Hello!
I’d like to know what the security implications are of enabling remote commands via `wazuh_command.remote_commands=1`.
Or what would you recommend? Should I enable this feature or not?
I’m currently setting up an agent monitoring integration and need to send commands to them; I know I can do this either this way or directly from the agent.
But I’d like to know what enabling this command entails.
If enabled, it is recommended to restrict its usage to specific agent groups, apply strict RBAC and API access controls, audit all command executions, and limit the allowed commands to predefined and validated operations only, you can read this documentation about the remote commands: https://documentation.wazuh.com/current/user-manual/capabilities/command-monitoring/configuration.html?utm_source=chatgpt.com#the-centralized-configuration-file
I understand that, but what are the security reasons for recommending that it not be enabled?
I understand that, but what are the security reasons for recommending that it not be enabled?
--
You received this message because you are subscribed to the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/fb372e6b-39d4-497f-a29e-37d9cdd77d1bn%40googlegroups.com.