This is a writeup of Wazuh module on tryhackme. This is in the SOC Level 1 path. » here
ENjoy :)
Wazuh is an opensource XDR and SIEM service
Intro
1
2
3
4
5
6
7
8
9
10
11
12
13
1. When was Wazuh released?
2015
2.
What is the term that Wazuh calls a device that is being monitored for suspicious activity and potential security threats?
agent
3.
Lastly, what is the term for a device that is responsible for managing these devices?
manager
Wazuh agents
1
2
3
4
5
6
7
8
9
1.
How many agents does this Wazuh management server manage?
2
2.
What are the status of the agents managed by this Wazuh management server?
disconnected
Wazuh Vulnerability Assessment & Security Events
1
2
3
4
1.
How many "Security Event" alerts have been generated by the agent "AGENT-001"?
196
1.
What application do we use on Linux to monitor events such as command execution?
auditd
2.
What is the full path & filename for where the aforementioned application stores rules?
/etc/audit/ruled.d/audit.rules