Submitting the form

All results for 'Openime Oniagbi'

Showing 6 of 6 results

Detecting malicious URLs using Wazuh and URLhaus

Blog / Engineering / Detecting malicious URLs using Wazuh and URLhaus

URLhaus is a project operated by abuse.ch. The purpose of the project is to collect, track, and share malware URLs, to help network administrators and security analysts protect their networks from cyber threats. URLhaus also offers an API to query information about malicious URLs. Integrating this API with Wazuh can help organizations improve their ability […]

Detecting Pandora Ransomware with Wazuh

Blog / Engineering / Detecting Pandora Ransomware with Wazuh

Pandora Ransomware gained notoriety in March 2022 when DENSO, a well-known giant in the automotive industry was compromised. After this, several malware researchers analyzed Pandora samples and agree that it is a variant of Rook ransomware, a well-known malware that first appeared on VirusTotal in November 2021. The Pandora ransomware group has published several victims […]

Detecting process injection attacks with Wazuh

Blog / Engineering / Detecting process injection attacks with Wazuh

Process injection is a defense evasion technique used by adversaries to execute malicious code within legitimate processes. When malware runs its code in the context of another process, it can access the process’ memory, use system/network resources, and assume elevated privileges. In most cases, users cannot differentiate an injected process from a legitimate one as […]

Detecting Dirty Pipe vulnerability with Wazuh (CVE-2022-0847)

Blog / Engineering / Detecting Dirty Pipe vulnerability with Wazuh (CVE-2022-0847)

A vulnerability in the Linux kernel, dubbed “Dirty Pipe”, allows unprivileged users to overwrite data in read-only files. This can allow users to gain access to root privileges on the vulnerable endpoints. This is possible because exploiting this vulnerability can allow unprivileged processes to inject code into root processes. The vulnerability was discovered and explained […]

Enhancing macOS protection with Wazuh

Blog / Engineering / Enhancing macOS protection with Wazuh

Since version 4.3.0, Wazuh introduced a new technique for collecting logs from macOS endpoints using the unified logging system (ULS). ULS is available in macOS 10.12 and later. Wazuh uses the CLI log tool to gather these logs in syslog format. This tool provides an interface for log collection in a filtered way using the […]

No results for 'Openime Oniagbi'

Please make sure that all words are spelled correctly.