Wednesday, August 12, 2026 4:00 PM UTC
Linux has shipped a powerful integrity-enforcement mechanism since 2009, and almost nobody turns it on. It's called IMA, the Integrity Measurement Architecture, and it does two things: it measures files by recording a hash of everything that executes, and it appraises them by checking each file against a known-good hash and refusing to run anything that doesn't match. In this session we'll turn it on, live.
You'll watch the kernel measure everything that runs on a system, then deny a binary that has been tampered with, using nothing but functionality already present in the kernel you're running today.
But turning it on is the easy part. The harder question is the one that actually determines whether a tool like this protects you. Not "has this file changed," but "should this have run at all?" We'll walk through why integrity checking is a solved problem while knowing what belongs on your system is not, and why that gap is a definition problem no scanner, feed, or lookup can close for you.
You'll leave knowing what IMA is, the difference between measuring and appraising, how to enable it on your own systems, and one thing you can do Monday to start getting value from it. No agents, no vendors, no dedicated security team required.
By registering after the event has passed, you will receive a recording of the webinar.
Copyright © 2026 | Ginger Cybersecurity LLC | All Rights Reserved