misje / opencti-wazuh-connector

OpenCTI–Wazuh connector looking for indicators in Wazuh and creating sightings
https://misje.github.io/opencti-wazuh-connector/
Apache License 2.0
15 stars 1 forks source link

Look for processes and network traffic in syscollector events #83

Open misje opened 4 months ago

misje commented 4 months ago

syscollector events (ID 221) are not stored by default, but if they are, they contains a lot of useful information, like process executions and open sockets (including non-listening if configured to do so). Include these fields in search and enrichment.