You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hello Team,
Actually I wanted to malware detection in wazuh. I download some malware samples for detection purpose. I am not getting any alerts and events regarding this in my wazuh gui interface. Can you please help how can i getting alert regarding malware detection if any malware execution in agent side.
Thanks in advance.
Maximiliano Ibarra
unread,
Jan 6, 2022, 9:28:56 AM1/6/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hi. First of all, thanks for contacting us. I gonna try to help you with the malware detections in your wazuh environment. The File integrity monitoring watches selected files and triggers alerts when these files are modified. Because of that, we need to configure the FIM module. First I suggested you read this article about Anomaly and Malware detection: https://documentation.wazuh.com/current/user-manual/capabilities/anomalies-detection/how-it-works.html
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hello Team,
Already I have done testing with some malware it is showing the alert but now we are testing with ransomware in this situation I am not getting any alert regarding ransomware. Is wazuh capable for detect the ransomware if yes please let me know.
Thanks
Maximiliano Ibarra
unread,
Jan 13, 2022, 12:23:26 PM1/13/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hi. Thanks for contacting us again. I was researching more about your doubt and I found the following article in our blog.