# How to Set Up AIDE for File Integrity Monitoring on Linux

> Set up AIDE for robust file integrity monitoring on Linux. Learn how to create a filesystem baseline and detect unauthorized changes with daily automated checks. Secure your server today.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**AIDE (Advanced Intrusion Detection Environment) creates a cryptographic baseline of your Linux filesystem and alerts you to unauthorized changes through automated daily integrity checks.**

Setting up AIDE for file integrity monitoring is a critical step in securing any Linux server against tampering and intrusion. The *How-To-Secure-A-Linux-Server* repository by imthenachoman provides a concise, production-ready workflow that covers installation through ongoing maintenance. This guide walks through the exact commands and configuration files used to deploy AIDE as a automated monitoring system.

## What Is AIDE and How Does It Work?

AIDE generates a read-only **baseline database** containing cryptographic hashes and metadata for monitored files and directories. According to the repository documentation, AIDE operates on a comparison model: it periodically scans the filesystem and compares current states against the stored baseline, reporting any discrepancies that could indicate unauthorized modifications or malware.

The architecture relies on two core components: the **baseline database** stored under `/var/lib/aide/` and the **rule definitions** that specify which attributes to monitor (permissions, ownership, hashes) and which paths to include or exclude.

## Installation and Initial Backup

Begin by installing the AIDE packages from your distribution's repository. The repository recommends installing both `aide` and `aide-common` on Debian-based systems.

Before modifying any configuration, preserve the original defaults to ensure you can revert if needed:

```bash

# Install AIDE

sudo apt install aide aide-common

# Backup the defaults file with timestamp

sudo cp -p /etc/default/aide \
    /etc/default/aide-COPY-$(date +"%Y%m%d%H%M%S")

# Backup the configuration directory recursively

sudo cp -pr /etc/aide /etc/aide-COPY-$(date +"%Y%m%d%H%M%S")

```

These backups safeguard against configuration errors while you tune the monitoring rules.

## Configuring AIDE for Your Environment

Configuration involves editing two critical locations: the defaults file that controls cron behavior, and the rule files that define what gets monitored.

### Editing /etc/default/aide

The `/etc/default/aide` file controls whether AIDE runs automated daily checks via cron. Open this file and set the following parameter:

```bash
sudo nano /etc/default/aide

```

Change the line to:

```

CRON_DAILY_RUN=yes

```

This enables the daily verification job that compares the live filesystem against your baseline database without manual intervention.

### Customizing Rules in /etc/aide/aide.conf

The primary rule file [`/etc/aide/aide.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/aide/aide.conf) defines which directories AIDE monitors and which attributes it tracks. You can also use modular rule snippets by placing files in `/etc/aide/aide.conf.d/`, which is useful for separating OS-default rules from custom monitoring logic.

Key configuration options include:
- **Monitoring paths**: Specify directories like `/etc`, `/bin`, `/sbin`, and `/usr/bin`
- **Attribute selection**: Track `p` (permissions), `i` (inode), `n` (number of links), `u` (user), `g` (group), `S` (size), `md5`, `sha256`, and other hash algorithms
- **Exclusions**: Remove volatile files (logs, temporary caches) to reduce false positives

## Creating the Baseline Database

After configuration, generate the initial baseline that represents your system's trusted state:

```bash
sudo aideinit

```

This command creates `/var/lib/aide/aide.db.new` containing the cryptographic fingerprints of all monitored files. The repository notes that this database should be treated as a read-only reference; store a copy offline or on read-only media for disaster recovery.

## Running Integrity Checks and Automation

To manually verify system integrity against the baseline, use the wrapper command:

```bash
sudo aide.wrapper --check

```

AIDE outputs a detailed report showing any added, removed, or modified files. When `CRON_DAILY_RUN=yes` is enabled in `/etc/default/aide`, this check executes automatically each day, with results typically logged to `/var/log/aide/`.

For testing purposes, simulate an unauthorized change to verify detection:

```bash

# Create a test file

sudo touch /etc/test.sh

# Run check to see detection

sudo aide.wrapper --check

# Clean up test artifact

sudo rm /etc/test.sh

```

## Maintaining the Database After Legitimate Changes

System updates, package installations, and configuration changes will modify monitored files, causing AIDE to report differences during its next check. After confirming these changes are authorized, update the baseline database to reflect the new trusted state:

```bash
sudo aideinit -y -f

```

The `-y` flag auto-approves prompts, and `-f` forces overwriting the previous database. Alternatively, you can re-run the full initialization process without flags to review changes interactively before committing them to the new baseline.

## Summary

- **AIDE** creates a cryptographic baseline of critical system files and detects unauthorized modifications by comparing current states against stored hashes.
- Install via `sudo apt install aide aide-common` and immediately backup `/etc/default/aide` and `/etc/aide/` before modification.
- Enable automated monitoring by setting `CRON_DAILY_RUN=yes` in `/etc/default/aide`.
- Initialize the baseline with `sudo aideinit`, which stores the database in `/var/lib/aide/`.
- Run manual checks with `sudo aide.wrapper --check` and update the trusted baseline after legitimate system changes using `sudo aideinit -y -f`.

## Frequently Asked Questions

### What is AIDE used for in Linux?

AIDE (Advanced Intrusion Detection Environment) serves as a file integrity monitor that detects unauthorized changes to system binaries, configuration files, and critical directories. It creates a cryptographic snapshot of your filesystem and alerts administrators when attributes like permissions, ownership, or hash values deviate from the established baseline.

### How often should AIDE integrity checks run?

The repository recommends daily automated checks enabled via `CRON_DAILY_RUN=yes` in `/etc/default/aide`. This frequency balances security needs with system performance, ensuring tampering is detected within 24 hours while minimizing resource impact during peak hours.

### Where does AIDE store its baseline database?

AIDE stores its baseline databases in `/var/lib/aide/`, with the active database typically named `aide.db` and new generations created as `aide.db.new` during initialization. These files contain cryptographic hashes and file metadata used for comparison during integrity checks.

### How do you update AIDE after system updates?

After applying legitimate system updates or configuration changes, run `sudo aideinit -y -f` to regenerate the baseline database. This command overwrites the existing database with current file states, preventing false positives on subsequent checks while maintaining protection against future unauthorized modifications.