# Devuan Security Automation Bundle

This document summarizes the security approach and the scripts created in this folder for a Devuan (SysV init, cron-based scheduling) server.

## Scope

This bundle provides:
- Weekly AIDE integrity checks with robust logging and clear exit codes.
- Monthly Lynis hardening audits with timestamped report archives.
- Cron wrapper files for `/etc/cron.weekly` and `/etc/cron.monthly`.
- Malware scanner package guidance for Lynis compliance and host visibility.

Assumptions:
- The server already has a working MTA or cron mail delivery path.
- Scripts run as root (standard for system cron directories).
- AIDE is initialized (`aideinit`) and has a valid baseline database.
- Scripts are deployed to `/opt/sysadmin_scripts/security/` and cron wrappers call that path.

## Why Both Tools

AIDE and Lynis address different risks:
- AIDE detects unauthorized or unexpected file changes against a trusted baseline.
- Lynis evaluates hardening posture and operational security configuration.

Recommended cadence in this bundle:
- AIDE: weekly (in `/etc/cron.weekly`).
- Malware scan (`rkhunter`/`chkrootkit`): weekly (in `/etc/cron.weekly`).
- Lynis: monthly (in `/etc/cron.monthly`).

## Files Created

- `bin/security_aide_check.sh`: Main production script for AIDE checks.
- `bin/security_malware_scan.sh`: Weekly malware scan script for `rkhunter` and `chkrootkit`.
- `bin/security_lynis_audit.sh`: Main production script for Lynis audits.
- `cron.weekly/aide-check`: Weekly cron wrapper to run the AIDE script.
- `cron.weekly/malware-scan`: Weekly cron wrapper to run the malware scan script.
- `cron.monthly/lynis-audit`: Monthly cron wrapper to run the Lynis script.

## Operational Behavior

### AIDE Script (`bin/security_aide_check.sh`)

- Uses a lock file to prevent overlapping runs.
- Verifies root execution and required binaries.
- Auto-detects AIDE config at `/etc/aide/aide.conf` or `/etc/aide.conf` and passes it explicitly.
- Logs all output to `/var/log/security/aide-check-YYYYmmdd-HHMMSS.log`.
- Prunes old logs (default retention: 120 days).
- Exit code handling:
  - `0`: no changes detected.
  - `1`: changes detected (intentional warning state for review).
  - `>=2`: execution/configuration error.

### Lynis Script (`bin/security_lynis_audit.sh`)

- Uses a lock file to prevent overlapping runs.
- Verifies root execution and required binaries.
- Runs `lynis audit system --quick --no-colors`.
- Stores run log at `/var/log/security/lynis/lynis-audit-YYYYmmdd-HHMMSS.log`.
- Archives Lynis report data from `/var/log/lynis-report.dat` into timestamped files.
- Prints a concise summary (hardening index, warning count, suggestion count).
- Prints top warning and suggestion entries (up to 10 each) after the summary.
- Prints scanner presence status for `rkhunter`, `chkrootkit`, and `clamscan`.
- Prunes old logs/reports (default retention: 365 days).

### Malware Scan Script (`bin/security_malware_scan.sh`)

- Uses a lock file to prevent overlapping runs.
- Verifies root execution and required runtime binaries.
- Runs `rkhunter` and `chkrootkit` when installed, and skips missing tools safely.
- Prints concise scanner summaries to stdout/email and stores full scanner output in the timestamped log file.
- Stores run logs at `/var/log/security/malware/malware-scan-YYYYmmdd-HHMMSS.log`.
- Prunes old scan logs (default retention: 120 days).

## Deployment

1. Install dependencies:

```bash
apt update
apt install aide lynis debsums
```

Optional but recommended for Lynis malware-scanner checks:

```bash
apt install rkhunter chkrootkit
```

Optional for file-upload, mail, or shared-content workloads:

```bash
apt install clamav clamav-daemon
freshclam
```

2. Verify package integrity before creating the initial AIDE baseline:

```bash
debsums -as
dpkg -V
```

3. Initialize AIDE once (first-time setup):

```bash
aideinit
cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db
```

4. Install scripts and wrappers:

```bash
install -d -o root -g root -m 0755 /opt/sysadmin_scripts/security/bin
install -o root -g root -m 0750 bin/security_aide_check.sh /opt/sysadmin_scripts/security/bin/security_aide_check.sh
install -o root -g root -m 0750 bin/security_malware_scan.sh /opt/sysadmin_scripts/security/bin/security_malware_scan.sh
install -o root -g root -m 0750 bin/security_lynis_audit.sh /opt/sysadmin_scripts/security/bin/security_lynis_audit.sh
install -o root -g root -m 0755 cron.weekly/aide-check /etc/cron.weekly/aide-check
install -o root -g root -m 0755 cron.weekly/malware-scan /etc/cron.weekly/malware-scan
install -o root -g root -m 0755 cron.monthly/lynis-audit /etc/cron.monthly/lynis-audit
```

5. Validate by manual runs:

```bash
/opt/sysadmin_scripts/security/bin/security_aide_check.sh
/opt/sysadmin_scripts/security/bin/security_malware_scan.sh
/opt/sysadmin_scripts/security/bin/security_lynis_audit.sh
```

6. Confirm cron execution and mail delivery after first scheduled run.

## Forcing AIDE Reinitialization (After Integrity Verification)

Use this when you intentionally want to rebuild the baseline after trusted maintenance and post-check verification:

```bash
debsums -as
dpkg -V
aideinit
cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db
```

Optional hard reset if stale temporary DB files are present:

```bash
rm -f /var/lib/aide/aide.db.new /var/lib/aide/aide.db.new.gz
aideinit
cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db
```

Notes:
- Only reinitialize after reviewing changes and confirming they are legitimate.
- Reinitialization makes the current trusted state the new reference, so do not run it on an untrusted host state.

## AIDE Noise Tuning (Dynamic Paths)

It is normal for AIDE to report constant changes under high-churn paths like `/run`, `/var/log`, and `/var/lib/mysql` unless you tune exclusions.

This repository includes a local tuning template:

- `config/aide/99-local-ignore-dynamic.conf`

Recommended host workflow:

1. Copy the template into AIDE's include directory:

```bash
cp /opt/sysadmin_scripts/security/config/aide/99-local-ignore-dynamic.conf /etc/aide/aide.conf.d/99-local-ignore-dynamic.conf
```

2. Verify your active AIDE config exists and still parses:

```bash
aide --config /etc/aide/aide.conf --check
```

3. Reinitialize baseline after tuning changes:

```bash
aideinit
cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db
```

Notes:
- Exclude only high-churn runtime data; avoid broad exclusions outside known noisy paths.
- Excluding `/var/lib/mysql` is common on DB hosts because data files churn constantly.
- Keep database config files (for example under `/etc/mysql`) monitored by AIDE.

## Notes

- AIDE change alerts after package upgrades are expected; review first, then rebuild baseline only for trusted changes.
- Run Lynis on-demand after major system or network-facing service changes, not only monthly.
- `rkhunter` and `chkrootkit` overlap but are complementary; using both is normal on Debian-like servers.
- `clamav` improves malware scanning for user-supplied files and mail flows but is optional on minimal hosts.
