Mehrdad-hajizadeh / SOC_Setup

0 stars 0 forks source link

W agent and malicious event detection #10

Open Mehrdad-hajizadeh opened 9 months ago

Mehrdad-hajizadeh commented 9 months ago

We are sending the logs to W for further analysis, hence

The agent helps to protect your system by providing threat prevention, detection, and response capabilities. It is also used to collect different types of system and application data that it forwards to the Wazuh server through an encrypted and authenticated channel. Hence,

ykrishnatuc commented 8 months ago

I did not find any proper solution for "agent performs detection and then sends its own log to server." In some articles, the agent performs both detection and log forwarding, while in other articles, the agent only forwards logs. This is confusing, but from my understanding, the agent typically only forwards logs to the server.

Here are some references for how an agent works:

  1. Incident RespIncident Response with Threat Intelligence: Practical insights into developing an incident response capability through intelligence-based threat hunting :By Roberto MartinezMartinez

Image

  1. Proceedings of Eighth International Congress on Information and Communication Technology: ICICT 2023, London, Volume 2 edited by Xin-She Yang

Image

  1. 2019_TFG_Gómez_IDS(pdf)

Image