AIDE Integration with DefectDojo
AIDE Integration with DefectDojo
AIDE (Advanced Intrusion Detection Environment) is an open source file integrity monitor for Linux and other Unix-like systems, developed by the AIDE project on GitHub. It records a baseline database of file attributes such as permissions, ownership, size, timestamps, and checksums. A later aide --check compares the live filesystem against that baseline and writes a plain text report of every path that was added, removed, or changed.
AIDE Integration with DefectDojo
We run AIDE on servers where unexpected change is itself a security signal: hosts that hold regulated data, jump boxes, and build machines. AIDE is good at saying what moved. It says nothing about who owns the change or whether anyone looked at it. Importing the aide --check report into DefectDojo makes each changed path a Finding on the host's Asset, with the old and new attribute values in the description, so someone can triage it, close it as expected, or escalate it, and the decision is recorded.
Why AIDE Matters
File integrity monitoring is one of the few controls that can catch tampering after an attacker is already on a host.
- Changes to system binaries, configuration files, or startup scripts are classic signs of persistence, and AIDE reports them by path.
- It works from a local baseline, so it runs on isolated or air-gapped hosts with no agent calling home.
- Many compliance programs expect file integrity monitoring on sensitive systems, and auditors want evidence that alerts were reviewed.
- Raw AIDE output is a text file per run. Without somewhere to put it, nobody can tell which changes were already reviewed last week.
Advantages of This Integration
- Each change becomes a reviewable Finding. Added, removed, and changed entries each become a Finding with the path in the title and in
file_path. - Full context in one place. The parser joins AIDE's "Changed entries" section with its "Detailed information about changes" section, so each changed file arrives with the attribute mask and the before and after values. Long checksums that AIDE wraps onto continuation lines are rejoined column by column so old and new values stay correct.
- A record of triage. Expected changes can be closed, risk-accepted, or marked false positive with a note, which gives auditors evidence that integrity alerts were reviewed.
- Lifecycle across runs. Reimporting the next report into the same Test mitigates changes that no longer appear (for example after you update the baseline) and adds new ones.
- One host view. Integrity findings sit beside vulnerability and configuration findings for the same Asset.
How This Integration Works
1. Create a baseline and run a check. AIDE needs a database before it can report anything. Database paths depend on your distribution and aide.conf:
aide --init
mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
aide --check > aide.txt
With report_url=stdout in the configuration, the report goes to standard output and can be redirected to a file. AIDE exits non-zero when it finds differences, so a CI or cron step that fails on a non-zero exit will stop before the upload. Handle that exit code explicitly.
2. Import the text report. In the UI, open the Engagement, choose Import Scan Results, select AIDE Scan, and upload aide.txt. To automate it, call the API (Community Edition or DefectDojo Pro):
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=AIDE Scan"
-F "file=@aide.txt"
-F "product_name=db-server-01"
-F "engagement_name=File Integrity"
-F "auto_create_context=true"
DefectDojo Pro users can use Universal Importer from the same job:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "AIDE Scan"
--report-path "./aide.txt"
--product-name "db-server-01"
--engagement-name "File Integrity"
--auto-create-context
3. Reimport on a schedule. Send later reports to /api/v2/reimport-scan/ against the same Test so changes that were folded into a new baseline are mitigated automatically.
A clean report is not empty. It contains a summary block and the database's own checksums, but only the Added, Removed, and Changed sections produce findings, so a clean run imports zero findings.
Because the report also carries a start timestamp and database checksums, two runs are never byte-identical. That doesn't matter to DefectDojo: findings are built only from the entry sections, and matching across runs uses the hashcode fields listed below, not the file as a whole.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in AIDE Report | Notes |
|---|---|---|
| Title | Section and path | Formatted as File added: /path, File removed: /path, or File changed: /path |
| Severity | Fixed at Medium | AIDE assigns no severity; triage by path |
| Description | Change type, path, attribute mask, attribute diffs | Mask kept verbatim; each changed attribute listed with old and new values |
| File Path | The reported path | No line number, since AIDE tracks whole files |
| Finding type | Dynamic | AIDE compares a baseline against a live filesystem |
| Deduplication | Hashcode | Default fields: title, cwe, line, file_path, description |
Use Cases
Change control on production hosts: A nightly cron job runs aide --check and imports the report. The on-call engineer reviews new findings each morning, closes the ones that match an approved change ticket, and escalates anything touching system binaries.
Compliance evidence: For hosts in scope for file integrity monitoring requirements, DefectDojo keeps each integrity alert with its review date, reviewer notes, and closure. An auditor can see that alerts were triaged without anyone collecting old report files.
Incident response: During an investigation, the team filters a host's AIDE findings by path to see which files changed and when the change first appeared in an import, alongside the host's other findings.
Golden image drift: A team baselines a hardened image and runs AIDE on instances built from it. Findings on any instance show drift from the approved build, grouped by Asset.
Operational Tips
- Everything imports at Medium. Use tags or severity edits to raise findings on sensitive paths such as system binary directories, and lower routine paths like temporary or log directories.
- Tune
aide.confto exclude paths that change constantly. A noisy rule set produces noisy findings, and the parser can't judge which changes matter. - After you approve a batch of changes, update the baseline (
aide --update, then move the new database into place) so the next report doesn't repeat them. - Use one Test per host and reimport into it to keep a clean history of what changed and when it was resolved.
- AIDE's non-zero exit on differences is normal. Make sure your automation still uploads the report in that case.
- The attribute mask is kept exactly as AIDE printed it, so you can cross-reference the original report when needed.