yes yes no no no 10m 0 3 plain secure 1514 tcp 131072 no yes yes yes yes yes yes yes 43200 etc/rootcheck/rootkit_files.txt etc/rootcheck/rootkit_trojans.txt yes yes 1800 1d yes wodles/java wodles/ciscat yes yes /var/log/osquery/osqueryd.results.log /etc/osquery/osquery.conf yes no 1h yes yes yes yes yes yes yes 10 yes yes 12h yes yes yes 60m yes https://wazuh.indexer:9200 /etc/ssl/root-ca.pem /etc/ssl/filebeat.pem /etc/ssl/filebeat.key no 43200 yes yes no /etc,/usr/bin,/usr/sbin /bin,/sbin,/boot /etc/mtab /etc/hosts.deny /etc/mail/statistics /etc/random-seed /etc/random.seed /etc/adjtime /etc/httpd/logs /etc/utmpx /etc/wtmpx /etc/cups/certs /etc/dumpdates /etc/svc/volatile .log$|.swp$ /etc/ssl/private.key yes yes yes yes 10 100 yes 5m 1h 10 127.0.0.1 ^localhost.localdomain$ 90.50.148.138 90.120.69.13 10.0.0.3 disable-account disable-account yes restart-wazuh restart-wazuh firewall-drop firewall-drop yes host-deny host-deny yes route-null route-null yes win_route-null route-null.exe yes netsh netsh.exe yes clamav-quarantine clamav-quarantine no firewall-drop local 5710,5711,5712,5716,5720,5760,5763 0 firewall-drop local authentication_failures 0 firewall-drop local authentication_failed 0 host-deny local 5710,5711,5712,5716,5720,5760,5763 0 firewall-drop local 7 web,attack 300 firewall-drop local 1002,2502,2503,2504 3600 host-deny local authentication_failures,authentication_failed 0 firewall-drop local 100202,100203,100205 21600 firewall-drop local 100204,100206 86400 clamav-quarantine local 52502 firewall-drop local 100210 86400 firewall-drop local 100300 3600 firewall-drop local 100301 86400 disable-account local 100310 7200 firewall-drop local 100310 21600 firewall-drop local 100220 21600 firewall-drop local 100290 86400 host-deny local 100290 0 firewall-drop local 100221 21600 firewall-drop local 100222 86400 host-deny local 100222 0 firewall-drop local 100292 0 host-deny local 100292 0 firewall-drop local 100223,100224 43200 firewall-drop local 100230 86400 firewall-drop local 100240 14400 firewall-drop local 100291 86400 firewall-drop local 100241 21600 firewall-drop local 100250 21600 firewall-drop local 100293 86400 firewall-drop local 100251 43200 firewall-drop local 100252 21600 firewall-drop local 100260 43200 firewall-drop local 100270 7200 firewall-drop local 100280 43200 firewall-drop local 100281 21600 no host-deny all 100210 86400 firewall-drop all 100204,100206 86400 firewall-drop all 5710,5711,5712,5716,5720,5760,5763 0 firewall-drop all authentication_failures 0 firewall-drop all authentication_failed 0 host-deny all 5710,5711,5712,5716,5720,5760,5763 0 firewall-drop all 7 web,attack 300 firewall-drop all 1002,2502,2503,2504 3600 host-deny all authentication_failures,authentication_failed 0 firewall-drop all 100202,100203,100205 21600 firewall-drop all 100300 3600 firewall-drop all 100301 86400 firewall-drop all 100220 21600 firewall-drop all 100290 86400 firewall-drop all 100221 21600 firewall-drop all 100222 86400 firewall-drop all 100292 0 firewall-drop all 100223,100224 43200 firewall-drop all 100230 86400 firewall-drop all 100240 14400 firewall-drop all 100291 86400 firewall-drop all 100241 21600 firewall-drop all 100250 21600 firewall-drop all 100293 86400 firewall-drop all 100251 43200 firewall-drop all 100252 21600 firewall-drop all 100260 43200 firewall-drop all 100270 7200 firewall-drop all 100280 43200 firewall-drop all 100281 21600 command df -P 360 full_command netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d netstat listening ports 360 full_command last -n 20 360 ruleset/decoders ruleset/rules 0025-sendmail_rules.xml 0030-postfix_rules.xml 0035-spamd_rules.xml 0040-imapd_rules.xml 0045-mailscanner_rules.xml 0050-ms-exchange_rules.xml 0055-courier_rules.xml 0065-pix_rules.xml 0070-netscreenfw_rules.xml 0075-cisco-ios_rules.xml 0080-sonicwall_rules.xml 0090-telnetd_rules.xml 0100-solaris_bsm_rules.xml 0105-asterisk_rules.xml 0110-ms_dhcp_rules.xml 0115-arpwatch_rules.xml 0130-trend-osce_rules.xml 0135-hordeimp_rules.xml 0155-dovecot_rules.xml 0160-vmpop3d_rules.xml 0165-vpopmail_rules.xml 0170-ftpd_rules.xml 0175-proftpd_rules.xml 0185-vsftpd_rules.xml 0190-ms_ftpd_rules.xml 0195-named_rules.xml 0215-policy_rules.xml 0750-github_rules.xml 0250-apache_rules.xml 0255-zeus_rules.xml 0265-php_rules.xml 0275-squid_rules.xml 0295-mysql_rules.xml 0305-dropbear_rules.xml 0315-apparmor_rules.xml 0350-amazon_rules.xml 0360-serv-u_rules.xml 0385-oscap_rules.xml 0390-fortiddos_rules.xml 0391-fortigate_rules.xml 0392-fortimail_rules.xml 0393-fortiauth_rules.xml 0120-symantec-av_rules.xml 0125-symantec-ws_rules.xml 0395-hp_rules.xml 0405-rsa-auth-manager_rules.xml 0410-imperva_rules.xml 0415-sophos_rules.xml 0990-amazon-security-lake_rules.xml 0435-ms_logs_rules.xml 0445-identity_guard_rules.xml 0450-mongodb_rules.xml 0460-jenkins_rules.xml 0470-vshell_rules.xml 0475-suricata_rules.xml 0480-qualysguard_rules.xml 0485-cylance_rules.xml 0700-paloalto_rules.xml 0500-owncloud_rules.xml 0505-vuls_rules.xml 0525-openvas_rules.xml 0530-mysql_audit_rules.xml 0535-mariadb_rules.xml 0540-pfsense_rules.xml 0545-osquery_rules.xml 0550-kaspersky_rules.xml 0555-azure_rules.xml 0565-ms_ipsec_rules.xml 0575-win-base_rules.xml 0580-win-security_rules.xml 0585-win-application_rules.xml 0590-win-system_rules.xml 0601-win-vipre_rules.xml 0602-win-wfirewall_rules.xml 0610-win-ms_logs_rules.xml 0630-nextcloud_rules.xml 0675-panda-paps_rules.xml 0680-checkpoint-smart1_rules.xml 0770-gitlab_rules.xml 0775-arbor_rules.xml 0780-fireeye_rules.xml 0785-huawei-usg_rules.xml 0800-sysmon_id_1.xml 0810-sysmon_id_3.xml 0820-sysmon_id_7.xml 0830-sysmon_id_11.xml 0840-win_event_channel.xml 0860-sysmon_id_13.xml 0870-sysmon_id_8.xml 0905-cisco-ftd_rules.xml 0690-gcp_rules.xml 0910-ms-exchange-proxylogon_rules.xml 0920-oracledb_rules.xml 0925-eset-remote_rules.xml 0955-WEF-baseline_rules.xml 0960-macos_rules.xml 0995-microsoft-graph_rules.xml 0755-office365_rules.xml 0140-roundcube_rules.xml 0998-aws-security-hub-rules.xml 0400-openvpn_rules.xml etc/lists/audit-keys etc/lists/amazon/aws-eventnames etc/lists/security-eventchannel etc/lists/malicious-ioc/malicious-ip etc/lists/malicious-ioc/malicious-domains etc/lists/malicious-ioc/malware-hashes etc/lists/wireguard-trusted-ips etc/decoders etc/rules yes 1 64 15m no 1515 no yes no HIGH:!ADH:!EXP:!MD5:!RC4:!3DES:!CAMELLIA:@STRENGTH no etc/sslmanager.cert etc/sslmanager.key no wazuh node01 master aa093264ef885029653eea20dfcf51ae 1516 0.0.0.0 wazuh.manager no yes syslog /var/ossec/logs/active-responses.log