Тёмный

Building a Blacklist Database in Wazuh - Let's Deploy a Host Intrusion Detection System #12 

Taylor Walton
Подписаться 18 тыс.
Просмотров 6 тыс.
50% 1

Join me as we configure our own blacklist database in Wazuh. Immediately detect with known malicious IPs are attemtping to login to your servers. Let's deploy a Host Intrusion Detection System and SIEM with free open source tools. Join me as we explore and learn together.
Command Used: github.com/OpenSecureCo/Wazuh...
Check us out: www.opensecure.co/
Interact with our demo: www.opensecure.co/demo
Hire us: www.opensecure.co/contact-us

Наука

Опубликовано:

 

30 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 5   
@MohammedYaseen-lz9yi
@MohammedYaseen-lz9yi 4 месяца назад
Can you make a video on Adding Malware hashes and test few of them on new Wazuh version and also Automatic logs Backup syncronization to another location @taylor
@neithaltair4597
@neithaltair4597 3 года назад
Thank Youuuuuuuuuuuuuuu !! Genius!.
@taylorwalton_socfortress
@taylorwalton_socfortress 3 года назад
Thanks for watching!
@crakkajakka15
@crakkajakka15 2 года назад
I would assume depending on the size of these list this could be pretty process intensive for the agent to process. Have you found a list limit or length where you start to see performance issues. I.e 1000 items in a list or 10000 items in a list etc.?
@taylorwalton_socfortress
@taylorwalton_socfortress 2 года назад
Hey, ya I am sure that could eventually become an issue, however, I assume these list can grow rather large because I have not ran into that issue yet. I also recommend taking advantage of Cortex and TheHive to gather IP, domain, etc. intelligence as well. This would offload gathering further intelligence from the Wazuh Manager and put that load onto another system. Check out TheHive and Cortex demos here: TheHive: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-VqIuP0AOCBg.html&ab_channel=OpenSecure Cortex: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-qz6xtINwK3I.html&ab_channel=OpenSecure Hope that helps and let me know if you have any other questions!
Далее
Chapter 12 - Wazuh Decoders and Rules
49:49
Просмотров 15 тыс.
Shuffle + Wazuh + TheHIVE + Cortex = Automation Bliss
46:50
iPhone 16 - 20+ КРУТЫХ ИЗМЕНЕНИЙ
5:20
НЕ БЕРУ APPLE VISION PRO!
0:37
Просмотров 370 тыс.
iPhone 16 - 20+ КРУТЫХ ИЗМЕНЕНИЙ
5:20