All integrations

AIDE Integration with DefectDojo

AIDE Integration with DefectDojo

AIDE (Advanced Intrusion Detection Environment) is an open source file integrity monitor for Linux and other Unix-like systems, developed by the AIDE project on GitHub. It records a baseline database of file attributes such as permissions, ownership, size, timestamps, and checksums. A later aide --check compares the live filesystem against that baseline and writes a plain text report of every path that was added, removed, or changed.

AIDE Integration with DefectDojo

We run AIDE on servers where unexpected change is itself a security signal: hosts that hold regulated data, jump boxes, and build machines. AIDE is good at saying what moved. It says nothing about who owns the change or whether anyone looked at it. Importing the aide --check report into DefectDojo makes each changed path a Finding on the host's Asset, with the old and new attribute values in the description, so someone can triage it, close it as expected, or escalate it, and the decision is recorded.

Why AIDE Matters

File integrity monitoring is one of the few controls that can catch tampering after an attacker is already on a host.

  • Changes to system binaries, configuration files, or startup scripts are classic signs of persistence, and AIDE reports them by path.
  • It works from a local baseline, so it runs on isolated or air-gapped hosts with no agent calling home.
  • Many compliance programs expect file integrity monitoring on sensitive systems, and auditors want evidence that alerts were reviewed.
  • Raw AIDE output is a text file per run. Without somewhere to put it, nobody can tell which changes were already reviewed last week.

Advantages of This Integration

  • Each change becomes a reviewable Finding. Added, removed, and changed entries each become a Finding with the path in the title and in file_path.
  • Full context in one place. The parser joins AIDE's "Changed entries" section with its "Detailed information about changes" section, so each changed file arrives with the attribute mask and the before and after values. Long checksums that AIDE wraps onto continuation lines are rejoined column by column so old and new values stay correct.
  • A record of triage. Expected changes can be closed, risk-accepted, or marked false positive with a note, which gives auditors evidence that integrity alerts were reviewed.
  • Lifecycle across runs. Reimporting the next report into the same Test mitigates changes that no longer appear (for example after you update the baseline) and adds new ones.
  • One host view. Integrity findings sit beside vulnerability and configuration findings for the same Asset.

How This Integration Works

1. Create a baseline and run a check. AIDE needs a database before it can report anything. Database paths depend on your distribution and aide.conf:

aide --init
mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
aide --check > aide.txt

With report_url=stdout in the configuration, the report goes to standard output and can be redirected to a file. AIDE exits non-zero when it finds differences, so a CI or cron step that fails on a non-zero exit will stop before the upload. Handle that exit code explicitly.

2. Import the text report. In the UI, open the Engagement, choose Import Scan Results, select AIDE Scan, and upload aide.txt. To automate it, call the API (Community Edition or DefectDojo Pro):

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=AIDE Scan" 
  -F "file=@aide.txt" 
  -F "product_name=db-server-01" 
  -F "engagement_name=File Integrity" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer from the same job:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "AIDE Scan" 
  --report-path "./aide.txt" 
  --product-name "db-server-01" 
  --engagement-name "File Integrity" 
  --auto-create-context

3. Reimport on a schedule. Send later reports to /api/v2/reimport-scan/ against the same Test so changes that were folded into a new baseline are mitigated automatically.

A clean report is not empty. It contains a summary block and the database's own checksums, but only the Added, Removed, and Changed sections produce findings, so a clean run imports zero findings.

Because the report also carries a start timestamp and database checksums, two runs are never byte-identical. That doesn't matter to DefectDojo: findings are built only from the entry sections, and matching across runs uses the hashcode fields listed below, not the file as a whole.

Data Granularity: What Gets Imported

DefectDojo Field Source in AIDE Report Notes
Title Section and path Formatted as File added: /path, File removed: /path, or File changed: /path
Severity Fixed at Medium AIDE assigns no severity; triage by path
Description Change type, path, attribute mask, attribute diffs Mask kept verbatim; each changed attribute listed with old and new values
File Path The reported path No line number, since AIDE tracks whole files
Finding type Dynamic AIDE compares a baseline against a live filesystem
Deduplication Hashcode Default fields: title, cwe, line, file_path, description

Use Cases

Change control on production hosts: A nightly cron job runs aide --check and imports the report. The on-call engineer reviews new findings each morning, closes the ones that match an approved change ticket, and escalates anything touching system binaries.

Compliance evidence: For hosts in scope for file integrity monitoring requirements, DefectDojo keeps each integrity alert with its review date, reviewer notes, and closure. An auditor can see that alerts were triaged without anyone collecting old report files.

Incident response: During an investigation, the team filters a host's AIDE findings by path to see which files changed and when the change first appeared in an import, alongside the host's other findings.

Golden image drift: A team baselines a hardened image and runs AIDE on instances built from it. Findings on any instance show drift from the approved build, grouped by Asset.

Operational Tips

  • Everything imports at Medium. Use tags or severity edits to raise findings on sensitive paths such as system binary directories, and lower routine paths like temporary or log directories.
  • Tune aide.conf to exclude paths that change constantly. A noisy rule set produces noisy findings, and the parser can't judge which changes matter.
  • After you approve a batch of changes, update the baseline (aide --update, then move the new database into place) so the next report doesn't repeat them.
  • Use one Test per host and reimport into it to keep a clean history of what changed and when it was resolved.
  • AIDE's non-zero exit on differences is normal. Make sure your automation still uploads the report in that case.
  • The attribute mask is kept exactly as AIDE printed it, so you can cross-reference the original report when needed.