-
Are they the same as for standalone Wazuh? I was testing one of my Ubuntu agents and I deleted the bash history file (which is one of the examples on Wazuh's website) and I didn't get even a Low alert. I also never got an alert for things like editing the passwd file manually. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 6 replies
-
We include the full Wazuh server and the full Wazuh agent. Are you getting any Wazuh alerts at all? |
Beta Was this translation helpful? Give feedback.
-
I was an Threat Detection engineer for a wazuh based SOC, and i gotta tell you after extensive atomic red team testing, Wazuh really starts to shine when you utilize it with sysmon and custom rules. If i remember right, even our dedicated Wazuh siem had trouble detecting invoke-mimikatz usage until we implemented sysmon and implemented some sigma rules. |
Beta Was this translation helpful? Give feedback.
We include the full Wazuh server and the full Wazuh agent. Are you getting any Wazuh alerts at all?