The Wazuh File Integrity Monitoring (FIM) Use case

Поделиться
HTML-код
  • Опубликовано: 16 ноя 2024

Комментарии • 65

  • @repairstudio4940
    @repairstudio4940 3 месяца назад +15

    Wazuh is awesome! You should do more Wazuh tutorials for those unfamiliar, it'd help save so many ppl's data.
    Absolutely wonderful video man, glad your part of the cyber security community! 🤘🏼😎

    • @MyDFIR
      @MyDFIR  3 месяца назад +3

      Thank you! I will definitely continue to provide tutorials for you all ❤️ thanks for watching.

    • @repairstudio4940
      @repairstudio4940 3 месяца назад

      @@MyDFIR Thank YOU! That's very much appreciated. 🙂

  • @deepaknarayanan3619
    @deepaknarayanan3619 3 месяца назад +6

    One of the most underrated youtuber in cybersecurity domain. Wishing you to reach more subscribers in future as these kinds of contents will be useful for many in this modern technology based society. Appreciate your consistency and determination on making these contents brother. Love from India ❤

    • @MyDFIR
      @MyDFIR  3 месяца назад +1

      Wow, thank you! That means a lot to me ❤️

  • @foxlarr
    @foxlarr 18 дней назад +1

    Wazuh is super tool! Please, make more wazuh tutorials, and thank you for your videos!

    • @MyDFIR
      @MyDFIR  18 дней назад +1

      More to come!

  • @JoycelynJack-rl6ve
    @JoycelynJack-rl6ve 2 месяца назад

    You just won a subscriber.
    This is just what i was looking for all over RUclips.
    Please provide more on both ubuntu and windows os.
    💯🔥

    • @MyDFIR
      @MyDFIR  2 месяца назад

      Thank you!

  • @ravindrapillay4319
    @ravindrapillay4319 3 месяца назад +1

    Awesome job..excellent and clear to understand tutorial

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Glad it was helpful!

  • @SoCyber-n5k
    @SoCyber-n5k 3 месяца назад

    Great video. I got your class course, and I was used Wazuh as additional SiEm tool to monitor on top of Splunk. With the FMI I will have more conf on windows and other OS.
    Thank you again 🎉for

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Awesome!! Thanks for your support and I hope you learned a lot ❤️

    • @SoCyber-n5k
      @SoCyber-n5k 3 месяца назад

      @@MyDFIR I do I do

  • @diegomed3364
    @diegomed3364 3 месяца назад

    Omg!! It was wanderfull. Hopefully you will include in your course

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Thanks!

  • @ronniejust
    @ronniejust 3 месяца назад

    Thanks am learning something from uganda africa

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Nice!

  • @alexpizana6816
    @alexpizana6816 2 месяца назад

    Thank you very much! Amazing video man... I've learned a lot. More videos on Wazuh BTT🙂

    • @MyDFIR
      @MyDFIR  2 месяца назад

      My pleasure 💙

  • @blackcastlemanagementgroup
    @blackcastlemanagementgroup 3 месяца назад

    Loved your video on FIM also!

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Glad you enjoyed it!

  • @wanderer4x4
    @wanderer4x4 2 месяца назад

    Fantastic explanation!! Just subscribed 👍

    • @MyDFIR
      @MyDFIR  2 месяца назад +1

      Awesome, thank you!

  • @Loco4Waffles
    @Loco4Waffles 3 месяца назад

    Fantastic video! I do have two questions: If I have multiple endpoints, how do I easily add custom paths to monitor in FIM? Do I have to manually edit the ossec.conf in every endpoint? Second question: Instead of drilling down to look for an alert in a every single endpoint, does the fim alerts appear in the top/main dashboard?

    • @MyDFIR
      @MyDFIR  2 месяца назад

      You can use a centralized config file documentation.wazuh.com/current/user-manual/reference/centralized-configuration.html and use the alerts dashboard for an overview rather than drilling down into each host

  • @cyberkits93
    @cyberkits93 3 месяца назад

    nice sharing, please share it more

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Thanks for watching!

  • @ianlondon2888
    @ianlondon2888 3 месяца назад

    An updated wazuh installation and configuration vid would be great. Particularly in docker

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Great idea!

  • @blackcastlemanagementgroup
    @blackcastlemanagementgroup 3 месяца назад

    I am loving Wazuh!!!

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Glad to hear!!

  • @j.t.2190
    @j.t.2190 2 месяца назад

    This vid is gold! Ive been using wazuh on a virtual machine for awhile to learn it. Its been great. Specially when poking my windows machine with kali linux and then check wazuh dashboad

    • @MyDFIR
      @MyDFIR  2 месяца назад

      Glad it helped! I’ll definitely put that to the list

  • @jainayrogeorge2924
    @jainayrogeorge2924 2 месяца назад

    More Wazuh content please, im trying to monitor a specific directory on mac but its not working

  • @jimhall9290
    @jimhall9290 3 месяца назад

    This was great and very informative! More Wazuh content, please. This Wazuh update with FIM looks like a great monitoring tool. How does Wazuh compare with Lima Charlie? Which is a more comprehensive security tool and why? Thank you in advance for any info you can provide! 🙂

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Great question! They both have their pros and cons but the main difference here is that LimaCharlie is more modular if that makes sense. It can work with practically any tool. Wazuh is more of a complete solution if tuned/configured properly. If possible, I would use both tools :)

  • @ohlordvoldy
    @ohlordvoldy 3 месяца назад

    Thank you for this!!

    • @MyDFIR
      @MyDFIR  3 месяца назад

      You're so welcome!

  • @joshuampere4327
    @joshuampere4327 3 месяца назад +1

    we need another project with wazuh and caldera

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Oooo 👀👀

  • @nelosboss
    @nelosboss 3 месяца назад

    This is brilliant Steven...but the question I have is this...In a real life scenario how would you install the agent unto the pc to monitor it if it belongs to a staff or is there a way to automatically have it installed by default through active directory or something...Maybe through the office domain and all

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Ive seen this done via GPO, SCCM, or manually via remote support. Really depends on the organization. As per Wazuh documentation “If you are deploying Wazuh in a large environment, with a high number of servers or endpoints, keep in mind that this deployment might be easier using automation tools such as Puppet, Chef, SCCM, or Ansible.”

    • @nelosboss
      @nelosboss 3 месяца назад

      @@MyDFIR Okay...thanks alot brother

  • @netSec360
    @netSec360 3 месяца назад

    Love to see your videos

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Thank you for watching ❤️

  • @alyx3135
    @alyx3135 3 месяца назад

    Hi,
    Would love to know how will you document for learning purposes after performing an attack such as using Atomic Red Team I followed your video and bought your roadmap thanks!

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Completely up to you! Some examples can be to create a step by step on how to setup/execute attacks and/or create a how to document on detecting the attacks you ran. Thanks for the support!

  • @2005sty
    @2005sty 2 месяца назад

    How can i know if wazuh is compromised by hacker? The dashboard ce showed a few File deleted the wazuh manager host device.

  • @JeffPedlow
    @JeffPedlow 3 месяца назад

    This is a great video, thanks for sharing. :)

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Thanks for watching!

  • @jg1000c
    @jg1000c 3 месяца назад

    can all the fim configuration be done centrally in agent.conf? I'm guessing yes.

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Spot on!

  • @maximilian4171
    @maximilian4171 3 месяца назад

    Hello! Quick question, are you running all these methods inside a virtual machine? Cause i'm thinking of creating one through microsoft azure

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Yup! Every lab video I use a VM as it’s easier for clean up when done.

    • @maximilian4171
      @maximilian4171 3 месяца назад

      @@MyDFIR alright, thank you. Will try doing this and exploring some more as an additional to my portfolio.

  • @ferozeworld5234
    @ferozeworld5234 3 месяца назад

    I have one question ccna or comptia network+ which one is best for cybersecurity...

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Both are good and both are optional but you must at the very least, understand networking concepts.

  • @robinjames779
    @robinjames779 3 месяца назад

    Which siem tool best to learn for beginners?

    • @MyDFIR
      @MyDFIR  3 месяца назад +1

      Any free one that you can put your hands on :) Wazuh is great

  • @greenpill810
    @greenpill810 3 месяца назад

    From today, you earned my subscription and I take you as my mentor. please accept me. I love the way you take your time to explain. I would want to implement wazuh in my present organization because we do not have a cyber security team and I would like to break into that space. we have a file server and a domain controller and 3 other member servers. My main question is, ON WHICH SERVER WOULD I INSTALL WAZUH. Hope to get a response.

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Ideally you would spin up another server dedicated to Wazuh.

  • @nullOwl
    @nullOwl 3 месяца назад

    Hey bro,can you do a video on how to integrate wazuh with slack to get real time alerts

    • @MyDFIR
      @MyDFIR  3 месяца назад +1

      Great idea, ill add that into my content list!

  • @Just_A_Tech.._
    @Just_A_Tech.._ 3 месяца назад

    👍