-monitor decides which of those changes are normal, noteworthy, or genuinely suspicious.
</div>



<h2 class="wp-block-heading">Core features</h2>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<div style="padding:20px;border-radius:14px;background:#f8fafc;height:100%;">
      <h3>📦 Apt-aware</h3>
      <p>Correlates file changes with recent package activity so normal upgrades do not become false alarms.</p>
    </div>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<div style="padding:20px;border-radius:14px;background:#f8fafc;height:100%;">
      <h3>🔍 Package verification</h3>
      <p>Uses package ownership and verification checks to distinguish trusted package-managed changes from unexpected drift.</p>
    </div>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<div style="padding:20px;border-radius:14px;background:#f8fafc;height:100%;">
      <h3>🧠 Learning mode</h3>
      <p>Suppresses recurring low-risk churn over the first days, so the system becomes quieter and more useful over time.</p>
    </div>
</div>
</div>



<h2 class="wp-block-heading">How it works</h2>



<p>The diagram below shows the full flow from raw AIDE detection to filtered operator alerts. Upload the included architecture image to your Media Library and replace this placeholder with the uploaded image if you want the visual embedded in the post.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="658" src="https://wiki.benoitvandevoorde.be/wp-content/uploads/2026/03/aide-monitor-architecture-premium-v2-1024x658.png" alt="" class="wp-image-576" srcset="https://wiki.benoitvandevoorde.be/wp-content/uploads/2026/03/aide-monitor-architecture-premium-v2-1024x658.png 1024w, https://wiki.benoitvandevoorde.be/wp-content/uploads/2026/03/aide-monitor-architecture-premium-v2-300x193.png 300w, https://wiki.benoitvandevoorde.be/wp-content/uploads/2026/03/aide-monitor-architecture-premium-v2-768x494.png 768w, https://wiki.benoitvandevoorde.be/wp-content/uploads/2026/03/aide-monitor-architecture-premium-v2.png 1400w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Quick start</h2>



<div style="margin:28px 0;padding:24px;border-radius:14px;background:#f8fafc;">
  <pre style="background:#111827;color:#e5e7eb;padding:18px;border-radius:10px;overflow:auto;">chmod +x install-aide-monitor.sh
sudo ./install-aide-monitor.sh --dry-run
sudo ./install-aide-monitor.sh</pre>
  <p style="margin:12px 0 0;">Once installed, the system runs automatically through a systemd timer.</p>
</div>



<h2 class="wp-block-heading">Operational model</h2>



<p>In normal operation, there is very little to do. The system stores full reports, writes a concise summary, and only emits alerts when a change cannot be confidently explained. That means most days you do not read AIDE output at all.</p>



<div style="padding:16px 18px;border-left:4px solid #ef4444;background:#fef2f2;margin:24px 0;">
  ⚠️ <strong>Always pay attention</strong> to unexpected changes in <code>/etc</code>, boot files, cron, systemd units, and local scripts under <code>/usr/local</code>.
</div>



<h3 class="wp-block-heading">Typical workflow</h3>



<ul class="wp-block-list">
<li>Check the timer: <code>systemctl status aide-monitor.timer</code></li>



<li>View recent alerts: <code>journalctl -t aide-alert -n 20</code></li>



<li>Inspect the latest summary: <code>less /var/log/aide/latest.summary</code></li>



<li>Refresh the baseline after intentional local changes: <code>sudo /usr/local/sbin/aide-monitor-refresh</code></li>
</ul>



<h2 class="wp-block-heading">Design philosophy</h2>



<p><strong>aide-monitor</strong> deliberately stays lightweight. There are no agents, no dashboards, and no external infrastructure. Instead, it combines AIDE, systemd, apt/dpkg metadata, and package verification into a small, auditable system that fits naturally on a Debian Raspberry Pi.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Keep it simple.<br>Keep it observable.<br>Only alert on what matters.</p>
</blockquote>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
