Windows Defender and Wazuh! - Forward Windows Defender Logs to Wazuh

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ม.ค. 2025

ความคิดเห็น • 18

  • @FailedSquare
    @FailedSquare ปีที่แล้ว +3

    quick and easy, thanks for not wasting my time

  • @ikersolozabal
    @ikersolozabal ปีที่แล้ว +1

    Thanks for the video it's great

  • @LeonardoSkorianez
    @LeonardoSkorianez 3 ปีที่แล้ว

    Very good video, now only think I miss is a kibana dashboard with ClamAV/Defender information

  • @MOSH90
    @MOSH90 2 ปีที่แล้ว

    Thank you so much for all your content! It has been a great learning curve and experience. A question - I currently have sysmon monitoring enabled, and when I tried to add this configuration for Windows Defender event channel, my agents were not sending any events to Wazuh. Anything I may have missed, or does Wazuh not support multiple event channels on a group agent configuration?

  • @naseraslam92
    @naseraslam92 2 ปีที่แล้ว

    Thanks, Nice video.

  • @farrasfauzan8095
    @farrasfauzan8095 ปีที่แล้ว

    good video.
    how about another antivirus? maybe like a trendmicro or something else?

  • @hamzamezo7422
    @hamzamezo7422 2 ปีที่แล้ว

    Thanks . it works like a charm 👌is there a possibility to send only errors and warning alerts?

  • @brunoisy
    @brunoisy ปีที่แล้ว

    Thanks!

  • @hayubelajarbareng
    @hayubelajarbareng 3 ปีที่แล้ว

    Thanks, please create a video log symantec enpoint to wazuh

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  3 ปีที่แล้ว

      Hey, unfortunately I don’t have a subscription to Symantec and I do not see a free trial available on their website. Do you know of anything I could take advantage of to complete a demo with Symantec?

    • @wolfteeth6049
      @wolfteeth6049 3 ปีที่แล้ว

      Symantec server allows to send syslog, it could be done on SEPM directly.

  • @numanmaavia8575
    @numanmaavia8575 3 ปีที่แล้ว

    Thanks for informative lecture,,,,
    Please create a video how to fetch azure activity log into Wazuh, I hope you will create
    Thanks

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  3 ปีที่แล้ว +1

      Hey Numan, I attempted to the other day but Azure requires a premiere license to make the API calls to O365 to collect activity logs. I tried a trial but unfortunately it was the same result....I will keep exploring and let you know what I find.

    • @numanmaavia8575
      @numanmaavia8575 3 ปีที่แล้ว

      @@taylorwalton_socfortress Thanks alot for your effort..

  • @calvinnguyen1699
    @calvinnguyen1699 2 ปีที่แล้ว

    How about kaspersky

  • @marciolima174
    @marciolima174 3 ปีที่แล้ว

    Need to create the client_buffer?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  3 ปีที่แล้ว +1

      Hey Marcio, you should not have to make any client buffer changes, but if the endpoint you are looking to collect these logs from is already sending a high volume of logs, you can increase the amount of logs collected with the client buffer setting: documentation.wazuh.com/current/user-manual/reference/ossec-conf/client_buffer.html
      Hope that helps!

  • @localadm
    @localadm 7 หลายเดือนก่อน

    wazuh name is like 'whatsup', not 'wazoo'. good piece of software with an unfortunate name to pronounce.