It has been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and maintenance, although it can also be used as standalone application on a single host.
The official change log:
- For the kernel check, the configure script should now detect if /dev/kmem exists but is dysfunctional. Also, a bug in the samhain_kmem kernel module has been fixed.
- The LogmonMarkSeverity option has been fixed
- Timeserver response is cached now for one second
- The Unix entropy gatherer supports /opt/local/bin now
- A compile time option has been added to disable the expansion of $(shell command) in the configuration file. Also, the signature of a signed configuration file is checked earlier now.
Download SAMHAIN v2.8.5