Know the instant a critical file changes.
Attackers rarely knock. They quietly drop a web shell, edit a config, or swap a binary - and on most systems nobody notices until it is far too late. Suriq watches the files and directories that matter on every host, captures every add, modify, and delete, and raises the changes that look like an attack before they become an incident.
The file changed weeks ago. You found out today.
A tampered config, a planted web shell, a quietly replaced binary - the change that opens the door is small and silent. Without continuous monitoring of the right paths, it sits unnoticed while the attacker settles in.
Watches the files that matter
Monitor key directories, configs, and binaries on every host - in real time on the paths that need it. Each add, modify, and delete is captured by the managed Wazuh core, with the file, the change, and the time it happened.
Tagged and raised, not buried
Changes that match known attack patterns are tagged to MITRE ATT&CK and raised as incidents, routed to on-call - not lost in a log nobody reads.
Tune out the noise
Baseline what is normal and ignore the paths that churn, per host. You hear about the changes that matter and stay quiet on the ones that do not.
Legacy stack vs. Suriq
| Dimension | Legacy | Suriq |
|---|---|---|
| Detection | Scheduled scans only | Real-time, configurable per path |
| Context | A raw change list | Incidents, MITRE-tagged where it matches |
| Tuning | All-or-nothing | Per-path baseline and ignore |
A verdict on each change, not a pile of diffs.
A standalone FIM tool hands you a raw list of every file that changed and leaves the triage to you. Suriq fuses the signals it already collects into a verdict for each change, so routine noise suppresses itself and the changes that look like an attack are the ones that reach a human.
Who changed it, not just what
Every change carries who-data attribution - the user or process behind the write - so you are not left guessing whether an admin or an intruder touched the file.
Reconciled with what you run
A change caused by a routine package or config-management action - dnf, apt, dpkg, and the rest - is tied back to it automatically, so a normal update does not page you.
Scored, then bucketed
Hash reputation - known-good versus known-bad - and sealed-path policy feed a verdict on every event: benign, worth a review, or suspicious. The overwhelming majority resolves on its own, so on-call sees the tail that matters.
Log tamper, not log noise
On the log files you monitor, Suriq tells a normal append apart from a truncation, an in-place rewrite, or a deletion - and raises only the tamper, not every new line written.
Suriq vs a standalone FIM tool
Netwrix, Tenable, Tripwire, and Tanium run file integrity as a dedicated product you deploy, tune, and watch on its own. Suriq gives you the same real-time, per-path monitoring - built on the open-source Wazuh core - but folds it into one managed detection platform, so the change is attributed, reconciled, and correlated instead of stranded in a change log of its own.
| Dimension | Standalone FIM tool | Suriq |
|---|---|---|
| What you get | A change list to triage yourself | A per-change verdict: benign, review, or suspicious |
| Attribution | The file and the time it changed | Who or what process made the change |
| Update noise | Every package update flags | Reconciled to the action that caused it |
| Where it lives | A separate product to run | Inside managed detection, agent-based, on one timeline |
Reflects the general difference between a dedicated file-integrity product and file integrity monitoring delivered as part of a managed detection platform.
What file integrity monitoring should cover
Good file integrity monitoring watches the right paths in real time, not everything on a schedule. Attackers touch a predictable set of places, and Suriq monitors them on every host through the managed Wazuh core - capturing each add, modify, and delete with the file, the change, and the time.
- System and service configuration files, where a quiet edit opens a door
- Web roots and application directories, where a web shell lands
- Critical binaries and shared libraries, swapped to hide a backdoor
- Authentication and account files, for added users or changed keys
- Scheduled-task and startup locations, where persistence likes to hide
Changes that match known attack patterns are tagged to MITRE ATT&CK and raised as incidents routed to on-call. The paths that churn are baselined per host, so routine noise stays quiet and only what matters reaches you - in real time, not on the next scan.
Standalone FIM products - Tenable, Netwrix, Tripwire - run change auditing as a dedicated tool you deploy and watch on its own. Suriq gives you the same real-time, per-path file integrity monitoring, agent-based with no separate appliance, but folds it into one managed detection platform: every change correlated with your other signals and raised as an incident, not stranded in a change log of its own.
Know which hosts a new CVE hits in seconds.
Continuous package scanning against the CVE databases, scored by CVSS and ranked worst-first, with a fix Jack can explain.
Hunt across every event, tagged to MITRE ATT&CK.
Search and pivot across retained detections, every one carrying its tactic and technique, correlated into incidents.
Know who is exposed in seconds.
Detect, correlate, alert, and recover - with a full audit trail from first signal to post-mortem.
Frequently asked questions
What is file integrity monitoring (FIM)?
Is Suriq's file integrity monitoring real-time?
How does Suriq cut file-monitoring noise?
How is Suriq's FIM different from a standalone FIM tool?
Is Suriq an alternative to Tenable or Netwrix file integrity monitoring?
Which files should I monitor with FIM?
Is Suriq open-source file integrity monitoring?
How does Suriq know who changed a file?
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.