PoC Windows netsh alienvault

32 views
Skip to first unread message

Bob Barrett

unread,
Sep 26, 2026, 12:57:47 PM (5 days ago) Sep 26
to Wazuh | Mailing List
Hello,

I set up a lab to test https://documentation.wazuh.com/current/proof-of-concept-guide/block-malicious-actor-ip-reputation.html#windows-endpoint.  I can generate the rule.id 100100 alert by making a web request from my "attacker" to the Windows agent running Apache.  I also get the rule.id 657 alert.

{ "_index": "wazuh-alerts-4.x-2026.09.26", "_id": "c_kN3aABVWzj1PfngvR6", "_score": null, "_source": { "input": { "type": "log" }, "agent": { "ip": "172.25.46.54", "name": "win-desktop", "id": "001" }, "manager": { "name": "ubuntu" }, "data": { "protocol": "GET", "srcip": "172.25.53.239", "id": "200", "url": "/" }, "rule": { "firedtimes": 3, "mail": false, "level": 10, "description": "IP address found in AlienVault reputation database.", "groups": [ "attack" ], "id": "100100" }, "location": "C:\\Apache24\\logs\\access_log", "decoder": { "name": "web-accesslog" }, "id": "1790415042.2726016", "full_log": "172.25.53.239 - - [26/Sep/2026:09:30:40 +0000] \"GET / HTTP/1.1\" 200 238", "timestamp": "2026-09-26T04:30:42.188-0500" }, "fields": { "timestamp": [ "2026-09-26T09:30:42.188Z" ] }, "sort": [ 1790415042188 ] }

However, I checked the logs and see that active-response/bin/netsh.exe cannot read srcip.

2026/09/26 09:39:23 active-response/bin/netsh.exe: Cannot read 'srcip' from data 2026/09/26 09:42:37 active-response/bin/netsh.exe: Starting 2026/09/26 09:42:37 active-response/bin/netsh.exe: {"version":1,"origin":{"name":"node01","module":"wazuh-execd"},"command":"add","parameters":{"extra_args":[],"alert":{"timestamp":"2026-09-26T04:42:37.944-0500","rule":{"level":10,"description":"IP address found in AlienVault reputation database.","id":"100100","firedtimes":7,"mail":false,"groups":["attack"]},"agent":{"id":"001","name":"win-desktop","ip":"172.25.46.54"},"manager":{"name":"ubuntu"},"id":"1790415757.2742226","full_log":"172.25.53.239 - - [26/Sep/2026:09:42:36 +0000] \"GET / HTTP/1.1\" 200 238","decoder":{"name":"web-accesslog"},"data":{"protocol":"GET","srcip":"172.25.53.239","id":"200","url":"/"},"location":"C:\\Apache24\\logs\\access_log"},"program":"active-response/bin/netsh.exe"}}
2026/09/26 09:42:37 active-response/bin/netsh.exe: Cannot read 'srcip' from data

Is there something I need to do in ossec.conf or with a decoder so srcip can be found?

Md. Nazmur Sakib

unread,
Sep 28, 2026, 7:35:01 AM (3 days ago) Sep 28
to Wazuh | Mailing List
Hello Bob!

I was able to reproduce the same error in my Lab. It seems that in the recent version, the script is throwing an error while running the script and the IP is not added to the Windows firewall block list.


2026/09/28 18:36:01 active-response/bin/netsh.exe: Starting

2026/09/28 18:36:01 active-response/bin/netsh.exe: {"version":1,"origin":{"name":"node01","module":"wazuh-execd"},"command":"add","parameters":{"extra_args":[],"alert":{"timestamp":"2026-09-28T09:36:01.062+0000","rule":{"level":10,"description":"IP address found in AlienVault reputation database.","id":"100100","firedtimes":2,"mail":false,"groups":["attack"]},"agent":{"id":"001","name":"win11","ip":"192.168.15.1"},"manager":{"name":"wazuh"},"id":"1790588161.2227648","full_log":"10.121.15.40 - - [28/Sep/2026:18:10:38 +0900] \"GET / HTTP/1.1\" 200 191","decoder":{"name":"web-accesslog"},"data":{"protocol":"GET","srcip":"10.121.15.40","id":"200","url":"/"},"location":"C:\\Apache24\\logs\\access_log"},"program":"active-response/bin/netsh.exe"}}

2026/09/28 18:36:01 active-response/bin/netsh.exe: Cannot read 'srcip' from data


But  Get-NetFirewallAddressFilter | Where-Object {$_.RemoteAddress -contains "10.121.15.40"}
Does not show any IP in the firewall block list.

I will share this with the development team to update the Active Response .exe file as soon as possible. Also, meanwhile, you can check this document on making a custom active response for Windows to achieve similar functionality with a custom active response.
Windows custom active response configuration

I will let you know the further progress on this.
Reply all
Reply to author
Forward
0 new messages