1. Goal
Create an integrity database and use it to detect unexpected changes to critical files.
2. Files and components involved
/etc/aide.conf
/var/lib/aide
/usr/bin/aide
3. Operational flow
aide --init
copy aide.db.new as the active database
schedule aide --check in cron
4. Operational verification
aide --check
ls -lh /var/lib/aide
tail -n 20 /var/log/cron
5. Practical notes
Apply these changes during a maintenance window and keep a backup of the original files for a quick rollback.
Tightening a policy without an alternative access path is the fastest way to lock out legitimate users as well.
Quick checklist
[ ] Backup or copy of the existing configuration completed
[ ] Files and commands updated as expected
[ ] Local test completed successfully
[ ] Logs or final output verified
[ ] Rollback procedure documented