284 lines
7.2 KiB
Markdown
284 lines
7.2 KiB
Markdown
# ClamAV Integration with Wazuh
|
|
|
|
Integration guide for deploying ClamAV antivirus with Wazuh monitoring stack.
|
|
|
|
## Overview
|
|
|
|
ClamAV scans files and containers for malware, while Wazuh collects and analyzes ClamAV logs for:
|
|
- Real-time malware detection alerts
|
|
- Ransomware detection
|
|
- Signature database update status
|
|
- Scan statistics and quarantine actions
|
|
|
|
---
|
|
|
|
## Architecture
|
|
|
|
```
|
|
┌─────────────────────────────────────┐
|
|
│ ClamAV Container (clamav) │
|
|
│ • Scans Docker containers/files │
|
|
│ • Generates logs: clamav.log │
|
|
│ • Freshclam updates signatures │
|
|
└──────────────┬──────────────────────┘
|
|
│ (logs volume)
|
|
↓
|
|
┌─────────────────────────────────────┐
|
|
│ Wazuh Manager (wazuh.manager) │
|
|
│ • Collects ClamAV logs │
|
|
│ • Parses with decoders │
|
|
│ • Matches detection rules │
|
|
│ • Sends alerts to indexer │
|
|
└──────────────┬──────────────────────┘
|
|
│ (syslog format)
|
|
↓
|
|
┌─────────────────────────────────────┐
|
|
│ Wazuh Dashboard (UI) │
|
|
│ • Display malware detections │
|
|
│ • Show scan results │
|
|
│ • Alert severity levels │
|
|
└─────────────────────────────────────┘
|
|
```
|
|
|
|
---
|
|
|
|
## Deployment
|
|
|
|
### 1. Add ClamAV to docker-compose
|
|
|
|
The following service has been added to `docker-compose-security.yml`:
|
|
|
|
```yaml
|
|
clamav:
|
|
image: clamav/clamav:stable
|
|
container_name: clamav
|
|
restart: unless-stopped
|
|
environment:
|
|
- FRESHCLAM_CHECKS=24
|
|
- CLAMD_SCAN_MAX_FILESIZE=100M
|
|
volumes:
|
|
- clamav_data:/var/lib/clamav # Signature database
|
|
- clamav_logs:/var/log/clamav # Log output
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
networks:
|
|
- monitoring_net
|
|
```
|
|
|
|
### 2. Deploy ClamAV
|
|
|
|
```bash
|
|
cd /home/ubuntu/docker
|
|
docker compose -f docker-compose-security.yml up -d clamav
|
|
|
|
# Verify deployment
|
|
docker ps | grep clamav
|
|
docker logs clamav
|
|
```
|
|
|
|
### 3. Wazuh Configuration
|
|
|
|
#### Log Collection
|
|
|
|
File: `wazuh/config/wazuh_manager/localfile_clamav.conf`
|
|
|
|
Configures Wazuh to collect:
|
|
- `clamav.log` — Main scanner logs
|
|
- `freshclam.log` — Signature update logs
|
|
- `alert.log` — High-priority detections
|
|
|
|
#### Detection Rules
|
|
|
|
File: `wazuh/config/wazuh_manager/rules/clamav_rules.xml`
|
|
|
|
Key rules (level/priority):
|
|
|
|
| Rule ID | Level | Trigger | Example |
|
|
|---------|-------|---------|---------|
|
|
| 100501 | 15 | FOUND/Infected | Malware detected |
|
|
| 100502 | 12 | Trojan/PUA | Potentially unwanted app |
|
|
| 100503 | 15 | .Virus/Worm | Classic virus detection |
|
|
| 100504 | 15 | Ransomware | Ransomware families |
|
|
| 100505 | 3 | Update successful | Signature DB refreshed |
|
|
| 100506 | 10 | Update failed | Download/connection error |
|
|
| 100507 | 8 | Daemon error | ClamAV process error |
|
|
| 100515 | 16 | Multiple hits in 1h | Possible outbreak |
|
|
|
|
---
|
|
|
|
## Log Format
|
|
|
|
### ClamAV Log Example
|
|
|
|
```
|
|
Jun 10 14:35:22 clamav clamd[1234]: /var/data/suspect.exe: Trojan.Win32.Generic!c FOUND
|
|
Jun 10 14:35:25 clamav freshclam[5678]: ClamAV update completed. 1 databases updated.
|
|
Jun 10 14:36:01 clamav clamd[1234]: Scanning started
|
|
Jun 10 14:36:45 clamav clamd[1234]: Scanning finished. 2 files scanned, 0 threats found
|
|
```
|
|
|
|
### Wazuh Alert Example
|
|
|
|
```json
|
|
{
|
|
"timestamp": "2026-06-10T14:35:22.000Z",
|
|
"rule": {
|
|
"id": "100501",
|
|
"level": 15,
|
|
"description": "ClamAV: Malware detected"
|
|
},
|
|
"data": {
|
|
"srcfile": "/var/data/suspect.exe",
|
|
"alert": "Trojan.Win32.Generic!c FOUND"
|
|
},
|
|
"groups": ["malware", "clamav", "infection"]
|
|
}
|
|
```
|
|
|
|
---
|
|
|
|
## Operations
|
|
|
|
### Check ClamAV Status
|
|
|
|
```bash
|
|
# Container status
|
|
docker ps | grep clamav
|
|
|
|
# View logs
|
|
docker logs clamav
|
|
|
|
# Manual scan
|
|
docker exec clamav clamscan -r /var/data
|
|
```
|
|
|
|
### Update Signatures
|
|
|
|
ClamAV automatically updates signatures (configured via `FRESHCLAM_CHECKS=24`).
|
|
|
|
Manual update:
|
|
```bash
|
|
docker exec clamav freshclam
|
|
```
|
|
|
|
### View Wazuh Alerts
|
|
|
|
1. Access Wazuh Dashboard: `https://10.0.0.2`
|
|
2. Go to: **Security Events** → **Search**
|
|
3. Filter by:
|
|
- `rule.id: 100501` — Malware detections
|
|
- `rule.id: 100504` — Ransomware alerts
|
|
- `rule.groups: malware` — All malware-related events
|
|
|
|
### Query via API
|
|
|
|
```bash
|
|
# Get recent malware detections
|
|
curl -k -H "Authorization: Bearer YOUR_TOKEN" \
|
|
"https://monitoring-uber:55000/api/v0/search?q=rule.id:100501&pretty"
|
|
|
|
# Get ClamAV scan statistics
|
|
curl -k -H "Authorization: Bearer YOUR_TOKEN" \
|
|
"https://monitoring-uber:55000/api/v0/search?q=group:clamav&pretty"
|
|
```
|
|
|
|
---
|
|
|
|
## Tuning & Optimization
|
|
|
|
### Scan Performance
|
|
|
|
Adjust scan parameters in docker-compose environment:
|
|
|
|
```yaml
|
|
environment:
|
|
- CLAMD_SCAN_MAX_FILESIZE=100M # Max file size to scan
|
|
- CLAMD_MAX_SCAN_SIZE=200M # Max total scan size
|
|
- CLAMD_SCAN_PE_PLUS=yes # Enhanced PE detection
|
|
- CLAMD_SCAN_ARCHIVE=yes # Scan inside archives
|
|
- CLAMD_MAX_FILES=10000 # Max files to scan
|
|
```
|
|
|
|
### Update Frequency
|
|
|
|
Default: 24 checks per day (every hour)
|
|
|
|
Change via:
|
|
```yaml
|
|
environment:
|
|
- FRESHCLAM_CHECKS=48 # 2-hourly updates
|
|
```
|
|
|
|
### Alert Severity
|
|
|
|
Adjust rule levels in `clamav_rules.xml` based on your risk tolerance:
|
|
- Level 3-6: Info/Low
|
|
- Level 8-10: Medium
|
|
- Level 12-15: High
|
|
- Level 16+: Critical/Outbreak
|
|
|
|
---
|
|
|
|
## Troubleshooting
|
|
|
|
### ClamAV Not Scanning
|
|
|
|
```bash
|
|
# Check daemon is running
|
|
docker exec clamav ps aux | grep clamd
|
|
|
|
# Check signatures are loaded
|
|
docker exec clamav clamscan --version
|
|
|
|
# Manually scan
|
|
docker exec clamav clamscan /var/data
|
|
```
|
|
|
|
### Signature Updates Failing
|
|
|
|
```bash
|
|
# Check freshclam logs
|
|
docker logs clamav | grep freshclam
|
|
|
|
# Manual update with verbose output
|
|
docker exec clamav freshclam -v
|
|
|
|
# Check internet connectivity
|
|
docker exec clamav wget https://cvd.clamav.net
|
|
```
|
|
|
|
### Wazuh Not Receiving Logs
|
|
|
|
```bash
|
|
# Check logs are being generated
|
|
docker exec clamav tail -f /var/log/clamav/clamav.log
|
|
|
|
# Check Wazuh log collection
|
|
docker exec wazuh_manager tail -f /var/ossec/logs/ossec.log | grep clamav
|
|
|
|
# Verify rules loaded
|
|
docker exec wazuh_manager cat /var/ossec/etc/rules/clamav_rules.xml | head -10
|
|
```
|
|
|
|
---
|
|
|
|
## Files Modified/Created
|
|
|
|
| File | Purpose |
|
|
|------|---------|
|
|
| `docker-compose-security.yml` | Added ClamAV service + volumes |
|
|
| `wazuh/config/wazuh_manager/localfile_clamav.conf` | Log collection config |
|
|
| `wazuh/config/wazuh_manager/rules/clamav_rules.xml` | Malware detection rules |
|
|
| `CLAMAV_INTEGRATION.md` | This documentation |
|
|
|
|
---
|
|
|
|
## Next Steps
|
|
|
|
1. Deploy: `docker compose up -d clamav`
|
|
2. Wait for initial database download (5-10 minutes)
|
|
3. Monitor logs: `docker logs -f clamav`
|
|
4. Check Wazuh dashboard for alerts
|
|
5. Configure scan schedules/locations as needed
|
|
6. Set up active response (optional) for automatic quarantine
|
|
|