Code Monkey home page Code Monkey logo

wazuh-ruleset's Introduction

Wazuh Ruleset

Slack Email Documentation Documentation

Wazuh ruleset is used to detect attacks, intrusions, software misuse, configuration problems, application errors, malware, rootkits, system anomalies or security policy violations.

The ruleset includes compliance mapping with PCI DSS v3.1 and CIS.

Installation

Directory structure

├── wazuh-ruleset
│ ├── decoders            # OSSEC decoders created/updated by Wazuh
│ ├── rules               # OSSEC rules created/updated by Wazuh
│ ├── rootchecks          # OSSEC rootchecks created/updated by Wazuh
│ ├── scap_content        # OVAL, XCCDF, DS created/updated by Wazuh
│ ├── lists               # CDB lists created/updated by Wazuh
|
│ ├── tools
|
│ ├── README.md
│ ├── VERSION
│ ├── update_ruleset.py   # Install/update ruleset

Full documentation

Full documentation at documentation.wazuh.com

Branches

  • stable branch on correspond to the last OSSEC Ruleset stable version.
  • master branch contains the latest code, be aware of possible bugs on this branch.
  • development branch includes all the new features we are adding and testing.

Contribute

If you have created new rules, decoders or rootchecks and you would like to contribute to our repository, please fork our Github repository and submit a pull request. To make a pull request for new rules and decoders, follow these instructions:

  1. If your rules and decoders are related to existent ones in the ruleset, you should add them at the end of the corresponding file. If they are made for a new application or device that Wazuh does not currently support, you should create a new XML following the title format. For example, if the last XML file is 0620-last-xml_rules.xml, the next one should be named 0625-new_integration.xml. Please, make sure your rules do not use an existent rule id.

  2. Make sure to create your test.ini file. You may find examples under the wazuh/wazuh-ruleset/tools/rules-testing/tests folder. Then add it to the repository along with the rest of the tests.

  3. Create the pull request

If you are not familiar with Github, you can also share them through our users mailing list, to which you can subscribe by sending an email to [email protected]. As well do not hesitate to request new rules or rootchecks that you would like to see running in Wazuh and our team will do our best to make it happen.

Web references

wazuh-ruleset's People

Contributors

jesuslinares avatar chemamartinez avatar vikman90 avatar snaow avatar cristgl avatar albertomn86 avatar tjoserafael avatar crd1985 avatar psanchezr avatar iasdeoupxe avatar elwali10 avatar crolopez avatar branchnetconsulting avatar banditopazzo avatar lopuiz avatar frgv avatar sitorbj avatar santiago-bassett avatar gkissand avatar hex2a avatar jlruizmlg avatar ddpbsd avatar adriiiprodri avatar bob-andrews avatar brauliov avatar druizz90 avatar jctello avatar miguelcasaresrobles avatar cerv1 avatar juan70 avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.