← All projects
Security & networking · Python
FI

fim

File integrity monitor — SHA-256 baselines, tamper detection and HMAC-signed verification, right in your browser.

1 Take a baseline

The simulated tree mirrors demo/run_demo.sh. Hashing uses the Web Crypto API (crypto.subtle.digest) — real SHA-256 in your browser.

No baseline yet. Click "fim init".

2 Current file system

Mutate the tree the way an attacker would, then run fim check.

Editing the baseline to hide a change fails the signature check when FIM_KEY is set.

3 fim check

Changes
—
Signature
—
Exit code
—
Run a check to see the report.

What it detects

  • added — new file under the root (web shells, uploads)
  • modified — SHA-256 of content changed (defacements)
  • removed — file present in baseline, missing now
  • permissions — mode bits changed, content same
  • baseline tamper — HMAC verification fails

Exit codes: 0 clean, 1 changes, 3 baseline error — same as the CLI.

Security notes

  • Keep the baseline off the monitored host (or on a read-only mount).
  • Keep FIM_KEY out of the monitored tree.
  • mtimes are recorded but not compared — they are trivial to fake.
  • Content hashes are what count.

A root-level attacker on the same host can still defeat any local monitor. This is one layer of defence.

7 tests · Python 3.10+ · standard library only · Built by Umer Hashmi