

--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/f0774835-69da-4910-b3cf-a3c06f810eabn%40googlegroups.com.
# auditctl -l-w /etc/passwd -p wa -k passwd_changes-w /sbin/insmod -p x -k module_insertion-a always,exit -F arch=b32 -S unlink,rename,unlinkat,renameat -F auid>=500 -F auid!=-1 -F key=delete-a always,exit -F arch=b64 -S rename,unlink,unlinkat,renameat -F auid>=500 -F auid!=-1 -F key=delete-a always,exit -S setresuid -F euid=0 -F key=audit-wazuh-c-a always,exit -F arch=b32 -S execve -F egid!=994 -F auid!=-1 -F key=audit-wazuh-c-a always,exit -F arch=b64 -S execve -F egid!=994 -F auid!=-1 -F key=audit-wazuh-c-w /bin -p wa -k wazuh_fim-w /boot -p wa -k wazuh_fim-w /etc -p wa -k wazuh_fim-w /etc/cron.d -p wa -k wazuh_fim-w /etc/cron.daily -p wa -k wazuh_fim-w /etc/cron.hourly -p wa -k wazuh_fim-w /etc/cron.monthly -p wa -k wazuh_fim-w /etc/cron.weekly -p wa -k wazuh_fim-w /etc/crontab -p wa -k wazuh_fim-w /home -p wa -k wazuh_fim-w /root -p wa -k wazuh_fim-w /sbin -p wa -k wazuh_fim-w /usr/bin -p wa -k wazuh_fim-w /usr/sbin -p wa -k wazuh_fim
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/f852526e-b861-44d5-a240-5208abcc0d59n%40googlegroups.com.
local_rules.xml, as seen here:
wazuh-logtest output from me trying to trigger that rule:Starting wazuh-logtest v4.3.9Type one log per linetype=CONFIG_CHANGE msg=audit(1667871080.337:40052): op=set audit_pid=19778 old=16601 auid=4294967295 ses=4294967295 subj==unconfined res=0^]AUID="unset"**Phase 1: Completed pre-decoding.full event: 'type=CONFIG_CHANGE msg=audit(1667871080.337:40052): op=set audit_pid=19778 old=16601 auid=4294967295 ses=4294967295 subj==unconfined res=0AUID="unset"'**Phase 2: Completed decoding.name: 'auditd'parent: 'auditd'audit.res: '0AUID="unset"'audit.type: 'CONFIG_CHANGE'**Phase 3: Completed filtering (rules).id: '80705'level: '3'description: 'Auditd: Configuration changed.'groups: '['audit', 'audit_configuration']'firedtimes: '1'gdpr: '['IV_30.1.g']'gpg13: '['10.1']'mail: 'False'**Alert to be generated.
{"options": {"config_plugin": "filesystem","logger_plugin": "filesystem","logger_path": "/var/log/osquery","disable_logging": "false","pidfile": "/var/osquery/osquery.pidfile","disable_events": "false","disable_audit": "false","audit_allow_config": "true","audit_persist": "true","audit_allow_process_events": "true","audit_allow_fim_events": "true","audit_allow_user_events": "true","audit_allow_sockets": "true","schedule_splay_percent": "10","database_path": "/var/osquery/osquery.db","utc": "true","worker_threads": "3"},
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAKVKe60D%3DA-m%3DoFCpp-MdKM%3DbDtGidvOmx5YxwsoFky6wYeOyw%40mail.gmail.com.
(sidenote: do you need to reload the wazuh-manager service before you can test rule changes using wazuh-logtest? I've been restarting it but I'm not sure if it's needed).
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAKVKe636wLi%3DJBvW9PZQ-UqzEZQoYgUjuwE9CC-OvgxgzyHbpg%40mail.gmail.com.