Vigilance vs AIDE

Updated 5 Oct 2026

AIDE watches files on a server and tells you when one changed. Vigilance finds the update that gained a hidden power, before you install it.

Start Free See Pricing

The Catch AIDE Cannot Make

AIDE tells you which files changed. It does not tell you what the change can do. Vigilance reads the change itself. It compares the version you trust with the version you install. It reports any file that can suddenly do more.

A real one: xz Utils, 2024

xz is a compression library on almost every Linux server. In release 5.6.1, a hidden backdoor shipped inside liblzma. It can intercept a remote login. The release was signed by its own maintainer. A file integrity checker reports that the library changed, and a normal update changes it too. One command shows what the change can do:

vigi diff --old ./xz-5.4.6 --new ./xz-5.6.1

HEADS UP. 1 file changed. liblzma can now run hidden code during a remote login.

Read the full record: xz Utils backdoor. See more in the attack library.

Run both. AIDE marks the file as changed. Vigilance shows the power that change adds. The two sit side by side below. For the wider field, read the software supply chain security tools guide or the full list of comparisons.

What AIDE Does Well

AIDE checks that the files on a Unix machine still match a database you made earlier. Its own site calls it "a file and directory integrity checker". It is a mature tool and many Linux distributions package it.

The workflow has four commands. The --init command builds a database of the files you select in the config file. The --check command compares that database with the disk. The --update command writes a new database. The --compare command compares two databases, for example from two hosts.

The database holds file type, permissions, inode, owner, group, size, link count and link name. It also holds modification, change and access times. AIDE supports several hash algorithms. The site lists md5, sha1, rmd160, tiger, crc32, sha256, sha512 and whirlpool. It can also check POSIX ACLs, SELinux contexts and extended attributes if support is compiled in.

Control is the second strength. The config file is plain text. You write regular expression rules to include or exclude files and directories. You can build your own attribute groups, and you can tell the report to ignore added, removed or changed attributes. A careful administrator can tune AIDE to a precise policy for one server.

AIDE is also easy to adopt. The license is GPL-2.0, the source is public on GitHub, and the site lists packages for Debian, Ubuntu, FreeBSD, Gentoo, macOS, NixOS, OpenBSD, openSUSE, SUSE, Red Hat, CentOS and Fedora. It can run as a static binary for a client and server layout. Support comes from a mailing list, an IRC channel and GitHub issues. It has no price and no account.

For a compliance task such as "tell me if a system file changed on this host", AIDE does the job at no cost. Our page on file integrity monitoring explains the category.

Where It Falls Short

AIDE falls short on meaning. It reports that a file differs from the database. It does not report what the new file can do.

This matters for software updates. A normal update changes many files. After a package upgrade, an AIDE check lists those files as changed. A backdoored update appears in the same list. The report holds the same kind of line in both cases. The administrator must then decide which of the changed files to read.

The second gap is timing. AIDE checks a machine after the files already sit on disk. You build the baseline from a system you trust, and you check later. It does not take a package file, a container image or an installer and compare it with the version you run today. Vigilance does that before you install.

The third gap is noise. A server in daily use changes constantly. The AIDE config lets you exclude paths and ignore attributes, but you write and maintain those rules yourself. Each exclusion also removes coverage. Vigilance takes the opposite path. A normal update changes files but gains no new capability, so it stays quiet. It speaks up when a file can reach the network, run a command or read a secret and the earlier version had no such power.

The fourth gap is reach. The AIDE site says it runs on any modern Unix. It names no Windows build, so a mixed fleet needs another tool for Windows. Vigilance runs on Windows, Mac, Linux and the BSDs, and it reads inside deb, rpm, npm, pip, containers, MSI and ISO files. See FIM for Windows for that case.

The fifth gap is the database itself. AIDE holds its baseline in a database file. The manual advises you to verify the signature of the source code you download. It gives no details on signing the database, so you must plan where to keep that file safe. Vigilance signs a receipt per machine into a folder you already back up.

Feature Comparison

The table shows that AIDE and Vigilance answer different questions. AIDE answers "did this file change". Vigilance answers "what can this file do that the last one did not have".

Question AIDE Vigilance
Tells you a file changed Yes Yes
Tells you what the changed file can now do No. It reports attributes and hashes. Yes
Compares an old version with a new version before you install No. It checks a live system against its own database. Yes
Tracks permissions, owner, inode and link count Yes No
Tracks ACLs, SELinux and extended attributes Yes, if support is compiled in No
Runs on Windows The site names no Windows build Yes
Reads inside deb, rpm, npm, pip, containers, MSI and ISO No Yes
Needs a rule file you write and tune Yes. Regular expression rules No. It needs no rules
Open source Yes. GPL-2.0 No
Price Free Free up to 50 machines. Pro from $999 per month

The AIDE column comes from the AIDE site and the AIDE manual. The Vigilance column comes from our docs and use cases.

When AIDE Is the Better Fit

AIDE is the better fit when you must prove that the files on a Unix server stay the same, and you have the time to tune it.

Choose AIDE if your task is an audit control such as "alert me when a system file, a config file or a permission changes". Vigilance does not track permissions, owners or inodes. AIDE does.

Choose AIDE if you need an open source license. AIDE is GPL-2.0, and anyone can read and change the source. Vigilance is a commercial product.

Choose AIDE if you have a small budget and a few Linux or BSD hosts. It costs nothing, and the packages sit in your distribution. Choose it if your team already knows its rule syntax and has a baseline process in place.

Choose AIDE if you must watch changes that no software update caused. An attacker who edits a file by hand on a live host changes the attributes AIDE tracks. A scheduled check can find that edit. Vigilance looks at versions of software, not at hand edits over time.

Choose Vigilance if your risk is the update you install. Run it when a dependency, a container image or a vendor installer changes. Run it on a laptop, a build server or an AI agent that installs packages on its own. Read the supply chain attack prevention page for the practice.

Pricing

AIDE costs nothing to license. The AIDE site lists it as open source under GPL-2.0 and states no price. Your cost is the time to write rules, store the database and read each report.

Vigilance has two plans, and both are flat for the whole company. There is no per-machine price. Prices are in Canadian dollars. The pricing section holds the current numbers.

For a team with a few Linux hosts and a file integrity task, AIDE alone costs less. For a team that installs outside software and wants to know what each update gained, the Free plan covers up to 50 machines.

Which One Do You Need?

Use both if you run Linux servers and install outside software. AIDE watches the machine over time. Vigilance reads each update before you trust it.

Use AIDE alone if your only need is an integrity check on a few Unix hosts. Use Vigilance alone if your need is to vet updates, dependencies and images, on any operating system.

Known Risk versus New Risk

Known risk

A file that no longer matches the baseline you recorded. AIDE works here.

New risk

A file that gained a capability it never had, inside an update that looks normal. Vigilance works here.

Common Questions

Is Vigilance an AIDE alternative?

Yes, for one job. AIDE reports that a file changed. Vigilance reports what the changed file can now do. Many teams run both.

What does Vigilance do that AIDE does not?

Vigilance compares the version you trust with a new one. It reports each file that gained a capability, such as reaching the network or running a command. AIDE records attributes and hashes, not capabilities.

What does AIDE do that Vigilance does not?

AIDE checks a live system against a stored database on a schedule. It tracks permissions, owners, inodes, ACLs and extended attributes. Vigilance does not track those. AIDE is also free open source software under GPL-2.0.

Is AIDE free?

Yes. AIDE is open source software under the GPL-2.0 license, and its site lists no price. Vigilance has a Free plan for up to 50 machines and a Pro plan that starts at $999 per month, in Canadian dollars.

Does AIDE run on Windows?

The AIDE site says it runs on any modern Unix and lists Linux, BSD and macOS packages. It names no Windows build. Vigilance runs on Windows, Mac, Linux and the BSDs. See FIM for Windows.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install. Download Vigilance and start free.

Start Free Talk to Us

Talk to Us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.