Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
IOCs based Rules
129 views
Skip to first unread message
John Carry
unread,
Jul 5, 2023, 1:59:57 AM
7/5/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Dear Wazuh Team,
Please provide us way to create IOCs based rules, for example what if we want to trigger rule for Hashes, IPs, File Names etc.
Pacome Kemkeu
unread,
Jul 5, 2023, 4:05:02 AM
7/5/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hello John,
The following blog post have all the coverage for your request, kindly take a look:
URLHaus:
Detecting malicious URLs using Wazuh and URLhaus
ABuseIPDB:
Detecting known bad actors with Wazuh and AbuseIPDB
Building IoCs files for Threat Intel:
build your own IoC files for
threat
intelligence
with Wazuh XDR
VirusTotal:
Detecting and removing malware using VirusTotal integration
I hope you find this helpful.
Reply all
Reply to author
Forward
0 new messages