Report Windows Firewall events through Event Channel
Windows Event Channel monitoring in OSSEC is the modern version of Event Log, and unlike this, Event Channel allows you to make queries in order to filter events. In this case...
Windows Event Channel monitoring in OSSEC is the modern version of Event Log, and unlike this, Event Channel allows you to make queries in order to filter events. In this case...
..."producer": "k8s.io" }, "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "javier.castro@wazuh.com" }, "authorizationInfo": [{ "granted": true, "permission": "io.k8s.core.v1.pods.list", "resource": "core/v1/namespaces/default/pods" }], "methodName": "io.k8s.core.v1.pods.list", "requestMetadata": { "callerIp": "sanitized", "callerSuppliedUserAgent": "GoogleCloudConsole" },...
Hi everyone. The team is pleased to announce that Wazuh 3.12.0 is released. This new version comes with lots of additions and improvements. Here are the highlights: Wazuh core This...
We are glad to announce that Wazuh 4.0.0 is released. Discover the new additions and improvements here! Wazuh is now better than ever. New features and changes in Wazuh 4.0...
...them a highly reliable tool to guarantee their security and defend their information,” states Camilo Fernandez, CEO at Devel Group, S.A. Devel Group, S.A.’s operations are concentrated in Central America...
The goal of this article is to explain how to set up a basic configuration of FIM (File Integrity Monitoring) using the syscheck component in OSSEC. After that, we will check...
In some environments the hardest part of the deployment process is the installation of OSSEC on Windows endpoints. Wazuh has created a tool to install, register and connect Windows agents using...
Lately, not only the tech and related communities, but also pretty much everyone else has heard of GDPR, the new standards for security compliance. GDPR (General Data Protection Regulation) has...
When you use Wazuh’s default configuration for the Elastic Stack (by following the installation guide) alerts are indexed in elasticsearch with the following naming convention: wazuh-alerts-3.x-YYYY.MM.dd This means you are...
Note Update 7/4/2022: Wazuh 4.3 natively supports Office 365 with a more robust and complete integration. If you are working with Wazuh 4.3 or newer, go to the Using Wazuh...
Please make sure that all words are spelled correctly.