Detect Reverse Shells With Wazuh! - Let's Build A Host Intrusion Detection System

  Рет қаралды 7,971

Taylor Walton

Taylor Walton

Күн бұрын

Пікірлер: 11
@michailgiannopoulos5274
@michailgiannopoulos5274 3 жыл бұрын
Cool video. Please do more about Wazuh product. It looks phenomenal!
@taylorwalton_socfortress
@taylorwalton_socfortress 3 жыл бұрын
Hey Michail, yes, wazuh is an awesome tool :) I have a lot of other wazuh videos so check those out if you haven’t already. Please feel free to make any recommendations for other tools! Thanks for watching!
@alejandroparrello6493
@alejandroparrello6493 Жыл бұрын
You're the master Taylor! 👏👏🤘🦸
@alejandroparrello6493
@alejandroparrello6493 Жыл бұрын
Dear taylor, I have a question: where/how did you learned about wazuh? Just from public wazuh documentation? Or some official course? Regards from Argentina 👋 😊
@Damielsestrem
@Damielsestrem Жыл бұрын
Hi Taylor, how can i adapt your tutorial for windows? for example... to lateral moviment with eternalblue or something like that... is the same way? can u give me an example?
@samuraidenis
@samuraidenis 2 жыл бұрын
Thanks again. Thoughts on shell from Windows ?
@yassine4855
@yassine4855 3 жыл бұрын
Great vid! I got a question for you bro I know that wazuh can monitor network devices like firewalls and switchs but is it possible to make the the firewall block IP address from wazuh using the response feature?
@taylorwalton_socfortress
@taylorwalton_socfortress 3 жыл бұрын
Hey Yassine, good question. Wazuh can ingest syslog which firewalls and switches can be configured to output. However, firewalls and switches generally have their own OS which is far different than a Linux, Windows, etc. OS and a Wazuh Agent cannot be installed on those type of OS. I recommend deploying a Wazuh-Agent on a jumpserver, bastion, reverse proxy, etc. that end users must interact with before they can get into your network. For example, one of my networks has a bastion server that users must logon to before they can interact with any internal hosts. The bastion server is a linux distro, is facing the internet and is running a wazuh-agent. I have active response enabled on this server so, for example, when an Ip address is observed attempting to login with multiple failed logins, active response runs and adds their IP as an iptables drop to the bastion server. This is a server that sits behind the firewall and in front of the internal network so no traffic can get through unless a valid user has logged onto the bastion server first and is a similar solution to what you are looking for. Hope that helps and thanks for watching!
@isriadeputra
@isriadeputra Жыл бұрын
wrong password admin "metallica", and not can check ip with "ip a/ ifonfig" message :comand not found
@antonandreea5291
@antonandreea5291 9 ай бұрын
did you find the right password?
@DavidLopez-fe7ue
@DavidLopez-fe7ue 3 ай бұрын
@@antonandreea5291 you have to log in via ssh, so: ssh admin@
Гениальное изобретение из обычного стаканчика!
00:31
Лютая физика | Олимпиадная физика
Рет қаралды 4,8 МЛН
小丑教训坏蛋 #小丑 #天使 #shorts
00:49
好人小丑
Рет қаралды 54 МЛН
Мясо вегана? 🧐 @Whatthefshow
01:01
История одного вокалиста
Рет қаралды 7 МЛН
Quarantine Malware with Wazuh + YARA
25:41
Taylor Walton
Рет қаралды 10 М.
Chapter 12 - Wazuh Decoders and Rules
49:49
SIEMonster
Рет қаралды 18 М.
Threat Detection & Active Response With Wazuh
45:56
HackerSploit
Рет қаралды 107 М.
Detecting Abnormal Network Connections With Wazuh
14:16
Taylor Walton
Рет қаралды 21 М.
Syslog and Wazuh - Let's Build A Host Intrusion Detection System
15:12
Гениальное изобретение из обычного стаканчика!
00:31
Лютая физика | Олимпиадная физика
Рет қаралды 4,8 МЛН