> On Nov 13, 2019, at 6:17 AM, dan (ddp) <
ddp...@gmail.com> wrote:
>
> On Thu, Nov 7, 2019 at 11:16 AM bill evergreen <
bill.ev...@gmail.com> wrote:
>>
>> Hello list,
>>
>> does Ossec alert if there are processes running without a binary on disk?
>>
>> Thank's a lot for any feedback
>>
>
> I don't think there's any rules for this.
>
>> Bill
>>
I believe you can use Osquery for this. You can integrate Osquery with Wazuh.