crow1011 / wazuh2thehive

Wazuh integration TheHive
32 stars 15 forks source link

Vulnerability scan events from Wazuh to TheHive #13

Open bradhawkins85 opened 1 year ago

bradhawkins85 commented 1 year ago

Is it possible to enable something to push vulnerability scan results from Wazuh to TheHive. I am receiving security events but not vulnerability events. MITRE ATT&CK would be great too if it is easy enough to do. I am running the latest version of Wazuh on Docker.

bradhawkins85 commented 1 year ago

I have checked the alerts.json file and the vulnerability-detector events are logged in there as level 10