Wazuh Active Response and AbuseIPDB - Dynamically Block Known Malicious IPs with Wazuh

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ม.ค. 2025

ความคิดเห็น • 9

  • @marciolima174
    @marciolima174 2 ปีที่แล้ว +2

    All your videos are great!
    I'm waiting for the next one, I would like you to do a talking about how I can manage the logs so as not to compromise the size of the disk.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว +1

      Check out one of my previous videos where we covered log rotation : th-cam.com/video/jvFUdtMqe8U/w-d-xo.html

  • @dcj4332
    @dcj4332 8 หลายเดือนก่อน

    wonderful video. i love the way you explain the actions you take.

  • @oscarmarte4850
    @oscarmarte4850 2 ปีที่แล้ว +1

    I love it, it's going a little bit beyond detection with abuseipdb (previous video), including blocking. Good and detailed explanation. How about making an integration video with wazuh, some opensource antiransomware for windows (Yjesus/antiransomware on github, or any other), or also some opensource edr. I can also think of any opensource antiddos integration? I have seen almost all the videos of wazuh and I have assembled it in my house. Thanks for entertaining me on weekends!!!

  • @JonathanRoy93
    @JonathanRoy93 ปีที่แล้ว

    Why are my iptables not showing the IP addresses that have been added? Does this have any effect because my firewall is turned off? the activity in integration. log is running, but the event in Wazuh is not showing. Wazuh manager is installed on CentOS 7.

  • @justSamadhi
    @justSamadhi 2 ปีที่แล้ว

    Can you tell how do the same for Windows?

  • @numanmaavia8575
    @numanmaavia8575 2 ปีที่แล้ว

    Great video

  • @ghaem51
    @ghaem51 2 ปีที่แล้ว

    your voice has a problem in this video

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว +2

      Ya, sorry about that. Will have that cleaned up for next video. Thanks for watching anyways :)