Tripwire for Servers
Tripwire for Servers — configuration control for servers and desktops
Tripwire® for Servers lets organizations regain configuration control of servers and desktop machines by alerting IT to improper change to key system files, directories and registries. Organizations first manually configure each monitored server and desktop the way they want, and then Tripwire for Servers agents detect any changes from that desired configuration. For many public, private and governmental organizations, Tripwire for Servers is a must for achieving compliance with important regulations or standards like the Federal Desktop Core Computing (FDCC) and ensuring the sensitive data that resides on agency desktops and servers is secure.
Upgrade to Tripwire Enterprise
Upgrading a Tripwire for Servers implementation to Tripwire Enterprise adds more intelligence and automation to your solution.
Request an EvaluationTripwire for Servers
Improper Change Detection
Detects improper change, including additions to, deletions from and modifications of file systems. It also determines what changed and where and when the change was made. In addition, it helps support change management processes, audits and data forensics by identifying the source of improper change through correlating event logs to Tripwire integrity reports.
Identifies Source of Improper Change by correlating event logs to Tripwire integrity reports, helping support change management processes, audits and data forensics.
Easy Management of Change Monitoring Policies
Simplifies and eases management of change monitoring policies with an intuitive interface that allows rapid set-up and "noise" reduction from non-critical alerts. It also lets users easily add, delete, or modify policies.
Improper Change Alerts
Alerts to improper change when and where needed with alerts sent in multiple ways–email, syslog, SNMP traps, XML and HTML output to the Tripwire Manager console–to ensure IT receives them.
Appropriate Detail Level of Information
Provides just the right level of information with high-level views that provide management with a picture of overall health and drill down to details that help technical staff remediate issues.
Automated Rollback
Supports automated rollback by triggering custom command line scripts that automatically restore files to the last known good state. Support for command line scripts can also extend reporting and notification capabilities.
Broad Platform Support
Offers broad platform support, monitoring machines–even virtual machines–running Windows, Linux, Solaris, HP-UX, and AIX. And when used with Tripwire Manager, Tripwire for Servers provides a single point of control to manage change to servers and desktops across the enterprise.
Tripwire Manager
Tripwire Manager centralizes management and reporting for multiple Tripwire for Servers installations on a variety of platforms–all without requiring a persistent connection.
Tripwire for Servers
Windows
Versions
- Windows NT 4.0 SP6a*
- Windows 2000 Professional, Server and Advanced Server (Service Packs 3 and 4)
- Windows Server 2003 (up to Service Pack 2) (x86 and x64)
- Windows Server 2008 R1 Service Pack 2 (x86 and x64) and R2 (x64)
- Windows XP Professional (up to Service Pack 2)
- Windows Vista Business, Ultimate and Enterprise Editions (with no Service Packs)
*Supported through an earlier version of Tripwire For Servers, contact support for information.
Recommended
- Pentium-class processor
- Intel Xeon and AMD Opteron (for x64 Edition)
- 128 MB RAM
- 12 MB disk space
Solaris
Versions
- Solaris (SPARC) 2.6*, 7, 8, 9 & 10
*Supported through an earlier version of Tripwire For Servers, contact support for information.
Recommended
- SPARC 2-class processor or above
- Sun recommended current patch level for all versions
- 128 MB RAM
- 56 MB disk space
Solaris on x64/x86
Versions
- Solaris 10 on x64/x86
Recommended
- Pentium class processor or above
- 150 MB RAM
- 33 MB disk space
IBM AIX
Versions
- AIX 4.3.3*, 5.1*, 5.2 & 5.3
*Supported through an earlier version of Tripwire For Servers, contact support for information.
Recommended
- RS/6000 class processor or above
- 128 MB RAM
- 56 MB hard disk space
Linux
Versions
- Red Hat Enterprise Linux 3, & 4 AS, ES & WS & 5 Server and Workstation
- Red Hat 7.1*, 7.2*, 7.3*, 8.0* & 9.0*
- SUSE 8.0*, 8.1* (on x86)
- SUSE EL 9 (on x86_64 and ia64)
- Fedora Core 2*
- Debian 2.2*
- Mandrake 8.2*
- Slackware 8.0*
*Supported through an earlier version of TFS, contact support for information.
Recommended
- Pentium-class processor or above
- Intel Xeon and AMD Opteron (RHEL 3, 4 & 5, SUSE EL 9)
- Intel Itanium (for Red Hat Enterprise Linux and SUSE EL 9)
- Linux (x86) kernel 2.4 or higher
- glibc 2.3 and higher
- 128 MB RAM
- 25 MB disk space (Itanium II processor - 41 MB disk space)
FreeBSD
Versions
- (x86) 4.5*, 4.6*, 4.7*, 4.10* & 5.3
*Supported through an earlier version of TFS, contact support for information.
Recommended
- Pentium-class processor or above
- 128 MB RAM
- 21 MB disk space
HP-UX
Versions
- HP-UX 10.2*, 11, 11i v1 & 11i v2 (PA-RISC)
*Supported through an earlier version of TFS, contact support for information.
Recommended
- PA-RISC 1.1 processor or higher
- 128 MB RAM
- 67 MB hard disk space
HP-UX 11i v2 (Itanium)
Versions
- 11i v2
*Supported through an earlier version of TFS, contact support for information.
Recommended
- Intel Itanium
- 128 MB RAM
- 82 MB hard disk space
Compaq Tru64 UNIX
Versions
- Tru64 UNIX 4.0F*, 4.0G*, 5.0A*, 5.1*, 5.1A* & 5.1B (Alpha)
*Supported through an earlier version of TFS, contact support for information.
Recommended
- Alpha processor
- 128 MB RAM
- 49 MB disk space
Tripwire Manager
Windows
Versions
- 2000 SP3 or SP4
- 2003 up to SP2
- Windows Vista
- XP Pro up to SP2
Recommended
- Pentium IV class processor or above
- 1024 MB RAM
- 75 MB disk space (150 MB for installation)
Solaris
Versions
- Solaris (SPARC) 7, 8, 9 & 10
Recommended
- Sun UltraSPARC II or higher processor
- 1024 MB RAM
- 86 MB disk space (229 MB for installation)
- X Window System
Linux
Versions
- Red Hat Enterprise Linux 3 & 4 AS, ES & WS (on x86) & 5 Server and Workstation (on x86)
Recommended
- Pentium IV class processor or above
- 1024 MB RAM
- 85 MB disk space (167 MB for installation)
- X Window System
What is Tripwire for Servers?
Tripwire for Servers is configuration control software that provides IT system administrators the ability to report on in-depth file system and registry changes on Windows, UNIX and Linux systems. This provides improved visibility of both authorized and unauthorized changes, and greater accountability for those changes, which ultimately results in increased server availability and enhanced security. It also ensures compliance with policies and change and IT configuration management processes.
What does Tripwire for Servers do?
Tripwire for Servers monitors all file and registry changes–whether they originate inside or outside of your organization or are accidental or malicious in nature. It identifies configuration changes to system attributes including hash values, file size, access flags, access time, write time, ACLs, inode number, security descriptors and more, and displays them in easy-to-read reports. Tripwire for Servers can receive commands from Tripwire Manager regarding system functions and reports back accordingly.
What is Tripwire Manager?
Tripwire Manager is a fully functional, cross-platform management console that allows system and security professionals to easily manage all installations of Tripwire for Servers software across an enterprise network. Tripwire Manager eliminates the need to manually monitor multiple discrete installations of Tripwire for Servers. Instead, IT professionals have a comprehensive view of configuration change information from a single, centralized console. Tripwire Manager also enables you to view and analyze reports from installations of Tripwire for Servers.
Do I need Tripwire Manager to operate Tripwire for Servers?
No, you can operate individual Tripwire for Servers installation as a standalone application. However, managing any more than five Tripwire for Servers installations without Tripwire Manager is generally found to be inefficient and time consuming.
How many machines can Tripwire Manager control?
Tripwire Manager allows you to manage the functions of Tripwire for Servers on up to 2,500 machines. Depending upon your system, Tripwire Manager may be able to manage many more.
Can Tripwire Manager alert me when an agent goes down?
Yes, Tripwire Manager displays an obvious graphical cue when a system is unavailable. The status information displayed for the affected system will explain whether the host system is unreachable or the Tripwire service is down. In addition, the 'Email no violations' function on critical servers may be used for alerting; if you stop receiving the 'No violations' email from targeted critical servers, either Tripwire has been disabled or the server is down.
Can I use Tripwire Manager to compare one server’s file system to other servers?
Yes, using Tripwire Manager you can replicate one server's integrity system (including the baseline snapshot) and deploy this to the other servers that you need to compare against. This is very useful in eliminating configuration drift, ensuring that all the production servers match policy.
How does Tripwire for Servers work?
Tripwire for Servers works by creating a baseline snapshot (database) of a server's file system in a known and trusted state. It then takes subsequent snapshots and compares the differences, if any, and reports any changes to files, file attributes and the Windows Registry.
Is the Tripwire snapshot secured?
Yes, the snapshot is cryptographically signed with a 1024-bit cryptography algorithm that detects any unauthorized tampering. A user can also sign the report, policy and configuration file for each Tripwire for Servers installation. The default policy file also monitors the Tripwire binary files, essentially using Tripwire to monitor Tripwire.
Can reports be exported?
Yes, reports can be exported from Tripwire for Servers in an XML or HTML format. This is helpful if the user wants to view reports from a Web browser. Reports can also be sent to the syslog/event logs.
Can wildcards be used in the policy file?
Yes, wildcards can be used in the policy file to make developing policy files easier. For example, if a user wants to scan all dll files in a certain folder or directory, they would be able to use *.dll. A user can use wildcards for both inclusion and exclusion (for example, monitor all files of a certain type or do not monitor any files of a certain type).
How does Tripwire for Servers track "who made the change?"
Tripwire for Servers tracks the identity of who made the change by correlating the information from the operating system's event and audit log with the change information that is detected by Tripwire for Servers. It uses this information to provide the identity of who made a certain change. Since we rely on the operating system to gather this information, the product only captures the "who" information from the operating systems that track this. Linux and FreeBSD do not track this information. This feature is called Event Log Correlation.
Does event tracking correlation require auditing to be turned on to determine "who" made a change?
Yes, auditing does have to be turned on for each directory or object for which a user would like this information.
What is Integrated Command Execution (ICE)?
ICE is a feature that can be used to execute a command when a change violation is identified. This can be configured for each file being monitored or entire directories on a server.
Can the Integrated Command Execution function be used to automatically back up files that are changed?
A user could develop a script to be automatically executed using the ICE function that would go to a user's back up system and replace the specific files that were violated. This function is specified for each rule within the policy file.
What if I delete Tripwire for Servers keys, and then replace policy, config and database files with my own signed versions that tell Tripwire software to check nothing?
Each Tripwire for Servers report details when the database was last updated, providing a quick benchmark detailing if or when the data files have been replaced. In order to replace these files, an attacker requires root or administrator level privileges and must know where Tripwire for Servers has been installed. On a properly secured system, gaining this level of access takes time and leaves physical evidence behind for Tripwire for Servers to detect prior to the system being compromised. Methods for reducing the risk of an intruder being able to replace a Tripwire for Servers installation include:
- Hiding the application by renaming configuration, data, and binary files and installing to a hidden location.
- Installing Tripwire for Servers to a read-only partition such as a CD-ROM.
Can I specify who receives an email based on different change violations?
Tripwire for Servers permits users to designate different email addresses within the policy file. For example, the Webmaster should receive an email if the configuration settings on the Web site have been altered, but the IT staff should be alerted if a new user account has been added.
Resources
To browse more white papers, visit the resource library.
To browse more videos, visit the resource library.
Resource Library
Read, watch or listen to valuable information about Tripwire solutions, customer success stories, IT security and compliance best practices, and more.






