Automate OSQUERY with Wazuh - Let's Build A Host Intrusion Detection System

  Рет қаралды 8,388

Taylor Walton

Taylor Walton

3 жыл бұрын

Join me as we use the Osquery Wazuh Wodle to run OSQUERY as a Daemon. Let's deploy a Host Intrusion Detection System and SIEM with free open source tools. Join me as we explore and learn together.
Defend with us on Slack: bit.ly/2Pi1byt
Check us out: www.opensecure.co/
Interact with our demo: www.opensecure.co/demo
Hire us: www.opensecure.co/contact-us

Пікірлер: 15
@iain_grant
@iain_grant 8 ай бұрын
Great vid - helps me understand where to place osquery as Wazuh isn't that clear on that.
@kennethshibaba4490
@kennethshibaba4490 10 ай бұрын
Hi Taylor. Great video. Did you install osquery in your server or agent device? Forgive the question.
@user-vi1nj7rc4l
@user-vi1nj7rc4l 3 ай бұрын
What could be causing nothing in wazuh to be showing up in the dashboard like yours does. I followed the video and cant seem to get any events in wazuh
@jasonyeung2498
@jasonyeung2498 2 жыл бұрын
Might I ask if I can put the osquery.conf into /var/ossec/etc/shared/ so that, for example in Windows, I can pull the conf file back at C:\Program Files (x86)\ossec-agent\shared\osquery.conf? Is it one way to do the remote deployment for osquery?
@taylorwalton1388
@taylorwalton1388 2 жыл бұрын
Hey Jason, unfortunately no. The /var/ossec/etc/shared directory contains parameters that also belong in the ossec.conf. This allows you to setup log collection, FIM directories, wodle modules, etc. and apply these settings to all wazuh agents in the group. To mass deploy the osquery.conf you could use Ansible, Chef or another remote deployment tool of your choice. Hope that helps and thanks for watching!
@JSRJS
@JSRJS 5 ай бұрын
What about OSQuery on Windows??? Wazuh settings you show are only for Linux : (
@pierreyoboue5473
@pierreyoboue5473 Жыл бұрын
Hi, thanks for all. I have a request, can i have your config and flag files? i want deploy on windows and i have some problem with these files
@tomsgrinbergs8020
@tomsgrinbergs8020 3 жыл бұрын
Little bit off topic here.. Wondering if there is a network flow(not cisco's netflow) tool that can be installed in a home lab setting and then integrated into Wazuh?
@taylorwalton_socfortress
@taylorwalton_socfortress 3 жыл бұрын
Hey Tom, Are you interested in monitoring network traffic, with something like an IDS/IPS device? If so, I really enjoy an Open Source tool called, Suricata. It can be set inline or receive packets via a span port. These results detail network flows as well as any network related events such as traffic to a command and control server, web application attacks, IP reputation and more. This tool integrates very well with Wazuh and ELK. I plan on covering Suricata and integrating it with Wazuh in future videos, but feel free to explore on your own! suricata.readthedocs.io/en/latest/what-is-suricata.html Thanks for watching!
@tomsgrinbergs8020
@tomsgrinbergs8020 3 жыл бұрын
@@taylorwalton_socfortress Thanks, yes I've been looking into Suricata. I'm struggling with aggregating the bytes sent and received, so essentially the sum of the below: data.flow.bytes_toclient data.flow.bytes_toserver It appears that these are strings and thus don't show under "Significant Terms" when "Sum" is selected within visualizations thus I'm not able to see the total or bytes sent and received between 2 IP addresses. I'm now wondering how to use Jupyter-Notebook to do this, but I think that's a big stretch. Anyhow, will wait for your video on Suricata in future, thanks for making this content - I really enjoy it!
@8eck
@8eck 8 ай бұрын
Automated installation of osquery would be more interesting...
@anhuc2824
@anhuc2824 2 жыл бұрын
Hi, i have fleet server to manage all agent osquery, and file: osquery_result of all server locate at fleet server, how do i add log osquery_result to wazuh . Thanks
@taylorwalton_socfortress
@taylorwalton_socfortress 2 жыл бұрын
If the osquery_result is being json outputted, install a wazuh_agent onto the fleet server and edit the ossec.conf file to contain this block /path/to/osquery_result json Hope that helps and thanks for watching!
@pierreyoboue5473
@pierreyoboue5473 Жыл бұрын
@@taylorwalton_socfortress but how know the format ?
@user-bk4oi2lp1f
@user-bk4oi2lp1f 11 ай бұрын
W0706 18:03:09.135244 2388 options.cpp:106] The CLI only flag --logger_plugin set via config file will be ignored, please use a flagfile or pass it to the process at startup im facing this login on my custom query but packs works fine
The joker's house has been invaded by a pseudo-human#joker #shorts
00:39
Untitled Joker
Рет қаралды 4,5 МЛН
Каха ограбил банк
01:00
К-Media
Рет қаралды 9 МЛН
Automate Your InfoSec Tasks with Wazuh's API!
29:14
Taylor Walton
Рет қаралды 7 М.
Causely Platform Overview
3:55
Causely
Рет қаралды 102
What is Osquery
7:07
OpenInfo
Рет қаралды 1,7 М.
Lid hologram 3d
0:32
LEDG
Рет қаралды 7 МЛН
Игровой Комп с Авито за 4500р
1:00
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 163 М.
CY Superb Earphone 👌 For Smartphone Handset
0:42
Tech Official
Рет қаралды 821 М.
WWDC 2024 Recap: Is Apple Intelligence Legit?
18:23
Marques Brownlee
Рет қаралды 6 МЛН