"As stated, Nmap and snort, both are killer apps in my book.  There's also LIDS for the linux kernel.  SATAN is a bit outdated but still can't hurt.  There's also LAST, but i have never used that one myself.  There is an open sourced (i.e. free) version of Tripwire, i use it on my linux servers here at work, but i don't know if it is portable to other OS/architectures.

satan has morphed into saint, which has in turn become sara.
