Skip to content

Comments

feat(wazuh): add santa decoder, added rules for lotl exfiltration detection and updated macos rules#175

Open
t-desmond wants to merge 1 commit intomainfrom
feat/sysmon-santa-lotl-exfil-rules
Open

feat(wazuh): add santa decoder, added rules for lotl exfiltration detection and updated macos rules#175
t-desmond wants to merge 1 commit intomainfrom
feat/sysmon-santa-lotl-exfil-rules

Conversation

@t-desmond
Copy link
Contributor

  • Added new santa and santa-kv decoders for event parsing
  • Added rules for lotl exfiltration events
  • Refactored macOS syslog and FIM rules for critical system events detection

…ection and updated macos rules

- Added new santa and santa-kv decoders for event parsing
- Added rules for lotl exfiltration events
- Refactored macOS syslog and FIM rules for critical system events detection
@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 9, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant