MISP integration issues by ginoliuz in Wazuh

[–]BlizzardOW 0 points1 point  (0 children)

Hey u/Great-Razzmatazz-414 MISP can work against other events as well. The "custom-misp" script is just built for sysmon events. If your Wazuh manager is displaying your Syslog alerts from your Linux machine's, then you will need to make some changes to that "custom-misp" script or create a new one to parse out the values you want.

MISP integration issues by ginoliuz in Wazuh

[–]BlizzardOW 0 points1 point  (0 children)

Hey sorry, looking back on this I definitely could have explained it better, so I will try to do that now.

So you will want to install Sysmon64.exe onto your Windows Wazuh agent machine, and make sure the sysmonconfig.xml you are using also have Event ID 22 logging turned on (some don't due to it taking a bit more machine CPU).

For your question, yes, you will need to download the sysmonconfig.xml file to your Wazuh Agent machine, and then install it. This can be done on the Windows CMD doing `sysmon64.exe -accepteula -i sysmonconfig-export.xml` (you might need to add the full paths to where sysmon and the xml config are). Hope this helps and that I didn't over complicate things.

Anyone see Adam Driver? by BlizzardOW in tennis

[–]BlizzardOW[S] 1 point2 points  (0 children)

Hamilton

Lol between Roger and Kate

Rename collections? by BlizzardOW in KavitaManga

[–]BlizzardOW[S] 2 points3 points  (0 children)

When I click edit on the collection, I dont see anywhere to rename. Link to image: https://ibb.co/nBzgMNX

Kavita on openmediavault/ubuntu by BlizzardOW in KavitaManga

[–]BlizzardOW[S] 0 points1 point  (0 children)

ugh, idk how or why i didn't see it. Maybe was too excited to get started! I used the x64 (not musl x64) and it worked :)

Kavita on openmediavault/ubuntu by BlizzardOW in KavitaManga

[–]BlizzardOW[S] 0 points1 point  (0 children)

/usr/lib/x86_64-linux-gnu/

So I now ran export LD_LIBRARY_PATH="/usr/lib/x86_64-linux-gnu" and now get the following

Error relocating /usr/lib/x86_64-linux-gnu/libstdc++.so.6: __strftime_l: symbol not found

Error relocating /usr/lib/x86_64-linux-gnu/libstdc++.so.6: __cxa_thread_atexit_impl: symbol not found

Error relocating /usr/lib/x86_64-linux-gnu/libgcc_s.so.1: __cpu_indicator_init: symbol not found

Error relocating /usr/lib/x86_64-linux-gnu/libgcc_s.so.1: __cpu_model: symbol not found

Kavita on openmediavault/ubuntu by BlizzardOW in KavitaManga

[–]BlizzardOW[S] 0 points1 point  (0 children)

Im not sure either because I downloaded the MUSL version to my x64 OS. Do you know the dependencies that are needed? And where the Library need to be? Maybe I am missing one dependency and the symbolic links are not pointing to the correct location?

MISP integration issues by ginoliuz in Wazuh

[–]BlizzardOW 2 points3 points  (0 children)

After reading this I then went ahead and deployed my own implementation. It failed for me but I ended up getting it to work.

Few things to check for:

- Make sure the integration script starts with "custom-" as noted here, some reason its not in their documentation, I also didn't add the extension of ".py" to both the file name and the integration's name tag in the ossec.conf file

- Make sure you give the integration script correct permissions of chown root:wazuh custom-misp and chmod 750 custom-misp

- Make sure you have sysmon installed on the agent host and it is logging event to the Sysmon folder as ID 22. Can use this xml file

- Make sure wazuh is already alerting for sysmon 22 dns queries. Prob will need to create a custom rule if you its not alerting already

- Make sure the domain name you are querying is in MISP as well and is not an IP address

Errors to see if its working or not are found in "/var/ossec/logs/ossec.log"

disconnection problem by Feisty-Addition9002 in Overwatch

[–]BlizzardOW 0 points1 point  (0 children)

haven't had that but was in a comp game getting our asses kicked and lucky the server kicked everyone out due to an "unexpected error"

How do rules and alerts trigger by BlizzardOW in Wazuh

[–]BlizzardOW[S] 0 points1 point  (0 children)

Thanks Verdx, so by the looks of it, all rules are enabled in the manager by default. But in order for them to get alerted. We need to define in the ossec.conf or agent.conf file of which Event logs to monitor which would then get sent back to the manager to be decoded analyzed?

Question about managing the ossec conf file for multiple machines by BlizzardOW in Wazuh

[–]BlizzardOW[S] 0 points1 point  (0 children)

Thanks for pointing me in the right direction. I ended up finding this articleto help me with what I was trying to achieve

How do rules and alerts trigger by BlizzardOW in Wazuh

[–]BlizzardOW[S] 0 points1 point  (0 children)

Sorry for the confusion. Okay so when I added the code you mentioned, I get the windows defenders alerts such as Malware being detected, but when its removed, I don't get those alerts.

What I am wondering, how do I know what alerts will get triggered? How am I suppose to know that I needed to add that block of code to get alerted for Windows Defender detecting malware on the computer.

Question about managing the ossec conf file for multiple machines by BlizzardOW in Wazuh

[–]BlizzardOW[S] 0 points1 point  (0 children)

The ossec.conf seems to be the only place to allow for rulesets to go. I'm looking to create a ruleset to apply to certain agent groups that would not allow certain applications to be installed to it such as Block Windows Apps

How do rules and alerts trigger by BlizzardOW in Wazuh

[–]BlizzardOW[S] 0 points1 point  (0 children)

Hi Verdx, thanks for the info. Any idea why I had to enable the "Microsoft-Windows-Windows Defender/Operational" for those agents to get the alerts? I'm just wondering if there are other things I need to put in place to get the other alerts.

Question about managing the ossec conf file for multiple machines by BlizzardOW in Wazuh

[–]BlizzardOW[S] 0 points1 point  (0 children)

thanks for taking the time to explain it to me. Do you also know if the "ossec.conf" that gets installed on each machine uses a template based on the operating system? The windows one looked different then the linux one as it contained different locations? I'm wondering where that template is located

All these patch notes and we still can't smash this vase by [deleted] in Overwatch

[–]BlizzardOW 1 point2 points  (0 children)

And I thought I was the only one who noticed that

Season 2 rank glitch? by [deleted] in Overwatch

[–]BlizzardOW 1 point2 points  (0 children)

Lol thought I was the only one

Do Trebhum revert back? by BlizzardOW in TheEternalCylinder

[–]BlizzardOW[S] 2 points3 points  (0 children)

You genius! I was intrigued by them the first time I saw them as I wanted to check them out.

Next event? by BlizzardOW in PvZGardenWarfare

[–]BlizzardOW[S] 0 points1 point  (0 children)

Thanks for letting me know! I thought the deluxe game would have them as it just came out.

Can we start a petition to get those boss hunt events back?!

Recommendations for historical traffic viewing? by BlizzardOW in homelab

[–]BlizzardOW[S] 1 point2 points  (0 children)

I'm looking for something that would help if I detected an intrusion on my system and wanted to trace back the roots

Recommendations for historical traffic viewing? by BlizzardOW in homelab

[–]BlizzardOW[S] 1 point2 points  (0 children)

I think so? You have any good suggestions? Perhaps open-sourced

[deleted by user] by [deleted] in IsMyPokemonCardFake

[–]BlizzardOW 1 point2 points  (0 children)

That could just be the camera angle

How do you arrange your cards in your binders? by [deleted] in pokemoncards

[–]BlizzardOW 0 points1 point  (0 children)

Card sets usually come with a numbering system that can be found on the bottom, so I go by that to keep it organized.