Building a Linux HIDS from Scratch, Then Testing It Against a Real Exploit
Most host intrusion detection projects stop at "it parses logs." I wanted something that actually caught something - not a toy that prints alerts on synthetic test data, but a tool I could point at a