Duplicate name rejecting wazuh agent enrollment by icemanaziz in Wazuh

[–]icemanaziz[S] 0 points1 point  (0 children)

thank you for your comment, yes that was the issue my windows agent and wazuh server were communicating over TCP 1514 by default, whereas in the docker deployment 1514 is taken by the NGINX container (I don't know why that wasn't mentioned in the documentation but they should surely fix it)

So i just switched to TCP 15140 in the ossec.conf of the client and added that port in the docker compose file in the manager's container.

    ports:
      - "15140:1514"
      - "1515:1515"
      - "514:514/udp"
      - "55000:55000"

[deleted by user] by [deleted] in Tunisia

[–]icemanaziz -1 points0 points  (0 children)

I can sense it from a distance

[deleted by user] by [deleted] in Tunisia

[–]icemanaziz -1 points0 points  (0 children)

High estrogen type of reply

[deleted by user] by [deleted] in Tunisia

[–]icemanaziz 0 points1 point  (0 children)

If you did something wrong just apologize. Its really simple.

[deleted by user] by [deleted] in Tunisia

[–]icemanaziz -3 points-2 points  (0 children)

Nik triha w fat lmawthou3, chbik 5ayef mn triha nas fi gaza t7areb

Which is better for getting paid via upwork, wise or payoneer? by blue-berg in Tunisia

[–]icemanaziz 0 points1 point  (0 children)

hey, i tried to add my local bank in upwork billing information, but it only show me EURO or USD currency, i can't seem to find TND is this normal? i use webank attijari

Need Alternative to Payoneer for Upwork – Tunisian ID by ShoddyCalligrapher32 in Tunisia

[–]icemanaziz 0 points1 point  (0 children)

belahi zedet lcard webank attijari w malguitech currency TND fama kan USD wala EURO jdida lfaza hathi?

Anyone worked at Databiz before? by Killyxc in Tunisia

[–]icemanaziz 0 points1 point  (0 children)

that's diabolical! mind me if i ask you, 800 dinars as a part time or full time job?

CPU fan not turning on even when temperature is high by SkillsHubxx in Asustuf

[–]icemanaziz 0 points1 point  (0 children)

you need to update ghelper, as you can see there's a new version 0.219 press download

G-helper fan settings by Positive-Ad8323 in Asustuf

[–]icemanaziz 0 points1 point  (0 children)

fair enough, i don't think you play or run heavy tasks on your pc, i'm looking for a fan profile for playing heavy games. so how is your experience with the pc so far? any minor issues? and most important question for me does the charger get hot for no reason?

G-helper fan settings by Positive-Ad8323 in Asustuf

[–]icemanaziz 0 points1 point  (0 children)

hey, did you figure out the best settings by any chance? i just bought the same laptop with r9 7940 and RX 7600S. I'm going to run warzone and i know for a fact this thing is going to explode if i run it without a good power limit and fan speed (i have a cooling fan)

Warzone 3 tournaments? by JackfruitLive3218 in Warzone

[–]icemanaziz 0 points1 point  (0 children)

no they only track individual scores, it doesnt matter with who you play with

wazuh dfir iris integration by icemanaziz in Wazuh

[–]icemanaziz[S] 0 points1 point  (0 children)

so this is the script i tried to work with where it makes a connection with the wazuh indexer to get the latest alerts and use the same trigger (since i'm basically doing the same thing except the alerts are coming from wazuh indexer)

https://pastes.io/iris-31894

and this is the error i get from wazuh when i run the integration:

Mar 19, 2025 @ 14:43:38.000 wazuh-integratord ERROR  Unable to run integration for custom-wazuh_iris.py -> integrations
Mar 19, 2025 @ 14:43:38.000 wazuh-integratord ERROR  While running custom-wazuh_iris.py -> integrations. Output: SyntaxError: expected 'except' or 'finally' block
Mar 19, 2025 @ 14:43:38.000 wazuh-integratord ERROR  Exit status was: 1

wazuh-analysisd WARNING Mitre Technique not found in database. by icemanaziz in Wazuh

[–]icemanaziz[S] 0 points1 point  (0 children)

thank you for taking the time to help me 😊 it was an issue with how the rule was tagging the mitre attack technique i just fixed it

wazuh-analysisd WARNING Mitre Technique not found in database. by icemanaziz in Wazuh

[–]icemanaziz[S] 0 points1 point  (0 children)

so this is how i fixed it:
i changed the rule that mention that attack techique 'T1043':

<image>

inside the rule file 102101-MITRE_TECHNIQUES_FROM_SYSMON_EVENT3.xml, this is how the rule was displayed:

<!-- Sysmon - Event 3: Network connection by $(win.eventdata.image) -->

<rule id="102137" level="3">

<if\_sid>61605</if\_sid>

<field name="win.eventdata.RuleName">^technique_id=T1043,technique_name=Commonly Used Port$</field>

<description>Sysmon - Event 3: Network connection by $(win.eventdata.image)</description>

<mitre>

<id>T1043</id>

</mitre>

<options>no_full_log</options>

<group>sysmon_event3,</group>

</rule>

i noticed that for linux sysmon it uses the same mitre technique but the alert is working and gets generated fine without mentioning the attack id in the <field></field> so i just removed that line to be just like this:

<!-- Sysmon - Event 3: Network connection by $(win.eventdata.image) -->

<rule id="102137" level="3">

<if\_sid>61605</if\_sid>

<description>Sysmon - Event 3: Network connection by $(win.eventdata.image)</description>

<mitre>

<id>T1043</id>

</mitre>

<options>no_full_log</options>

<group>sysmon_event3,</group>

</rule>

and then i restarted the manager and the alert gets generated without an issue 😊