ClamAV + Wazuh, powerful Anti-Virus protection for Linux

Поделиться
HTML-код
  • Опубликовано: 4 янв 2025

Комментарии • 56

  • @Kevin-oj2uo
    @Kevin-oj2uo Месяц назад +32

    Please make more videos with Wazuh!! I love this security videos.

    • @christianlempa
      @christianlempa  Месяц назад +5

      Good idea! Let's see what I can do with it ;)

  • @jacksoncremean1664
    @jacksoncremean1664 Месяц назад +15

    On the topic of ClamAV's subpar detection, using ClamAV with fangfrisch is a must. It adds a bunch of 3rd party signatures to ClamAV that makes it comparable to commercial Antivirus solutions.

    • @RobertLaneTech
      @RobertLaneTech Месяц назад +2

      I was just setting up a Nextcloud instance with ClamAV, this will be super handy. I always thought ClamAV was a bit weak, but I've always figured better than nothing.

    • @christianlempa
      @christianlempa  Месяц назад +1

      Thanks for the feedback @jacksoncremean1664 that's already on my list to review for next year :D, But it seems there's a bigger challenge to using it in Docker, so I'll have to look at this.

    • @RandomUserName92840
      @RandomUserName92840 Месяц назад

      Any projects looking to do this as a unified package with a easy installer (maybe flatpak) now that ClamGTK is no more?

  • @loop-0-2
    @loop-0-2 Месяц назад +14

    A small contribution to make more non-advertised videos about security possible

  • @mikigurevich4477
    @mikigurevich4477 Месяц назад +2

    I've been labbing for years and only recently started applying my 20 years experience (Sr. DevSecOps Engineering) to building my lab into the division of production (DMZ) and RnD (dev+test).
    This video was truly helpful to understand that FOSS can be use fully to protect my start-up-business-idea-in-home-lab equipment! Thank you for your videos and work you put in to making them; keep it up!

    • @danielrauer5864
      @danielrauer5864 Месяц назад +2

      You have not understood in 20 years of professional experience what advantages FOSS brings with it? I am not an evangelist for FOSS, but in my 20 years of professional experience >90% of OSes, tools, and platforms were and are FOSS :)

    • @sanyika96
      @sanyika96 Месяц назад

      If you're only now figuring this out after 20 years then please resign and never go back to work.

    • @christianlempa
      @christianlempa  Месяц назад +1

      Don't be rude guys, everyone has to start somewhere, even experienced IT guys are beginners in fields they never touched on, don't forget that! ;)
      @mikigurevich4477 thank you so much for the kind words! I'm glad the videos helped you

  • @EduardoRodriguez-fu4ry
    @EduardoRodriguez-fu4ry Месяц назад +1

    Another informative video. Keep it up Christian!

  • @diegoarmendariz1259
    @diegoarmendariz1259 Месяц назад

    Thanks for making this kind of videos, as an cybersecurity student it helps me a lot!

  • @gerardocaceres7997
    @gerardocaceres7997 Месяц назад

    Thanks for sharing! Would like to see more of this!!

  • @marceloantunes1193
    @marceloantunes1193 Месяц назад

    Obrigado!

    • @christianlempa
      @christianlempa  Месяц назад

      Thank you so much for your support ❤️

  •  Месяц назад +4

    What's the point when ClamAV misses about 80% of viruses compared to others?

    • @jacksoncremean1664
      @jacksoncremean1664 Месяц назад

      Use fangfrisch with ClamAV for the better detection.

    • @christianlempa
      @christianlempa  Месяц назад +2

      The point is to learn about the technology, how AV engines work and how to connect it to a SIEM

    • @alecfagan9753
      @alecfagan9753 Месяц назад

      Compared to..? Paid solutions I assume?

  • @henryvanho7971
    @henryvanho7971 Месяц назад

    Thanks Christian for sharing about ClamAV. After setting up ClamAV, I believe it is a bit lacking to demo malware logging solution to log. ClamAV logging format is not normal, no standardized format which ingesting difficult to any SIEM platform. Installation of ClamAV is also a pain to setup. There are over 8 libraries I had to setup on Redhat. After getting ClamAV and ClamDaemon installed and configured, you’ll need to schedule a cron to run scans. ClamAV daemon doesn’t monitor files automatically. Verbose logging is also lagging. ClamAV cannot send logs via remote syslog server.

    • @christianlempa
      @christianlempa  Месяц назад

      That's why you have to pay for a security platform if you want that to work out-of-the-box. With free and open-source tools you sometimes have to fiddle around ;)

  • @RandomUserName92840
    @RandomUserName92840 16 дней назад

    Wazuh provides a pre-built virtual machine image in Open Virtual Appliance (OVA) format. It uses Amazon Linux 2 as the OS.
    It is my understanding that AL2 is basically forked Redhat, but I still feel uneasy running an Amazon rolled OS. How crazy is this? any thoughts?

  • @GrishTech
    @GrishTech Месяц назад +2

    Wazuh is actually really good. I would take sponsored videos that are good content.

  • @joshuaboley4135
    @joshuaboley4135 Месяц назад +1

    Great video! I was already aware of clamav but had never taken it further than the command line. You’ve definitely piqued my interest in Wazuh; I’m curious to see what else we could do with it.

    • @christianlempa
      @christianlempa  Месяц назад

      Awesome! Thank you so much for the feedback :)

  • @---tr9qg
    @---tr9qg Месяц назад

    It was 🔥🔥🔥.

  • @0zzy0zwood
    @0zzy0zwood Месяц назад

    @christianlempa do you have anywhere the config files in a repo or something?
    Also my question is, is it possible to use clamav on a dedicated container/Lxc/VM to scan a few systems or a entire dedicated network?
    Looking for such a solution for my Homelab.

    • @christianlempa
      @christianlempa  Месяц назад

      Sure: github.com/ChristianLempa/boilerplates
      I'm still looking into clamav and containers, I think that's where I need more time researching it

  • @consecratedtech
    @consecratedtech Месяц назад

    Didn't clamAV have some big issue last year? Are they better now? Never heard anything after that report about them fixing anything

  • @ankashk
    @ankashk 9 дней назад

    Does anyone know about Falco Security? Its seems good though and its docker based.

  • @-martintheengineer-7465
    @-martintheengineer-7465 Месяц назад

    Hello Christian. It would be wonderful to get a solution for Spam/AV scanning on WINDOWS 11. I mean, I have Outlook 2019 running on an IMAP mail gate of my DNS provider and Iget SPAM thats not normal. How can I avoid this? Best regards Martin

  • @GdncHfjbdkf
    @GdncHfjbdkf Месяц назад

    Has there been a mitigation on cups yet?

  • @santiago.bassett
    @santiago.bassett 23 дня назад

    👏👏👏

  • @Bob-of-Zoid
    @Bob-of-Zoid 23 дня назад

    First time I ever watched this channel, but I will bite myself in the butt (or try my best to) if Christian isn't German! Well a good indicator he's more likely to know what he is talking about than not.
    On the topic of Clam AV: I think its great 🤫but also still scares me for being so used to Popups, with update notifications, virus and malware warnings, only to tell you you may have a virus, get it wrong often, and has warnings for things it does a poor job at removing without breaking all sorts, or not removing anything at all, even when up to date... and to really do what they say they can do turns out to be mostly just give you a clue, pretending it's doing you a favor, and you end up having to do the most of the removal manually or risk it taking out stuff, and justifying it's price by how well it prevents intrusion while annoying you more than anything else! I have had them from DOS, and all flavors of Windows, home, media pro NT's and all, Up to 7 before I nuked Windows, ditched everything Microsoft, even busted up all install media to have no fallback to pull me away from getting with the Linux program, and forced myself through Linux boot camp! Freakin' best computing decision I ever made!
    The scary part is that I never had even the slightest sign of a virus, nor any other malware, nor even the slightest peep ever from it, which is troubling, because it feels like it's not running at all, and could at least tell me like 4 times a year "Hey I'm still here doing my thing, everything is A-OK,so nothing to worry about, see you in three months"! I don't even know if it has ever found an intrusion, or so good at eliminating them there's no need to bother me with it!?!?!?🧐🤔

  • @loop-0-2
    @loop-0-2 Месяц назад +28

    It’s a shame this whole video is an ad. I’d love to watch an unsponsored video on how to secure my servers

    • @ghangj
      @ghangj Месяц назад +3

      ?

    • @christianlempa
      @christianlempa  Месяц назад +8

      Sponsorships help me to get compensated for the countless hours of researching, planning and producing content that is free to watch for everybody. Without placements, it wouldn't be possible to make all these tutorials.

    • @loop-0-2
      @loop-0-2 Месяц назад +6

      @@christianlempa Of course! That doesn’t change the fact that for the viewer, it’s hard to determine which things from this video you actually agree with, and which you’re paid to say. The word ‘advertisement’ on the screen isn’t very obvious, so I though it good to point this out in the comments. If people want to watch an advertisement, that’s fine with me, but they should know about it.

    • @christianlempa
      @christianlempa  Месяц назад +8

      @@loop-0-2 I never say anything just because I'm paid to do. That's why you never see any advertisement for shady Temu products, or any crappy Homelab gear because I decline these deals. All of it is authentic, but I'm getting paid to make videos about specific topics and tools like Wazuh in this case, but they didn't tell me what exactly I should cover or say.

    • @loop-0-2
      @loop-0-2 Месяц назад +3

      @@christianlempa that’s great to hear, keep up the amazing work, thank you!

  • @canadianwildlifeservice8883
    @canadianwildlifeservice8883 Месяц назад

    Too bad Avira stopped offering AV for Linux. If anything, just use TLS / HTTPS decrypt and scan using Avira through the Sophos Firewall

  • @LexUsamn
    @LexUsamn Месяц назад

    its possible use this one in proxmox?

    • @christianlempa
      @christianlempa  Месяц назад

      I haven't tried it yet, but I think you can install the wazuh agent and clamav on proxmox as well