2022/09/29 18:25:22 wazuh-agent: INFO: Received exit signal.
2022/09/29 18:25:22 wazuh-agent: INFO: Set pending exit signal.
2022/09/29 18:25:22 wazuh-modulesd:syscollector: INFO: Stop received for Syscollector.
2022/09/29 18:25:22 wazuh-modulesd:syscollector: INFO: Module finished.
2022/09/29 18:25:22 wazuh-agent: INFO: Exiting...
2022/09/29 18:25:22 wazuh-agent: INFO: (1314): Shutdown received. Deleting responses.
2022/09/29 18:25:23 wazuh-agent: INFO: Using notify time: 10 and max time to reconnect: 60
2022/09/29 18:25:23 wazuh-agent: INFO: (1410): Reading authentication keys file.
2022/09/29 18:25:23 wazuh-agent: INFO: Started (pid: 360).
2022/09/29 18:25:23 wazuh-agent: INFO: Using AES as encryption method.
2022/09/29 18:25:24 wazuh-agent: WARNING: The check_winaudit option is deprecated in favor of the SCA module.
2022/09/29 18:25:24 rootcheck: INFO: Started (pid: 360).
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\comfile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\comfile'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\exefile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\exefile'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\piffile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\piffile'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Directory', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Directory'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Folder', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Folder'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Policies'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Policies'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Security', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Security'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:25:24 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\programdata\microsoft\windows\start menu\programs\startup', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | realtime'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\regedit.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\at.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\attrib.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\cacls.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\cmd.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\drivers\etc', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\eventcreate.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\ftp.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\lsass.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\net.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\net1.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\netsh.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\reg.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\regedt32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\regsvr32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\runas.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\sc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\schtasks.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\sethc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\subst.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\wbem\wmic.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\windowspowershell\v1.0\powershell.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\winrm.vbs', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system.ini', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\at.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\attrib.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\cacls.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\cmd.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\drivers\etc', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\eventcreate.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\ftp.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\net.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\net1.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\netsh.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\reg.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\regedit.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\regedt32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\regsvr32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\runas.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\sc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\schtasks.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\sethc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\subst.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\wbem\wmic.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\windowspowershell\v1.0\powershell.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\winrm.vbs', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\win.ini', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:25:24 wazuh-agent: INFO: (6207): Ignore 'file' sregex '.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$'
2022/09/29 18:25:24 wazuh-agent: INFO: (6206): Ignore 'registry' entry 'HKEY_LOCAL_MACHINE\Security\Policy\Secrets'
2022/09/29 18:25:24 wazuh-agent: INFO: (6206): Ignore 'registry' entry 'HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users'
2022/09/29 18:25:24 wazuh-agent: INFO: (6207): Ignore 'registry' sregex '\Enum$'
2022/09/29 18:25:24 wazuh-agent: INFO: Started (pid: 360).
2022/09/29 18:25:24 wazuh-agent: INFO: Windows version is 6.0 or newer. (Microsoft Windows 7 Professional Service Pack 1 [Ver: 6.1.7601] - Wazuh v4.2.7).
2022/09/29 18:25:24 wazuh-agent: INFO: (1951): Analyzing event log: 'Application'.
2022/09/29 18:25:24 wazuh-modulesd:agent-upgrade: INFO: (8153): Module Agent Upgrade started.
2022/09/29 18:25:24 wazuh-modulesd:ciscat: WARNING: No evals defined. Exiting...
2022/09/29 18:25:24 wazuh-modulesd:syscollector: INFO: Module started.
2022/09/29 18:25:24 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2022/09/29 18:25:24 wazuh-agent: INFO: (1951): Analyzing event log: 'Security'.
2022/09/29 18:25:24 wazuh-agent: INFO: (1951): Analyzing event log: 'System'.
2022/09/29 18:25:24 wazuh-agent: INFO: (1950): Analyzing file: 'C:\Program Files (x86)\ossec-agent\active-response\active-responses.log'.
2022/09/29 18:25:25 wazuh-agent: INFO: Started (pid: 360).
2022/09/29 18:25:25 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2022/09/29 18:25:25 wazuh-agent: INFO: (6000): Starting daemon...
2022/09/29 18:25:25 wazuh-agent: INFO: (6010): File integrity monitoring scan frequency: 43200 seconds
2022/09/29 18:25:25 wazuh-agent: INFO: (6008): File integrity monitoring scan started.
2022/09/29 18:25:25 rootcheck: INFO: Starting rootcheck scan.
2022/09/29 18:25:30 rootcheck: INFO: Ending rootcheck scan.
2022/09/29 18:25:39 wazuh-agent: INFO: (6009): File integrity monitoring scan ended.
2022/09/29 18:25:39 wazuh-agent: INFO: (6012): Real-time file integrity monitoring started.
2022/09/29 18:31:31 wazuh-agent: ERROR: (1137): Lost connection with manager. Setting lock.
2022/09/29 18:31:32 wazuh-agent: ERROR: (1216): Unable to connect to '
192.168.160.147:1514/tcp': 'No connection could be made because the target machine actively refused it.'.
2022/09/29 18:31:43 wazuh-agent: ERROR: (1216): Unable to connect to '
192.168.160.147:1514/tcp': 'No connection could be made because the target machine actively refused it.'.
2022/09/29 18:31:53 wazuh-agent: INFO: Server responded. Releasing lock.
2022/09/29 18:32:32 wazuh-agent: INFO: Received exit signal.
2022/09/29 18:32:32 wazuh-agent: INFO: Set pending exit signal.
2022/09/29 18:32:32 wazuh-modulesd:syscollector: INFO: Stop received for Syscollector.
2022/09/29 18:32:32 wazuh-modulesd:syscollector: INFO: Module finished.
2022/09/29 18:32:32 wazuh-agent: INFO: Exiting...
2022/09/29 18:32:32 wazuh-agent: INFO: (1314): Shutdown received. Deleting responses.
2022/09/29 18:32:33 wazuh-agent: INFO: Using notify time: 10 and max time to reconnect: 60
2022/09/29 18:32:34 wazuh-agent: INFO: (1410): Reading authentication keys file.
2022/09/29 18:32:34 wazuh-agent: INFO: Started (pid: 3712).
2022/09/29 18:32:34 wazuh-agent: INFO: Using AES as encryption method.
2022/09/29 18:32:34 wazuh-agent: WARNING: The check_winaudit option is deprecated in favor of the SCA module.
2022/09/29 18:32:34 rootcheck: INFO: Started (pid: 3712).
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\comfile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\comfile'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\exefile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\exefile'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\piffile', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\piffile'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Directory', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Directory'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Folder', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Folder'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Policies'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Policies'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Security', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Security'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components [x64]', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6002): Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components', with options 'size | permissions | owner | group | mtime | hash_md5 | hash_sha1 | hash_sha256'
2022/09/29 18:32:34 wazuh-agent: INFO: (6356): Maximum file size limit to generate diff information configured to '51200 KB' for 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\programdata\microsoft\windows\start menu\programs\startup', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | realtime'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\regedit.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\at.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\attrib.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\cacls.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\cmd.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\drivers\etc', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\eventcreate.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\ftp.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\lsass.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\net.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\net1.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\netsh.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\reg.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\regedt32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\regsvr32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\runas.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\sc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\schtasks.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\sethc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\subst.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\wbem\wmic.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\windowspowershell\v1.0\powershell.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\sysnative\winrm.vbs', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system.ini', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\at.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\attrib.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\cacls.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\cmd.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\drivers\etc', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\eventcreate.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\ftp.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\net.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\net1.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\netsh.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\reg.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\regedit.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\regedt32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\regsvr32.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\runas.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\sc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\schtasks.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\sethc.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\subst.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\wbem\wmic.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\windowspowershell\v1.0\powershell.exe', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\system32\winrm.vbs', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6003): Monitoring path: 'c:\windows\win.ini', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | attributes | scheduled'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6207): Ignore 'file' sregex '.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$'
2022/09/29 18:32:34 wazuh-agent: INFO: (6206): Ignore 'registry' entry 'HKEY_LOCAL_MACHINE\Security\Policy\Secrets'
2022/09/29 18:32:34 wazuh-agent: INFO: (6206): Ignore 'registry' entry 'HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users'
2022/09/29 18:32:34 wazuh-agent: INFO: (6207): Ignore 'registry' sregex '\Enum$'
2022/09/29 18:32:34 wazuh-agent: INFO: Started (pid: 3712).
2022/09/29 18:32:34 wazuh-agent: INFO: Windows version is 6.0 or newer. (Microsoft Windows 7 Professional Service Pack 1 [Ver: 6.1.7601] - Wazuh v4.2.7).
2022/09/29 18:32:34 wazuh-agent: INFO: (1951): Analyzing event log: 'Application'.
2022/09/29 18:32:34 wazuh-agent: INFO: (1951): Analyzing event log: 'Security'.
2022/09/29 18:32:34 wazuh-modulesd:agent-upgrade: INFO: (8153): Module Agent Upgrade started.
2022/09/29 18:32:34 wazuh-modulesd:ciscat: WARNING: No evals defined. Exiting...
2022/09/29 18:32:34 wazuh-agent: INFO: (1951): Analyzing event log: 'System'.
2022/09/29 18:32:34 wazuh-agent: INFO: (6000): Starting daemon...
2022/09/29 18:32:34 wazuh-agent: INFO: (6010): File integrity monitoring scan frequency: 43200 seconds
2022/09/29 18:32:34 wazuh-agent: INFO: (6008): File integrity monitoring scan started.
2022/09/29 18:32:34 rootcheck: INFO: Starting rootcheck scan.
2022/09/29 18:32:34 wazuh-agent: INFO: (1950): Analyzing file: 'C:\Program Files (x86)\ossec-agent\active-response\active-responses.log'.
2022/09/29 18:32:35 wazuh-modulesd:syscollector: INFO: Module started.
2022/09/29 18:32:35 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2022/09/29 18:32:35 wazuh-agent: INFO: Started (pid: 3712).
2022/09/29 18:32:35 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2022/09/29 18:32:40 rootcheck: INFO: Ending rootcheck scan.
2022/09/29 18:32:53 wazuh-agent: INFO: (6009): File integrity monitoring scan ended.
2022/09/29 18:32:53 wazuh-agent: INFO: (6012): Real-time file integrity monitoring started.