M8. I watched your videos till this. You are UNFUCKINGBELIEVABLE! I didn't understand most of what wazuh can do until you. You simply enlightened me. The documentation although being ok is ... And wtf can I do with this? Please keep on the good work. You may saved some 1billion neurons to a complete stranger. THANK YOU!
@taylorwalton_socfortress3 жыл бұрын
Hey Johnny, I really appreciate the kind words! I am glad you find my videos helpful and feel free to recommend any new tools or features you would like to see, as long as they are open source of course :). Thanks for watching!
@Xanderboy2 жыл бұрын
I second this!
@Kuba_kubowy Жыл бұрын
Great video!
@АндрейПольский-ж5б Жыл бұрын
Hi, can I have more audit examples, for example: how do I watch folder changes? and to make audit exceptions for certain folders or commands. Thanks
@petarsimovic562810 ай бұрын
Thank you
@adriensaladin50823 жыл бұрын
Great video, as always ! A few questions: at min 26, you define a rule that checks for audit.execve.a1. I guess it would not detect the command "sudo cat /foo/bar /etc/passwd" since it would be the second argument to the cat command, so execve.a2, right ? Can a rule check that /etc/passwd is within audit.execve list? thanks!
@taylorwalton_socfortress3 жыл бұрын
Hey Adrien, your first question is correct. Ya a rule could check the field of the audit.execve fields for /etc/password, or whatever else you would like to search for
@mozibulhoque64392 жыл бұрын
That's great bro! I am glad to u and request to u, how to integrate hive & cortex in wazuh?
@anhuc28243 жыл бұрын
That is all agent have to install auditd to receive log cmd in linux, right?
@taylorwalton_socfortress3 жыл бұрын
Correct. Also ensure you grab the ruleset from github
@ihavenoname.49292 жыл бұрын
auditd is great, I prefer tlog because it'll show me the output of the user command as well as the command itself.
@taylorwalton_socfortress2 жыл бұрын
I'll have to check that out!
@oliveiras.de.emerson3 жыл бұрын
How i can monitor cmd comands in windows?
@pedronicolasgomez56773 жыл бұрын
Hi Emerson, I have some doubts with your question, do you want to run commands in Windows and monitor the output of the commands or do you want to monitor if a command was executed? In the first case, Wazuh has a functionality that allows you to get the output command with a custom rule if you create it. The following section of the documentation explains how it works: Wazuh-Documentation->user-manual->capabilities->command-monitoring Please, you should follow these steps to use the feature: 1. Set the logcollector.remote_command flag to 1 in local_internal_options.conf file. 2. Add the localfile section in ossec.conf or agent.conf depending on whether you want to share the configuration with a group of agents or configure it for a specific agent. 3. Create a rule to receive the alert in the manager. In the following section of the documentation, there are interesting examples on command monitoring. Wazuh-Documentation->user-manual->capabilities->command-monitoring->command-configuration In the second case, you can configure windows agents to monitor Sysmon events The following blog explains how to configure it: Wazuh-page->blog->using-wazuh-to-monitor-sysmon-events I hope it helps.
@petarsimovic562810 ай бұрын
vi /etc/audit/rules.d/audit.rules #add line: -a exit,always -F arch=b64 -F euid=0 -S execve -k audit-wazuh-c #load rules: auditctl -R /etc/audit/rules.d/audit.rules