Wazuh Active Response and AbuseIPDB - Dynamically Block Known Malicious IPs with Wazuh

Поделиться
HTML-код
  • Опубликовано: 3 фев 2025

Комментарии • 9

  • @marciolima174
    @marciolima174 2 года назад +2

    All your videos are great!
    I'm waiting for the next one, I would like you to do a talking about how I can manage the logs so as not to compromise the size of the disk.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад +1

      Check out one of my previous videos where we covered log rotation : ruclips.net/video/jvFUdtMqe8U/видео.html

  • @dcj4332
    @dcj4332 10 месяцев назад

    wonderful video. i love the way you explain the actions you take.

  • @oscarmarte4850
    @oscarmarte4850 2 года назад +1

    I love it, it's going a little bit beyond detection with abuseipdb (previous video), including blocking. Good and detailed explanation. How about making an integration video with wazuh, some opensource antiransomware for windows (Yjesus/antiransomware on github, or any other), or also some opensource edr. I can also think of any opensource antiddos integration? I have seen almost all the videos of wazuh and I have assembled it in my house. Thanks for entertaining me on weekends!!!

  • @JonathanRoy93
    @JonathanRoy93 Год назад

    Why are my iptables not showing the IP addresses that have been added? Does this have any effect because my firewall is turned off? the activity in integration. log is running, but the event in Wazuh is not showing. Wazuh manager is installed on CentOS 7.

  • @numanmaavia8575
    @numanmaavia8575 3 года назад

    Great video

  • @justSamadhi
    @justSamadhi 2 года назад

    Can you tell how do the same for Windows?

  • @ghaem51
    @ghaem51 3 года назад

    your voice has a problem in this video

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад +2

      Ya, sorry about that. Will have that cleaned up for next video. Thanks for watching anyways :)