← All projects
Security & networking · Python
FI
fim
File integrity monitor — SHA-256 baselines, tamper detection and HMAC-signed verification, right in your browser.
1 Take a baseline
The simulated tree mirrors demo/run_demo.sh. Hashing uses the Web Crypto API (crypto.subtle.digest) — real SHA-256 in your browser.
No baseline yet. Click "fim init".
2 Current file system
Mutate the tree the way an attacker would, then run fim check.
Editing the baseline to hide a change fails the signature check when FIM_KEY is set.
3 fim check
Changes
—
Signature
—
Exit code
—
Run a check to see the report.
What it detects
- added — new file under the root (web shells, uploads)
- modified — SHA-256 of content changed (defacements)
- removed — file present in baseline, missing now
- permissions — mode bits changed, content same
- baseline tamper — HMAC verification fails
Exit codes: 0 clean, 1 changes, 3 baseline error — same as the CLI.
Security notes
- Keep the baseline off the monitored host (or on a read-only mount).
- Keep
FIM_KEYout of the monitored tree. - mtimes are recorded but not compared — they are trivial to fake.
- Content hashes are what count.
A root-level attacker on the same host can still defeat any local monitor. This is one layer of defence.