example being the insertion of unauthorized code or installation of an unauthorized program that executes in the environment (ie: virus), Tripwire does integrity checking and obviously it would detect the change in environment upon insertion/installation, but would it also prevent the code/program from executing?
