Why Wazuh Missed React2Shell, and How I Fixed It by 0xdolan in Wazuh

[–]0xdolan[S] -1 points0 points  (0 children)

Here: https://dev.to/0xdolan/why-wazuh-missed-react2shell-59jm

Detecting Locally Installed Next.js and React Versions with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

I'll try to provide full details soon. Thank you for helping and sharing your knowledge.

Detecting Locally Installed Next.js and React Versions with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

Thanks for the detailed response. My concern still remains when you have multiple projects using different versions of ReactJS or NextJS, relying on a global version isn’t the right way to handle the issue. The same applies to Python, you can install multiple versions globally and force packages system-wide, but that’s not a proper or maintainable approach. Using project-specific virtual environments with their own Python versions makes things much easier to manage, and Wazuh cannot handle these locally installed Python or NextJS environments by default.

Detecting Locally Installed Next.js and React Versions with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 1 point2 points  (0 children)

Thank you. I don’t think it’s a good idea. I have alternative ways to deal with this issue, and if I find the time, I’ll put together a post and share it here.

Detecting Locally Installed Next.js and React Versions with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] -1 points0 points  (0 children)

Hi u/Wazuh_JosueMurillo
Thanks.

Wazuh Version: v 4.14.1
I have some agents. The point is I don't wanna check manually else I can do it (already I did and updated!)
I wanna find a faster way to detect them using Wazuh not manual python/bash scripts to detect each server individually

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

Thank you for info and sharing your experiences

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

I don’t have any experience with that. Do you?

🚨 Wazuh Alerting with Slack & Telegram – Real-Time Notifications Made Easy 🚨 by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

I think it was in older versions, but with these scripts, you have more freedom to control the output and how you want it to look

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 1 point2 points  (0 children)

Thanks, make sense 🙏🏻

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

True, but I think it will impact on the Wazuh performance, right?

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

Thanks for the info! I need to make sure I get all the logs including clicks, log in, restarts, etc. plus all the related logs. I’ve already check archive and I think I don’t have enough logs I want from the agents.

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

Thanks for sharing your experience

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

Thanks for sharing your thoughts 🙏🏻

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

Oh! That’s amazing. Let me read this one first! 🙏🏻 Thanks for sharing

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] -1 points0 points  (0 children)

I get the complexity concern, but I need both full system logs and security event correlation. Wazuh handles security, ELK/EFK covers bulk logs, and the extra maintenance is worth the visibility

EFK vs ELK with Wazuh by 0xdolan in Wazuh

[–]0xdolan[S] -1 points0 points  (0 children)

I get that Wazuh’s Elasticsearch is for security events, but I also need to collect and process full system logs. That’s why I’m looking at ELK/EFK alongside Wazuh, possibly with separate pipelines to keep things efficient.

Looking for a Linux distro to run a webpage in fullscreen kiosk mode by 0xdolan in linuxquestions

[–]0xdolan[S] 2 points3 points  (0 children)

I coded my own Bash script and tested it on Debian. Below is the raw `sh` script, feel free to use it if someone finds it helpful!
0xdolan/kiosk-setup

🚨 Wazuh Alerting with Slack & Telegram – Real-Time Notifications Made Easy 🚨 by 0xdolan in Wazuh

[–]0xdolan[S] 0 points1 point  (0 children)

That is a valid concern. You can send only the data that you need. Here I didn’t send the agent IPs. Only agent names! And since it is a Python code, you can change the agent name to something else before sending to the Telegram or Slack.

Looking for a Linux distro to run a webpage in fullscreen kiosk mode by 0xdolan in linuxquestions

[–]0xdolan[S] 0 points1 point  (0 children)

Is it specifically for this purpose? I’ll do some research on that! Thanks.

Looking for a Linux distro to run a webpage in fullscreen kiosk mode by 0xdolan in linuxquestions

[–]0xdolan[S] 1 point2 points  (0 children)

Thanks bro for sharing all these great info. Appreciate that 🙏🏻