wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
10.96k stars 1.67k forks source link

LDAP/AD telemetry and metadata #14250

Open hitman28594 opened 2 years ago

hitman28594 commented 2 years ago
4.x Manager
X.Y.Z-rev Wazuh component Manager/Agent Packages/Sources OS version

Hello Team,

I would like to make a feature request for a mechanism to query and ingest computer metadata from AD/LDAP. A lot of other products have several of the proposed use cases and I think these would be a great feature addition to wazuh which would make the user experience a lot more friendly.

Use cases:

Config options:

https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-adcomputer?view=windowsserver2022-ps

hitman28594 commented 2 years ago

The feature request made here also related to native AD monitoring/integration:

https://github.com/wazuh/wazuh/issues/3878

We would be able to query LDAP to pre-populate things like cdb lists and automatically enrich entities out of the box.