WAZUH - File Integrity Monitoring (FIM)

แชร์
ฝัง
  • เผยแพร่เมื่อ 27 ก.ย. 2024
  • #fileintegrity #wazuh #fileintegritymonitoring #fim
    How to Setup File Integrity Monitoring - Monitor your critical servers using file integrity monitoring feature of Wazuh.
    Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response and compliance.
    Feature Like
    1. Security Analytics
    2. Intrusion Detection
    3. Log Data Analysis
    4. File Integrity Monitoring
    5. Vulnerability Detection
    6. Configuration Assessment
    7. Incident Response
    8. Regulatory Compliance
    9. Cloud Security
    10. Containers Security
    Wazuh - wazuh.com/
    Wazuh Ova Download (Version 3.12) - documentation.....
    Wazuh Agent Download - documentation....
    Wazuh FIM - documentation....
    Wazuh Setup Video - • Setup Wazuh - Open Sou...
    UpBrightSkills Blogs - www.upbrightsk...

ความคิดเห็น • 28

  • @naseraslam92
    @naseraslam92 2 ปีที่แล้ว +3

    Nice Video. Keep it up, These videos are helpful for us. Thanks!

  • @symnrari
    @symnrari 3 ปีที่แล้ว +3

    Hi, It's very good video it works for me .

  • @nurbekkoblanov5103
    @nurbekkoblanov5103 3 ปีที่แล้ว +3

    Hello sir
    the centralized configuration will take preference and override the local configuration. Do i need to change this settings in local or in the manager? if i set real time only in one directoris it will send logs immediately to the manager? and the others directory will be checked every 12 hours>

    • @UpBrightSkills
      @UpBrightSkills  3 ปีที่แล้ว

      Central configuration will take precedence. You can define the central agent based configuration in agent.conf file for respective agent group.

  • @indramayathanait8806
    @indramayathanait8806 4 ปีที่แล้ว +2

    I have one question. Rule to detect brute force attack in windows agent please give me solution

    • @UpBrightSkills
      @UpBrightSkills  4 ปีที่แล้ว +1

      You can use Kibana dashboard to grab the alerts.
      documentation.wazuh.com/3.12/learning-wazuh/rdp-brute-force.html?highlight=brute%20force%20attack

    • @indramayathanait8806
      @indramayathanait8806 4 ปีที่แล้ว

      @@UpBrightSkills how can this output should alert in email. I have little problem alerting this output to my mail.

  • @tanaypatil6751
    @tanaypatil6751 2 ปีที่แล้ว +1

    Sir please make videos on "THREAT DETECTION AND RESPONSE in WAZUH"

    • @UpBrightSkills
      @UpBrightSkills  2 ปีที่แล้ว +1

      Yes it is in pipeline will be uploading video soon

  • @srich9382
    @srich9382 ปีที่แล้ว

    How do configure email alert. Can you please make a video for this.

  • @SuperChelseaSW6
    @SuperChelseaSW6 4 ปีที่แล้ว

    Nice vid sir. I have a question. My cluster has a yellow health .I have only one machine running elasticsearch.so I want to add another node , how do I figure out? Thanks!

  • @chungdutshering-cr4ju
    @chungdutshering-cr4ju 6 หลายเดือนก่อน

    Hello, Is it possible to show IP address of the other users on FIM wazuh running on windows server?

  • @HammadAshaq
    @HammadAshaq ปีที่แล้ว +1

    can i use it as a final year project of cyber security
    ????
    if not tell me how i make integerity cheaker project

    • @UpBrightSkills
      @UpBrightSkills  7 หลายเดือนก่อน

      Yes you can use it for final year project, making and integrity cheaker is very easy with Wazuh.

  • @RavindraRaivlogs
    @RavindraRaivlogs 3 ปีที่แล้ว

    follow your video step but still not show dashboard please help me why
    my OS is linux ubuntu

    • @UpBrightSkills
      @UpBrightSkills  3 ปีที่แล้ว

      Which dashboard you are talking about sir.

    • @Ravindrakumar-xo1jm
      @Ravindrakumar-xo1jm 3 ปีที่แล้ว

      @@UpBrightSkills
      no
      43200
      yes
      yes
      no
      /etc,/usr/bin,/usr/sbin
      /bin,/sbin,/boot
      /root/npst
      NOTE:- only i have change add this line because i create directory npst /root/npst

    • @Ravindrakumar-xo1jm
      @Ravindrakumar-xo1jm 3 ปีที่แล้ว

      ravindra kumar is also npst noida

    • @Ravindrakumar-xo1jm
      @Ravindrakumar-xo1jm 3 ปีที่แล้ว

      i am talking about file integrity dasboard

  • @lavishjhamb3521
    @lavishjhamb3521 4 ปีที่แล้ว +1

    Does it support real-time monitoring?

    • @UpBrightSkills
      @UpBrightSkills  4 ปีที่แล้ว +1

      Yes, It Support real-time monitoring and will also send alerts based on the rules which you configure.

    • @lavishjhamb3521
      @lavishjhamb3521 4 ปีที่แล้ว

      @@UpBrightSkills How does it do the real time monitoring - Does it hook the kernel directly or leverage the syslog service?

    • @ab866
      @ab866 3 ปีที่แล้ว

      @@lavishjhamb3521 You can use Syslog or API integration for firewall devices and for Kernel level you can enable the "Kernel Module".

  • @SuperChelseaSW6
    @SuperChelseaSW6 4 ปีที่แล้ว +1

    Policy monitoring and pci-dss are interesting demos.

  • @ebrahima3611
    @ebrahima3611 3 ปีที่แล้ว

    Thanks for the video.. I followed exact the same steps but no idea why it shows [There are no results] on Kibana integrity monitoring dashboard!

  • @wambanguemo6457
    @wambanguemo6457 2 ปีที่แล้ว +1

    Thanls for This Video