AIDE (Advanced Intrusion Detection Environment) turns your Artica appliance into a file-integrity monitor (FIM).
It takes a cryptographic baseline of the files and directories that matter — system binaries, account files, SSH keys, service configuration — and, on every scheduled run, compares the live filesystem against that baseline.
Any file that was added, removed or modified becomes a reviewable event that a security team can approve or flag.
Unlike a stand-alone aide install, Artica manages the full lifecycle for you:
The binary, the configuration, the scan schedule, the baseline, an operator triage workflow, and structured forwarding to your SIEM.
No shell, no cron editing.

/etc/passwd, /etc/shadow, SSH keys and service configs — the first thing an attacker touches after a breach.apt), the configuration is generated from editable rule groups, and the schedule is a click away.key=value syslog lines (tag artica-aide) to your local syslog, or straight to a remote SIEM (Wazuh, Splunk, ELK, QRadar…) over UDP/TCP The feature is organized as a set of tabs. Each has its own guide:
You enable the feature; Artica installs AIDE, seeds best-practice rule groups, generates configuration and builds the initial baseline.
A schdule entry then runs the check on your schedule.
Each detected change is upserted as an event and emitted to syslog/SIEM.
Your team triages events (approve or flag suspect). Once every change is approved, you may update the baseline to promote the current state to the new trusted reference.
That gate is the core safety property: the baseline never silently absorbs an unreviewed change.