Hi Yana.
I looked at the sysmon and active response modules.
I looked at the things you are planning on working on. I don't see anything in there expanding this capability (endpoint process and network monitoring/termination). Is it something that doesn't fit within the project goals of Wazuh and should be handled by a different tool?
thanks,
Geoff
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2e999698-075b-43f8-b6c5-2f8d1835d5e4n%40googlegroups.com.
Hi.
Are people then relying on AV/NGAV to manage the local malware
and actively shut it down?
thanks,
Geoff
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/8cd8b269-7a6c-4dd1-9bf7-69d3e0113411n%40googlegroups.com.