Blog / Engineering / Detect and respond to BlackSuit ransomware with Wazuh
...ransomware executable detection" author = "Aishat Motunrayo Awujola" reference = "https://github.com/Neo23x0/yarGen" date = "2024-10-03" hash1= "90ae0c693f6ffd6dc5bb2d5a5ef078629c3d77f874b2d2ebd9e109d8ca049f2c" strings: $x1 = "C:\\Users\\pipi-\\source\\repos\\encryptor\\Release\\encryptor.pdb" fullword ascii $s2 = "api-ms-win-core-synch-l1-2-0.dll" fullword wide /* reversed goodware...
Blog / Engineering / Detecting Brain Cipher ransomware with Wazuh
...file C:\Program Files (x86)\ossec-agent\active-response\bin\yara\rules\yara_rules.yar and add the following Brain Cipher ransomware rule: rule BrainCipher_ransomware { meta: description = "Brain Cipher ransomware executable detection" author = "Aishat Motunrayo Awujola" reference =...
Blog / Engineering / Achieving CJIS compliance with Wazuh
The Criminal Justice Information Services (CJIS) security policy 2022, version 5.9.1, establishes the standards for safeguarding sensitive criminal justice information (CJI) in the United States. Issued by the FBI, this...