Blog / Engineering / Detecting Medusa ransomware with Wazuh
...the following Medusa ransomware rule: rule Medusa_ransomware { meta: description = "Medusa Ransomware" author = "Obinna Uchubilo" reference = "https://github.com/Neo23x0/yarGen" date = "2025-04-16" hash1 = "3a6d5694eec724726efa3327a50fad3efdc623c08d647b51e51cd578bddda3da" strings: $s1 = "api-ms-win-core-synch-l1-2-0.dll"...
Blog / Engineering / Detecting BlackCat ransomware with Wazuh
BlackCat, also known as ALPHV ransomware, is a sophisticated ransomware that analysts first observed in November 2021. It operates as a Ransomware-as-a-Service (RaaS), where affiliates pay for software that enables...
Blog / Engineering / Deploying Wazuh agents using ManageEngine
Wazuh is an open source security platform that offers Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) capabilities to organizations. It provides security to IT infrastructure...
Blog / Engineering / Detecting Lynx ransomware with Wazuh
Lynx ransomware is a sophisticated malware threat that has been active since mid-2024, with over 20 victims across various industries. It primarily targets Windows operating systems, encrypting files using the...