Building a Blacklist Database in Wazuh - Let's Deploy a Host Intrusion Detection System #12

Поделиться
HTML-код
  • Опубликовано: 9 янв 2025

Комментарии • 5

  • @MohammedYaseen-lz9yi
    @MohammedYaseen-lz9yi 9 месяцев назад

    Can you make a video on Adding Malware hashes and test few of them on new Wazuh version and also Automatic logs Backup syncronization to another location @taylor

  • @crakkajakka15
    @crakkajakka15 3 года назад

    I would assume depending on the size of these list this could be pretty process intensive for the agent to process. Have you found a list limit or length where you start to see performance issues. I.e 1000 items in a list or 10000 items in a list etc.?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  3 года назад

      Hey, ya I am sure that could eventually become an issue, however, I assume these list can grow rather large because I have not ran into that issue yet. I also recommend taking advantage of Cortex and TheHive to gather IP, domain, etc. intelligence as well. This would offload gathering further intelligence from the Wazuh Manager and put that load onto another system. Check out TheHive and Cortex demos here:
      TheHive: ruclips.net/video/VqIuP0AOCBg/видео.html&ab_channel=OpenSecure
      Cortex: ruclips.net/video/qz6xtINwK3I/видео.html&ab_channel=OpenSecure
      Hope that helps and let me know if you have any other questions!

  • @neithaltair4597
    @neithaltair4597 3 года назад

    Thank Youuuuuuuuuuuuuuu !! Genius!.