Skip to main content

A high-performance file integrity monitoring CLI tool.

Project description

ChangeLens

ChangeLens is a high-performance, point-in-time File Integrity Monitor (FIM) and cryptographic auditing CLI utility. Built for security compliance, automated system auditing, and post-incident forensics, ChangeLens captures deterministic snapshots of file states and instantly detects unauthorized file modifications, additions, or deletions.


Core Features

  • Multi-Threaded Performance
    Concurrent, zero-leak cryptographic file hashing optimized for large, deep enterprise filesystems.

  • Cryptographic Tamper Protection
    Optional snapshot signing via HMAC-SHA256 to prevent attackers from altering baseline logs.

  • Persistent Exclusion Contract
    Local .changelensignore wildcards (similar to .gitignore) are compiled directly into the snapshot contract so verification runs remain completely drift-proof.

  • Offline Forensic Diff Engine
    Compare two historical snapshots completely offline without requiring access to the live environment.

  • CI/CD & Automation Ready
    Structured JSON summaries for SIEM pipelines alongside clean Markdown summaries for automated GitHub Action/GitLab CI job logs.


Installation

Production Installation (Recommended)

ChangeLens is distributed as a pre-compiled Python Wheel via GitHub Releases. You do not need to clone the source code to use it.

Download and install the latest release directly via pip:

pip install pip install https://github.com/Mohamed-Zouari-dev/Change_Lens/releases/download/v1.0.0/changelens-1.0.0-py3-none-any.whl

Local Development Setup

To contribute to the project or inspect the codebase, clone the repository and install it in editable mode:

git clone https://github.com/Mohamed-Zouari-dev/Change_Lens.git
cd changelens
pip install -e .

Getting Started

Once installed, the global changelens binary is available anywhere on your system path.


1. Initialize a Baseline Snapshot

Scan a target directory and freeze its state.

You can pass inline exclusions or rely on a local .changelensignore file placed in the target directory root.

changelens init /etc/nginx --output nginx_baseline.json --exclude "*.tmp"

Example output:

Baseline created successfully.
Files scanned: 12543
Snapshot saved: nginx_baseline.json

2. Verify System Integrity

Compare a live directory against a historical baseline to detect:

  • Unauthorized modifications
  • Malware persistence
  • Configuration drift
  • Software changes
  • Security breaches
changelens verify nginx_baseline.json /etc/nginx

3. Generate Automation and Audit Logs

Export structural details to feed external alerting pipelines, SIEM systems, or CI/CD reports.

changelens verify nginx_baseline.json /etc/nginx \
    --save-json audit_report.json \
    --save-md summary.md

Generated reports:

audit_report.json
summary.md

4. Offline Directory Diffing

Compare two completely separate snapshots taken at different points in time without accessing the original filesystem.

changelens diff monday_baseline.json friday_snapshot.json

Useful for:

  • Incident response investigations
  • Compliance audits
  • Historical forensic analysis

Advanced Hardening: Tamper Protection

To prevent attackers with elevated privileges from modifying tracking baselines, ChangeLens supports cryptographic snapshot signing using HMAC-SHA256.

Sign the Baseline During Initialization

Set a high-entropy secret key:

export CHANGELENS_SECRET="your-high-entropy-signing-key"

Create a signed snapshot:

changelens init /var/www/html -o secure.json

Verify With Strict Authenticity Checks

export CHANGELENS_SECRET="your-high-entropy-signing-key"

changelens verify secure.json /var/www/html

If an attacker manually modifies secure.json to forge malicious file changes, the signature validation engine detects the alteration using constant-time comparison, aborts verification, and raises a critical integrity alert.


Architecture Overview

ChangeLens is designed around four main components:

                +----------------+
                |  CLI Interface |
                +--------+-------+
                         |
                         v
                +----------------+
                | Snapshot Engine |
                +--------+-------+
                         |
        +----------------+----------------+
        |                                 |
        v                                 v
+---------------+              +----------------+
| Hash Workers  |              | Ignore Parser  |
| SHA-256 Engine|              | Contract Rules |
+---------------+              +----------------+
        |
        v
+----------------+
| Snapshot Store |
| JSON Metadata  |
+----------------+

Security Model

ChangeLens provides:

Feature Protection
SHA-256 hashing Detects file content changes
HMAC-SHA256 signing Prevents snapshot tampering
Ignore contract Prevents inconsistent scans
Offline diffing Enables forensic analysis
JSON reports Integrates with security tooling

Example Use Cases

Enterprise Servers

Monitor critical directories:

changelens init /etc --output etc_baseline.json

Verify periodically:

changelens verify etc_baseline.json /etc

Web Application Security

Monitor deployed applications:

changelens init /var/www/application \
    --output production.json

Detect unauthorized changes after deployment.


Compliance Auditing

Generate evidence reports:

changelens verify baseline.json /secure/data \
    --save-md compliance_report.md

Useful for:

  • Security audits
  • Change management
  • Regulatory compliance

Roadmap

v1.0

  • SHA-256 file hashing
  • Directory snapshots
  • Integrity verification
  • JSON reporting
  • Markdown reporting

v1.1

  • Parallel hashing optimization
  • .changelensignore support
  • HMAC snapshot signing
  • Advanced diff engine

v2.0

  • SIEM integrations
  • Real-time filesystem monitoring
  • Web dashboard
  • Distributed agent architecture

License

This project is licensed under the MIT License.

See the LICENSE file for details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

changelens-1.0.0.tar.gz (13.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

changelens-1.0.0-py3-none-any.whl (14.7 kB view details)

Uploaded Python 3

File details

Details for the file changelens-1.0.0.tar.gz.

File metadata

  • Download URL: changelens-1.0.0.tar.gz
  • Upload date:
  • Size: 13.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.14

File hashes

Hashes for changelens-1.0.0.tar.gz
Algorithm Hash digest
SHA256 b10a1ef3ccc45d44239dd7832cb3480c63b356a65198495ae3e746f41328ec4f
MD5 cc8e95e27f279db2142cb9821cd80950
BLAKE2b-256 4d75f9205a97a865c1b56ffce02ceab86fb67e223bc0116061d96bb160a1dbdc

See more details on using hashes here.

File details

Details for the file changelens-1.0.0-py3-none-any.whl.

File metadata

  • Download URL: changelens-1.0.0-py3-none-any.whl
  • Upload date:
  • Size: 14.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.14

File hashes

Hashes for changelens-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 d7d7fbb1c61265398af532acee78437d8681eaba19a883103bd4a5faa067c5fc
MD5 f953ca8de266a79ed630dda0a80fd33e
BLAKE2b-256 bad0f60d50c84ce125c826e5b680324ca0020da233ce69ea48cb49328d44c5ee

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page