yes
yes
no
no
no
10m
0
3
plain
secure
1514
tcp
131072
no
yes
yes
yes
yes
yes
yes
yes
43200
etc/rootcheck/rootkit_files.txt
etc/rootcheck/rootkit_trojans.txt
yes
yes
1800
1d
yes
wodles/java
wodles/ciscat
yes
yes
/var/log/osquery/osqueryd.results.log
/etc/osquery/osquery.conf
yes
no
1h
yes
yes
yes
yes
yes
yes
yes
10
yes
yes
12h
yes
yes
yes
60m
yes
https://wazuh.indexer:9200
/etc/ssl/root-ca.pem
/etc/ssl/filebeat.pem
/etc/ssl/filebeat.key
no
43200
yes
yes
no
/etc,/usr/bin,/usr/sbin
/bin,/sbin,/boot
/etc/mtab
/etc/hosts.deny
/etc/mail/statistics
/etc/random-seed
/etc/random.seed
/etc/adjtime
/etc/httpd/logs
/etc/utmpx
/etc/wtmpx
/etc/cups/certs
/etc/dumpdates
/etc/svc/volatile
.log$|.swp$
/etc/ssl/private.key
yes
yes
yes
yes
10
100
yes
5m
1h
10
127.0.0.1
^localhost.localdomain$
90.50.148.138
90.120.69.13
10.0.0.3
disable-account
disable-account
yes
restart-wazuh
restart-wazuh
firewall-drop
firewall-drop
yes
host-deny
host-deny
yes
route-null
route-null
yes
win_route-null
route-null.exe
yes
netsh
netsh.exe
yes
clamav-quarantine
clamav-quarantine
no
firewall-drop
local
5710,5711,5712,5716,5720,5760,5763
0
firewall-drop
local
authentication_failures
0
firewall-drop
local
authentication_failed
0
host-deny
local
5710,5711,5712,5716,5720,5760,5763
0
firewall-drop
local
7
web,attack
300
firewall-drop
local
1002,2502,2503,2504
3600
host-deny
local
authentication_failures,authentication_failed
0
firewall-drop
local
100202,100203,100205
21600
firewall-drop
local
100204,100206
86400
clamav-quarantine
local
52502
firewall-drop
local
100210
86400
firewall-drop
local
100300
3600
firewall-drop
local
100301
86400
disable-account
local
100310
7200
firewall-drop
local
100310
21600
firewall-drop
local
100220
21600
firewall-drop
local
100290
86400
host-deny
local
100290
0
firewall-drop
local
100221
21600
firewall-drop
local
100222
86400
host-deny
local
100222
0
firewall-drop
local
100292
0
host-deny
local
100292
0
firewall-drop
local
100223,100224
43200
firewall-drop
local
100230
86400
firewall-drop
local
100240
14400
firewall-drop
local
100291
86400
firewall-drop
local
100241
21600
firewall-drop
local
100250
21600
firewall-drop
local
100293
86400
firewall-drop
local
100251
43200
firewall-drop
local
100252
21600
firewall-drop
local
100260
43200
firewall-drop
local
100270
7200
firewall-drop
local
100280
43200
firewall-drop
local
100281
21600
no
host-deny
all
100210
86400
firewall-drop
all
100204,100206
86400
firewall-drop
all
5710,5711,5712,5716,5720,5760,5763
0
firewall-drop
all
authentication_failures
0
firewall-drop
all
authentication_failed
0
host-deny
all
5710,5711,5712,5716,5720,5760,5763
0
firewall-drop
all
7
web,attack
300
firewall-drop
all
1002,2502,2503,2504
3600
host-deny
all
authentication_failures,authentication_failed
0
firewall-drop
all
100202,100203,100205
21600
firewall-drop
all
100300
3600
firewall-drop
all
100301
86400
firewall-drop
all
100220
21600
firewall-drop
all
100290
86400
firewall-drop
all
100221
21600
firewall-drop
all
100222
86400
firewall-drop
all
100292
0
firewall-drop
all
100223,100224
43200
firewall-drop
all
100230
86400
firewall-drop
all
100240
14400
firewall-drop
all
100291
86400
firewall-drop
all
100241
21600
firewall-drop
all
100250
21600
firewall-drop
all
100293
86400
firewall-drop
all
100251
43200
firewall-drop
all
100252
21600
firewall-drop
all
100260
43200
firewall-drop
all
100270
7200
firewall-drop
all
100280
43200
firewall-drop
all
100281
21600
command
df -P
360
full_command
netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d
netstat listening ports
360
full_command
last -n 20
360
ruleset/decoders
ruleset/rules
0025-sendmail_rules.xml
0030-postfix_rules.xml
0035-spamd_rules.xml
0040-imapd_rules.xml
0045-mailscanner_rules.xml
0050-ms-exchange_rules.xml
0055-courier_rules.xml
0065-pix_rules.xml
0070-netscreenfw_rules.xml
0075-cisco-ios_rules.xml
0080-sonicwall_rules.xml
0090-telnetd_rules.xml
0100-solaris_bsm_rules.xml
0105-asterisk_rules.xml
0110-ms_dhcp_rules.xml
0115-arpwatch_rules.xml
0130-trend-osce_rules.xml
0135-hordeimp_rules.xml
0155-dovecot_rules.xml
0160-vmpop3d_rules.xml
0165-vpopmail_rules.xml
0170-ftpd_rules.xml
0175-proftpd_rules.xml
0185-vsftpd_rules.xml
0190-ms_ftpd_rules.xml
0195-named_rules.xml
0215-policy_rules.xml
0750-github_rules.xml
0250-apache_rules.xml
0255-zeus_rules.xml
0265-php_rules.xml
0275-squid_rules.xml
0295-mysql_rules.xml
0305-dropbear_rules.xml
0315-apparmor_rules.xml
0350-amazon_rules.xml
0360-serv-u_rules.xml
0385-oscap_rules.xml
0390-fortiddos_rules.xml
0391-fortigate_rules.xml
0392-fortimail_rules.xml
0393-fortiauth_rules.xml
0120-symantec-av_rules.xml
0125-symantec-ws_rules.xml
0395-hp_rules.xml
0405-rsa-auth-manager_rules.xml
0410-imperva_rules.xml
0415-sophos_rules.xml
0990-amazon-security-lake_rules.xml
0435-ms_logs_rules.xml
0445-identity_guard_rules.xml
0450-mongodb_rules.xml
0460-jenkins_rules.xml
0470-vshell_rules.xml
0475-suricata_rules.xml
0480-qualysguard_rules.xml
0485-cylance_rules.xml
0700-paloalto_rules.xml
0500-owncloud_rules.xml
0505-vuls_rules.xml
0525-openvas_rules.xml
0530-mysql_audit_rules.xml
0535-mariadb_rules.xml
0540-pfsense_rules.xml
0545-osquery_rules.xml
0550-kaspersky_rules.xml
0555-azure_rules.xml
0565-ms_ipsec_rules.xml
0575-win-base_rules.xml
0580-win-security_rules.xml
0585-win-application_rules.xml
0590-win-system_rules.xml
0601-win-vipre_rules.xml
0602-win-wfirewall_rules.xml
0610-win-ms_logs_rules.xml
0630-nextcloud_rules.xml
0675-panda-paps_rules.xml
0680-checkpoint-smart1_rules.xml
0770-gitlab_rules.xml
0775-arbor_rules.xml
0780-fireeye_rules.xml
0785-huawei-usg_rules.xml
0800-sysmon_id_1.xml
0810-sysmon_id_3.xml
0820-sysmon_id_7.xml
0830-sysmon_id_11.xml
0840-win_event_channel.xml
0860-sysmon_id_13.xml
0870-sysmon_id_8.xml
0905-cisco-ftd_rules.xml
0690-gcp_rules.xml
0910-ms-exchange-proxylogon_rules.xml
0920-oracledb_rules.xml
0925-eset-remote_rules.xml
0955-WEF-baseline_rules.xml
0960-macos_rules.xml
0995-microsoft-graph_rules.xml
0755-office365_rules.xml
0140-roundcube_rules.xml
0998-aws-security-hub-rules.xml
0400-openvpn_rules.xml
etc/lists/audit-keys
etc/lists/amazon/aws-eventnames
etc/lists/security-eventchannel
etc/lists/malicious-ioc/malicious-ip
etc/lists/malicious-ioc/malicious-domains
etc/lists/malicious-ioc/malware-hashes
etc/lists/wireguard-trusted-ips
etc/decoders
etc/rules
yes
1
64
15m
no
1515
no
yes
no
HIGH:!ADH:!EXP:!MD5:!RC4:!3DES:!CAMELLIA:@STRENGTH
no
etc/sslmanager.cert
etc/sslmanager.key
no
wazuh
node01
master
aa093264ef885029653eea20dfcf51ae
1516
0.0.0.0
wazuh.manager
no
yes
syslog
/var/ossec/logs/active-responses.log