Capturing User Commands with Auditd and Wazuh - Let's Deploy a Host Intrusion Detection System #9

  Рет қаралды 5,874

Taylor Walton

Taylor Walton

Күн бұрын

Пікірлер: 16
@johnnyrico9957
@johnnyrico9957 3 жыл бұрын
M8. I watched your videos till this. You are UNFUCKINGBELIEVABLE! I didn't understand most of what wazuh can do until you. You simply enlightened me. The documentation although being ok is ... And wtf can I do with this? Please keep on the good work. You may saved some 1billion neurons to a complete stranger. THANK YOU!
@taylorwalton_socfortress
@taylorwalton_socfortress 3 жыл бұрын
Hey Johnny, I really appreciate the kind words! I am glad you find my videos helpful and feel free to recommend any new tools or features you would like to see, as long as they are open source of course :). Thanks for watching!
@Xanderboy
@Xanderboy 2 жыл бұрын
I second this!
@Kuba_kubowy
@Kuba_kubowy Жыл бұрын
Great video!
@АндрейПольский-ж5б
@АндрейПольский-ж5б Жыл бұрын
Hi, can I have more audit examples, for example: how do I watch folder changes? and to make audit exceptions for certain folders or commands. Thanks
@petarsimovic5628
@petarsimovic5628 10 ай бұрын
Thank you
@adriensaladin5082
@adriensaladin5082 3 жыл бұрын
Great video, as always ! A few questions: at min 26, you define a rule that checks for audit.execve.a1. I guess it would not detect the command "sudo cat /foo/bar /etc/passwd" since it would be the second argument to the cat command, so execve.a2, right ? Can a rule check that /etc/passwd is within audit.execve list? thanks!
@taylorwalton_socfortress
@taylorwalton_socfortress 3 жыл бұрын
Hey Adrien, your first question is correct. Ya a rule could check the field of the audit.execve fields for /etc/password, or whatever else you would like to search for
@mozibulhoque6439
@mozibulhoque6439 2 жыл бұрын
That's great bro! I am glad to u and request to u, how to integrate hive & cortex in wazuh?
@anhuc2824
@anhuc2824 3 жыл бұрын
That is all agent have to install auditd to receive log cmd in linux, right?
@taylorwalton_socfortress
@taylorwalton_socfortress 3 жыл бұрын
Correct. Also ensure you grab the ruleset from github
@ihavenoname.4929
@ihavenoname.4929 2 жыл бұрын
auditd is great, I prefer tlog because it'll show me the output of the user command as well as the command itself.
@taylorwalton_socfortress
@taylorwalton_socfortress 2 жыл бұрын
I'll have to check that out!
@oliveiras.de.emerson
@oliveiras.de.emerson 3 жыл бұрын
How i can monitor cmd comands in windows?
@pedronicolasgomez5677
@pedronicolasgomez5677 3 жыл бұрын
Hi Emerson, I have some doubts with your question, do you want to run commands in Windows and monitor the output of the commands or do you want to monitor if a command was executed? In the first case, Wazuh has a functionality that allows you to get the output command with a custom rule if you create it. The following section of the documentation explains how it works: Wazuh-Documentation->user-manual->capabilities->command-monitoring Please, you should follow these steps to use the feature: 1. Set the logcollector.remote_command flag to 1 in local_internal_options.conf file. 2. Add the localfile section in ossec.conf or agent.conf depending on whether you want to share the configuration with a group of agents or configure it for a specific agent. 3. Create a rule to receive the alert in the manager. In the following section of the documentation, there are interesting examples on command monitoring. Wazuh-Documentation->user-manual->capabilities->command-monitoring->command-configuration In the second case, you can configure windows agents to monitor Sysmon events The following blog explains how to configure it: Wazuh-page->blog->using-wazuh-to-monitor-sysmon-events I hope it helps.
@petarsimovic5628
@petarsimovic5628 10 ай бұрын
vi /etc/audit/rules.d/audit.rules #add line: -a exit,always -F arch=b64 -F euid=0 -S execve -k audit-wazuh-c #load rules: auditctl -R /etc/audit/rules.d/audit.rules
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН
Sigma Kid Mistake #funny #sigma
00:17
CRAZY GREAPA
Рет қаралды 30 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Threat Detection & Active Response With Wazuh
45:56
HackerSploit
Рет қаралды 109 М.
Getting started with Linux Audit
47:02
SHARE Association
Рет қаралды 10 М.
Detecting Exploits - OMIGod (Linux Logging with Auditd)
54:08
The Wazuh File Integrity Monitoring (FIM) Use case
32:04
MyDFIR
Рет қаралды 19 М.
Auditd TutorialPart 01
14:41
Cyber Lessons
Рет қаралды 15 М.
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН