Dear Julian,
Thank you so mcuh for your reply.
May i check with you, do Wazuh have a better way to detect abnormally port connection instead of checking every 6 min?
Understand that in endpoint ossec.conf below it runs every 360 seconds (6minutes) hence from all these observation security event for MacOS, that "Listened ports status (netstat) changed (new port opened or closed)” is more of like noises / false positive. For example like every 6 minutes when endpoint browse website event id:533 will be triggered.
3. By referring to the enclosed screenshot, if we analyze the eventid:533 level 7’s full_log, if we wan to close any unused port, it is based on the highlighted top portion only? And we configure at user’s Mac firewall setting to closed?
Please help advice.
Thanks & Best Regards,
Isaac