The Wazuh File Integrity Monitoring (FIM) Use case

  Рет қаралды 19,842

MyDFIR

MyDFIR

Күн бұрын

Пікірлер: 81
@repairstudio4940
@repairstudio4940 6 ай бұрын
Wazuh is awesome! You should do more Wazuh tutorials for those unfamiliar, it'd help save so many ppl's data. Absolutely wonderful video man, glad your part of the cyber security community! 🤘🏼😎
@MyDFIR
@MyDFIR 6 ай бұрын
Thank you! I will definitely continue to provide tutorials for you all ❤️ thanks for watching.
@repairstudio4940
@repairstudio4940 6 ай бұрын
@@MyDFIR Thank YOU! That's very much appreciated. 🙂
@deepaknarayanan3619
@deepaknarayanan3619 6 ай бұрын
One of the most underrated youtuber in cybersecurity domain. Wishing you to reach more subscribers in future as these kinds of contents will be useful for many in this modern technology based society. Appreciate your consistency and determination on making these contents brother. Love from India ❤
@MyDFIR
@MyDFIR 6 ай бұрын
Wow, thank you! That means a lot to me ❤️
@connerhaynes2197
@connerhaynes2197 21 күн бұрын
I am just starting to configure and use Wazuh in our company and honestly this is one of the most informative and helpful video on YT I have ever seen. Really great information. Have to check out your other posts and we be happy to see more of this. Thank you so much!
@MyDFIR
@MyDFIR 21 күн бұрын
Glad it was helpful! It was really fun making this video and there definitely will be more Wazuh content coming this year!
@ericgonzalez4120
@ericgonzalez4120 21 күн бұрын
Excellent video. You did an amazing job explaining the features and do manage your voice/tone very well. Just subscribed to your channel. Yes, please add more Wazuh videos!
@MyDFIR
@MyDFIR 21 күн бұрын
Thank you! I’m glad you found it helpful! I’ll keep the Wazuh content coming.
@bigrigbutters187
@bigrigbutters187 6 күн бұрын
Wow. This was a BANGER of a video! Thanks to the algorithm.
@MyDFIR
@MyDFIR 6 күн бұрын
You’re awesome 💙 thanks for watching!!
@foxlarr
@foxlarr 3 ай бұрын
Wazuh is super tool! Please, make more wazuh tutorials, and thank you for your videos!
@MyDFIR
@MyDFIR 3 ай бұрын
More to come!
@JoycelynJack-rl6ve
@JoycelynJack-rl6ve 5 ай бұрын
You just won a subscriber. This is just what i was looking for all over KZbin. Please provide more on both ubuntu and windows os. 💯🔥
@MyDFIR
@MyDFIR 5 ай бұрын
Thank you!
@arcvasquez64
@arcvasquez64 Ай бұрын
Great video! With simple to follow examples but very helpful. Keep it up!
@MyDFIR
@MyDFIR Ай бұрын
Thanks, I appreciate it!
@hwakeyedgaming1751
@hwakeyedgaming1751 Ай бұрын
my man i got to learn so much in such a easy way would love to see more content like this..
@MyDFIR
@MyDFIR Ай бұрын
Thanks! Stay tuned 💙
@ravindrapillay4319
@ravindrapillay4319 6 ай бұрын
Awesome job..excellent and clear to understand tutorial
@MyDFIR
@MyDFIR 6 ай бұрын
Glad it was helpful!
@SoCyber-n5k
@SoCyber-n5k 6 ай бұрын
Great video. I got your class course, and I was used Wazuh as additional SiEm tool to monitor on top of Splunk. With the FMI I will have more conf on windows and other OS. Thank you again 🎉for
@MyDFIR
@MyDFIR 6 ай бұрын
Awesome!! Thanks for your support and I hope you learned a lot ❤️
@SoCyber-n5k
@SoCyber-n5k 6 ай бұрын
@@MyDFIR I do I do
@leav.8874
@leav.8874 Ай бұрын
to add new agent: server management -> endpoints summary -> deploy new agent
@alexpizana6816
@alexpizana6816 4 ай бұрын
Thank you very much! Amazing video man... I've learned a lot. More videos on Wazuh BTT🙂
@MyDFIR
@MyDFIR 4 ай бұрын
My pleasure 💙
@wanderer4x4
@wanderer4x4 4 ай бұрын
Fantastic explanation!! Just subscribed 👍
@MyDFIR
@MyDFIR 4 ай бұрын
Awesome, thank you!
@diegomed3364
@diegomed3364 6 ай бұрын
Omg!! It was wanderfull. Hopefully you will include in your course
@MyDFIR
@MyDFIR 6 ай бұрын
Thanks!
@blackcastlemanagementgroup
@blackcastlemanagementgroup 6 ай бұрын
Loved your video on FIM also!
@MyDFIR
@MyDFIR 6 ай бұрын
Glad you enjoyed it!
@ronniejust
@ronniejust 6 ай бұрын
Thanks am learning something from uganda africa
@MyDFIR
@MyDFIR 6 ай бұрын
Nice!
@JeffPedlow
@JeffPedlow 6 ай бұрын
This is a great video, thanks for sharing. :)
@MyDFIR
@MyDFIR 6 ай бұрын
Thanks for watching!
@cyberkits93
@cyberkits93 6 ай бұрын
nice sharing, please share it more
@MyDFIR
@MyDFIR 6 ай бұрын
Thanks for watching!
@blackcastlemanagementgroup
@blackcastlemanagementgroup 6 ай бұрын
I am loving Wazuh!!!
@MyDFIR
@MyDFIR 6 ай бұрын
Glad to hear!!
@ohlordvoldy
@ohlordvoldy 6 ай бұрын
Thank you for this!!
@MyDFIR
@MyDFIR 6 ай бұрын
You're so welcome!
@CronicasDeRunaterra-rg9jt
@CronicasDeRunaterra-rg9jt 2 ай бұрын
Muy interesante la verdad te agradezco mucho, tu contenido es de calidad, podrías explicar cómo puedo poner que estos eventos pasen a ser "alertas criticas"? hay alguna posibilidad?
@netSec360
@netSec360 6 ай бұрын
Love to see your videos
@MyDFIR
@MyDFIR 6 ай бұрын
Thank you for watching ❤️
@j.t.2190
@j.t.2190 4 ай бұрын
This vid is gold! Ive been using wazuh on a virtual machine for awhile to learn it. Its been great. Specially when poking my windows machine with kali linux and then check wazuh dashboad
@MyDFIR
@MyDFIR 4 ай бұрын
Glad it helped! I’ll definitely put that to the list
@jimhall9290
@jimhall9290 6 ай бұрын
This was great and very informative! More Wazuh content, please. This Wazuh update with FIM looks like a great monitoring tool. How does Wazuh compare with Lima Charlie? Which is a more comprehensive security tool and why? Thank you in advance for any info you can provide! 🙂
@MyDFIR
@MyDFIR 6 ай бұрын
Great question! They both have their pros and cons but the main difference here is that LimaCharlie is more modular if that makes sense. It can work with practically any tool. Wazuh is more of a complete solution if tuned/configured properly. If possible, I would use both tools :)
@jainayrogeorge2924
@jainayrogeorge2924 4 ай бұрын
More Wazuh content please, im trying to monitor a specific directory on mac but its not working
@ianlondon2888
@ianlondon2888 6 ай бұрын
An updated wazuh installation and configuration vid would be great. Particularly in docker
@MyDFIR
@MyDFIR 6 ай бұрын
Great idea!
@MrChino2627
@MrChino2627 Ай бұрын
Hello, this must be configured in each of the deployed agents. Is there a way to do this from the dashboard?
@oOMrYairOo
@oOMrYairOo 8 күн бұрын
Great video,can you make tutorial how to push config files to agents? Becouse no it admin is gonna sit and config lets say 100 workstation one by one to monitor.
@MyDFIR
@MyDFIR 8 күн бұрын
That is a great idea! In the meantime, I believe this documentation from Wazuh would be helpful: documentation.wazuh.com/current/user-manual/reference/centralized-configuration.html
@Loco4Waffles
@Loco4Waffles 5 ай бұрын
Fantastic video! I do have two questions: If I have multiple endpoints, how do I easily add custom paths to monitor in FIM? Do I have to manually edit the ossec.conf in every endpoint? Second question: Instead of drilling down to look for an alert in a every single endpoint, does the fim alerts appear in the top/main dashboard?
@MyDFIR
@MyDFIR 5 ай бұрын
You can use a centralized config file documentation.wazuh.com/current/user-manual/reference/centralized-configuration.html and use the alerts dashboard for an overview rather than drilling down into each host
@greenpill810
@greenpill810 6 ай бұрын
From today, you earned my subscription and I take you as my mentor. please accept me. I love the way you take your time to explain. I would want to implement wazuh in my present organization because we do not have a cyber security team and I would like to break into that space. we have a file server and a domain controller and 3 other member servers. My main question is, ON WHICH SERVER WOULD I INSTALL WAZUH. Hope to get a response.
@MyDFIR
@MyDFIR 6 ай бұрын
Ideally you would spin up another server dedicated to Wazuh.
@joshuampere4327
@joshuampere4327 6 ай бұрын
we need another project with wazuh and caldera
@MyDFIR
@MyDFIR 6 ай бұрын
Oooo 👀👀
@nullOwl
@nullOwl 5 ай бұрын
Hey bro,can you do a video on how to integrate wazuh with slack to get real time alerts
@MyDFIR
@MyDFIR 5 ай бұрын
Great idea, ill add that into my content list!
@nelosboss
@nelosboss 6 ай бұрын
This is brilliant Steven...but the question I have is this...In a real life scenario how would you install the agent unto the pc to monitor it if it belongs to a staff or is there a way to automatically have it installed by default through active directory or something...Maybe through the office domain and all
@MyDFIR
@MyDFIR 6 ай бұрын
Ive seen this done via GPO, SCCM, or manually via remote support. Really depends on the organization. As per Wazuh documentation “If you are deploying Wazuh in a large environment, with a high number of servers or endpoints, keep in mind that this deployment might be easier using automation tools such as Puppet, Chef, SCCM, or Ansible.”
@nelosboss
@nelosboss 6 ай бұрын
@@MyDFIR Okay...thanks alot brother
@jg1000c
@jg1000c 6 ай бұрын
can all the fim configuration be done centrally in agent.conf? I'm guessing yes.
@MyDFIR
@MyDFIR 6 ай бұрын
Spot on!
@Just_A_Tech.._
@Just_A_Tech.._ 6 ай бұрын
👍
@alyx3135
@alyx3135 6 ай бұрын
Hi, Would love to know how will you document for learning purposes after performing an attack such as using Atomic Red Team I followed your video and bought your roadmap thanks!
@MyDFIR
@MyDFIR 6 ай бұрын
Completely up to you! Some examples can be to create a step by step on how to setup/execute attacks and/or create a how to document on detecting the attacks you ran. Thanks for the support!
@2005sty
@2005sty 4 ай бұрын
How can i know if wazuh is compromised by hacker? The dashboard ce showed a few File deleted the wazuh manager host device.
@robinjames779
@robinjames779 6 ай бұрын
Which siem tool best to learn for beginners?
@MyDFIR
@MyDFIR 6 ай бұрын
Any free one that you can put your hands on :) Wazuh is great
@ferozeworld5234
@ferozeworld5234 6 ай бұрын
I have one question ccna or comptia network+ which one is best for cybersecurity...
@MyDFIR
@MyDFIR 6 ай бұрын
Both are good and both are optional but you must at the very least, understand networking concepts.
@maximilian4171
@maximilian4171 6 ай бұрын
Hello! Quick question, are you running all these methods inside a virtual machine? Cause i'm thinking of creating one through microsoft azure
@MyDFIR
@MyDFIR 6 ай бұрын
Yup! Every lab video I use a VM as it’s easier for clean up when done.
@maximilian4171
@maximilian4171 6 ай бұрын
@@MyDFIR alright, thank you. Will try doing this and exploring some more as an additional to my portfolio.
Cybersecurity SOC Analyst Lab - PDF Analysis
17:17
MyDFIR
Рет қаралды 4,6 М.
Avoid Compromise with Wazuh Active Response
16:35
MyDFIR
Рет қаралды 3,3 М.
So Cute 🥰 who is better?
00:15
dednahype
Рет қаралды 19 МЛН
СИНИЙ ИНЕЙ УЖЕ ВЫШЕЛ!❄️
01:01
DO$HIK
Рет қаралды 3,3 МЛН
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН
How To Become a SOC Analyst in 2025
16:53
MyDFIR
Рет қаралды 15 М.
ClamAV + Wazuh, powerful Anti-Virus protection for Linux
30:21
Christian Lempa
Рет қаралды 23 М.
EXCLUSIVE LOOK | Tour our Security Operations Center (SOC)
2:10
DOT Security
Рет қаралды 35 М.
Cybersecurity Trends for 2025 and Beyond
16:55
IBM Technology
Рет қаралды 239 М.
100+ Linux Things you Need to Know
12:23
Fireship
Рет қаралды 1,6 МЛН
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 2,5 МЛН
Detect Hackers & Malware on your Computer (literally for free)
16:38
So Cute 🥰 who is better?
00:15
dednahype
Рет қаралды 19 МЛН