Docker and Wazuh Integration - Let's Build A Host Intrusion Detection System

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ธ.ค. 2024

ความคิดเห็น • 8

  • @andrewa3216
    @andrewa3216 2 ปีที่แล้ว

    Could you please post the docs you use to do these videos and also links to related videos? I jumped into this one and I had no idea how to install wazuh in the configuration that you have in this video... I also have no idea what a wodle is.

  • @dedsec0173
    @dedsec0173 2 ปีที่แล้ว

    very insightful!!, but this is tutorial for docker host i think, and then how to monitor inside container with wazuh ? Thanks!

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      Correct, you could mount a volume to the container that grabs the log files that you want and have your wazuh-agent read that volume mount. I also recommend Falco: github.com/falcosecurity/falco but I plan on covering that soon!
      Thanks for watching :)

  • @LeonardoSkorianez
    @LeonardoSkorianez 3 ปีที่แล้ว

    Very nice videos, keep doing thoses for the ultimate Open Source SIEM :)

  • @SimoneBacciglieriAS
    @SimoneBacciglieriAS 3 ปีที่แล้ว

    Very good video, thank you

  • @s0j0urner15
    @s0j0urner15 2 ปีที่แล้ว

    Windows agents are sending docker events to wazuh