wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
10.56k stars 1.62k forks source link

Create SCA Policy for Windows Server 2012 (non R2) #18535

Closed jk-olaoluwa closed 1 month ago

jk-olaoluwa commented 1 year ago
Component Action type Main Issue
SCA Create #18306

Main tasks

Checks

Syntax and semantic

Content

Unit testing

Analysisd (server or local)

analysisd.debug=2

Auth daemon debug (server)

authd.debug=0

Exec daemon debug (server, local, or Unix agent)

execd.debug=0

Monitor daemon debug (server, local, or Unix agent)

monitord.debug=0

Log collector (server, local or Unix agent)

logcollector.debug=0

Integrator daemon debug (server, local or Unix agent)

integrator.debug=0

Unix agentd

agent.debug=2

Deployment

Documentation

Johnng007 commented 8 months ago

Fix for Issue https://github.com/wazuh/wazuh/issues/21298

(L1) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer days, but not 0'. (Automated)

jk-olaoluwa commented 8 months ago

Update 05/02/2024

Update 06/02/2024

Update 07/02/2024

Update 08/02/2024

Update 09/02/2024

Update 12/02/2024

Update 13/02/2024

Update 14/02/2024

Update 15/02/2024

Update 16/02/2024

Update 19/02/2024

Update 20/02/2024

Update 21/02/2024

Update 22/02/2024

Update 23/02/2024

Update 26/02/2024

Update 27/02/2024

Update 28/02/2024

Update 04/03/2024

Update 05/03/2024

Update 06/03/2024

Update 07/03/2024

Update 08/04/2024

Update 12/03/2024

Update 14/03/2024

IsExec commented 6 months ago

Review Update - 15/03/2024

Section 1.1.1 - 2.3.1.3

Review Update - 18/03/2024

Justification for 2.3.5.5

2012

Review Update - 02/04/2024

Section 2.3.7.2 - 2.3.11.2

Review Update - 03/04/2024

Section 2.3.11.2 - 9.1.1

Review Update - 04/04/2024

Review Update - 05/04/2024

Review Update - 08/04/2024

Review Update - 16/04/2024

Section 18.10.57.3.9.5 - 18.10.87.2

jk-olaoluwa commented 6 months ago

Review Update - 15/03/2024

18/03/2024

03/04/2024

04/04/2024

05/04/2024

ooniagbi commented 4 months ago

Currently working on other issues.

ooniagbi commented 3 months ago

This is still on hold because of higher-priority issues.

ooniagbi commented 2 months ago

This is still on hold because of higher-priority issues.

IsExec commented 2 months ago

Windows Server 2012 non-R2 SCA Testing Report

Condition: The new SCA was benchmarked against Windows server 2012 R2 SCA.

Agent running on old SCA (Windows server 2012 R2 SCA)

Endpoint spec

CPU/RAM ````console >systeminfo Host Name: WINDOWS-SERVER- OS Name: Microsoft Windows Server 2012 R2 Standard OS Version: 6.3.9600 N/A Build 9600 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Server OS Build Type: Multiprocessor Free Registered Owner: Registered Organization: Vagrant Product ID: 00252-00105-69793-AA339 Original Install Date: 1/13/2015, 3:27:02 AM System Boot Time: 7/31/2024, 4:38:06 PM System Manufacturer: innotek GmbH System Model: VirtualBox System Type: x64-based PC Processor(s): 1 Processor(s) Installed. [01]: Intel64 Family 6 Model 142 Stepping 10 GenuineIntel ~2112 Mhz BIOS Version: innotek GmbH VirtualBox, 12/1/2006 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume1 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (UTC-06:00) Central Time (US & Canada) Total Physical Memory: 4,024 MB Available Physical Memory: 2,731 MB Virtual Memory: Max Size: 5,432 MB Virtual Memory: Available: 4,293 MB Virtual Memory: In Use: 1,139 MB Page File Location(s): C:\pagefile.sys ````
Disk ````console >wmic logicaldisk get size,freespace,caption Caption FreeSpace Size C: 40912048128 64055406592 D: ````

Footprint test results

Metrics ![cpu_percent_plot](https://github.com/user-attachments/assets/9acbfcac-6802-4769-8614-a8865fff2eb6) ![disk_percent_plot](https://github.com/user-attachments/assets/9de464a9-145f-48fc-96e8-486c165e3375) ![disk_used_(mb)_plot](https://github.com/user-attachments/assets/ab5076e2-2b21-454b-9473-3289428b7f18) ![memory_percent_plot](https://github.com/user-attachments/assets/d4395da9-4893-42cd-874d-bc419bcd2ae4) ![memory_used_(mb)_plot](https://github.com/user-attachments/assets/17c6ba57-f3f7-4734-874c-f887597928f8) ![ProcessesCPU](https://github.com/user-attachments/assets/92faabb3-f88e-40c0-9d8b-e2f50c904b0e) ![ProcessesCPU_Change_Point](https://github.com/user-attachments/assets/419edfc8-8c52-4291-bd41-02fa5f3ab57a) ![ProcessesCPUlegend](https://github.com/user-attachments/assets/00e9c2a6-ae4a-4357-a6e3-835a4bda32d4) ![ProcessesRAM](https://github.com/user-attachments/assets/3231893c-002a-44dc-a551-dccd5a15b304) ![ProcessesRAM_Change_Point](https://github.com/user-attachments/assets/53513472-a908-45c7-bfda-7817dcedd7d7) ![ProcessesRAMlegend](https://github.com/user-attachments/assets/7f3427d3-f86f-4d2e-9cdd-6334d13b92fe) ![swap_percent_plot](https://github.com/user-attachments/assets/78cff161-9906-48dc-9b98-ce1b74fe1085) ![swap_used_(mb)_plot](https://github.com/user-attachments/assets/39076e2f-7b9a-48cf-bdc2-45b77e62bf3b)
SCA logs ````console 2024/07/31 22:20:50 sca: INFO: Starting Security Configuration Assessment scan. 2024/07/31 22:20:51 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/07/31 22:20:56 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/07/31 22:20:56 sca: INFO: Security Configuration Assessment scan finished. Duration: 6 seconds. 2024/07/31 22:25:50 sca: INFO: Starting Security Configuration Assessment scan. 2024/07/31 22:25:50 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/07/31 22:25:56 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/07/31 22:25:56 sca: INFO: Security Configuration Assessment scan finished. Duration: 6 seconds. 2024/07/31 22:30:50 sca: INFO: Starting Security Configuration Assessment scan. 2024/07/31 22:30:50 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/07/31 22:30:56 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/07/31 22:30:56 sca: INFO: Security Configuration Assessment scan finished. Duration: 6 seconds. ````

metrics.zip

Agent running on new SCA (Windows server 2012 non-R2 SCA Rework)

Endpoint spec

CPU/RAM ````console >systeminfo Host Name: WIN-VC0KKML8ORL OS Name: Microsoft Windows Server 2012 Standard Evaluation OS Version: 6.2.9200 N/A Build 9200 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Server OS Build Type: Multiprocessor Free Registered Owner: Vagrant Registered Organization: Vagrant Product ID: 00183-90000-00001-AA422 Original Install Date: 8/1/2024, 8:16:59 PM System Boot Time: 8/1/2024, 8:18:02 PM System Manufacturer: innotek GmbH System Model: VirtualBox System Type: x64-based PC Processor(s): 1 Processor(s) Installed. [01]: Intel64 Family 6 Model 142 Stepping 10 GenuineIntel ~2112 Mhz BIOS Version: innotek GmbH VirtualBox, 12/1/2006 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume1 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (UTC) Coordinated Universal Time Total Physical Memory: 4,024 MB Available Physical Memory: 2,896 MB Virtual Memory: Max Size: 7,608 MB Virtual Memory: Available: 6,601 MB Virtual Memory: In Use: 1,007 MB Page File Location(s): C:\pagefile.sys ````
Disk ````console >wmic logicaldisk get size,freespace,caption Caption FreeSpace Size C: 17856405504 42580570112 ````

Footprint test results

Metrics ![cpu_percent_plot](https://github.com/user-attachments/assets/0eb71936-64e1-4a62-b6f4-b9d90e060307)!![disk_percent_plot](https://github.com/user-attachments/assets/bbeba744-380b-43fa-bc63-4cb4051d0935) ![disk_used_(mb)_plot](https://github.com/user-attachments/assets/13779c99-c47e-481f-b6dc-6bfb2cfa3699) ![memory_percent_plot](https://github.com/user-attachments/assets/ba39ada8-d0f5-4b49-ba34-cdbb79a69691) ![memory_used_(mb)_plot](https://github.com/user-attachments/assets/df75e6b6-f5f8-44a5-a215-cfa1cd1662ba) ![ProcessesCPU](https://github.com/user-attachments/assets/733b1d9c-d367-494e-81de-02be3966c7f5) ![ProcessesCPU_Change_Point](https://github.com/user-attachments/assets/9a2e052e-0b64-4ab4-9a75-b9bb51a60761) ![ProcessesCPUlegend](https://github.com/user-attachments/assets/f4024e7e-6502-42d8-b77f-2890dd78b3aa) ![ProcessesRAM](https://github.com/user-attachments/assets/cc7d4c03-d1f0-464f-a48a-8e25dd57da3b) ![ProcessesRAM_Change_Point](https://github.com/user-attachments/assets/2b41c5fc-7ef7-43d1-ac0a-cfc92228ee75) ![ProcessesRAMlegend](https://github.com/user-attachments/assets/26ce469d-2537-4322-9173-368bf630ffbe) ![swap_percent_plot](https://github.com/user-attachments/assets/5504c552-264f-42e8-b317-beac8930546d) ![swap_used_(mb)_plot](https://github.com/user-attachments/assets/63f5836c-835c-4421-a9cf-8b7ce5c838d5)
SCA logs ````console 2024/08/02 00:49:53 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/02 00:49:53 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/02 00:49:57 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/02 00:49:57 sca: INFO: Security Configuration Assessment scan finished. Duration: 4 seconds. 2024/08/02 00:54:53 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/02 00:54:53 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/02 00:54:58 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/02 00:54:58 sca: INFO: Security Configuration Assessment scan finished. Duration: 5 seconds. 2024/08/02 00:59:53 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/02 00:59:53 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/02 00:59:58 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/02 00:59:58 sca: INFO: Security Configuration Assessment scan finished. Duration: 5 seconds. ````

metrics.zip

Analysis

Β  Benchmark (Win server 2012 R2 SCA) New SCA (Win server 2012 nonR2) Difference
CPU Β  Β  Β 
wazuh-agent.exeΒ average CPU percent 2.3 0.75 -1.55
Overall average CPU percent 11.6 4.4 -7.2
Overall peak CPU percent 18.1 8.3 -9.8
Memory Β  Β  Β 
wazuh-agent.exe average memory (MB) 0.02 0.02 0
Overall average memory used (MB) 1299.9 1227.41 -72.49
Overall peak memory used peak (MB) 1301.05 1227.52 -73.53
Disk Β  Β  Β 
Overall average disk used (MB) 22069.54 23578.23 1508.69
Overall peak disk used (MB) 22069.54 23578.23 1508.69
Overall average disk read bytes N/A N/A N/A
Overall peak disk read bytes N/A N/A N/A
Overall average disk write bytes N/A N/A N/A
Overall peak disk write bytes N/A N/A N/A

Note on Disk Read Bytes and Disk Write Bytes

Disk read and disk write bytes were excluded because the get_metrics.py script returned an Attribute error.

Error ```console >python get_metrics.py -- interval 5 -- duration 600 Traceback global_metrics = get_global_env_values (args.unit> File "C:\Users\Administrator\Desktop\sca_footprint\get_metrics.py", line 95, i n get_global_env_values disk_read_bytes = convert_units AAA AttributeError: 'NoneType' object has no attribute 'read_bytes' ```

The disk read and write bytes were excluded by commenting out the parts of the script that fetch the disk read and write bytes data.

IsExec commented 1 month ago

Windows Server 2012 non-R2 SCA Re-Test Report

Note on Disk Read Bytes and Disk Write Bytes

To capture the disk write and disk read values, it is required to enable disk metrics by running the command below:

>diskperf -y

Condition: The new SCA was benchmarked against old Windows server 2012 R2 SCA.

Agent running on old SCA (Windows server 2012 R2 SCA)

Endpoint spec

CPU/RAM ````console >systeminfo Host Name: WINDOWS-SERVER- OS Name: Microsoft Windows Server 2012 R2 Standard OS Version: 6.3.9600 N/A Build 9600 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Server OS Build Type: Multiprocessor Free Registered Owner: Registered Organization: Vagrant Product ID: 00252-00105-69793-AA339 Original Install Date: 1/13/2015, 3:27:02 AM System Boot Time: 8/11/2024, 1:07:05 PM System Manufacturer: innotek GmbH System Model: VirtualBox System Type: x64-based PC Processor(s): 1 Processor(s) Installed. [01]: Intel64 Family 6 Model 142 Stepping 10 GenuineIntel ~2112 Mhz BIOS Version: innotek GmbH VirtualBox, 12/1/2006 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume1 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (UTC-06:00) Central Time (US & Canada) Total Physical Memory: 4,024 MB Available Physical Memory: 3,126 MB Virtual Memory: Max Size: 5,432 MB Virtual Memory: Available: 4,560 MB Virtual Memory: In Use: 872 MB Page File Location(s): C:\pagefile.sys Domain: WORKGROUP ````
Disk ````console >wmic logicaldisk get size,freespace,caption C a p t i o n F r e e S p a c e S i z e C : 4 3 3 1 7 2 4 8 0 0 0 6 4 0 5 5 4 0 6 5 9 2 ````

Footprint test results

Metrics ![cpu_percent_plot](https://github.com/user-attachments/assets/5c490be2-62ab-467a-b516-b863d79e761e) ![disk_percent_plot](https://github.com/user-attachments/assets/d53fd2dd-0b20-4fb2-8c23-665ba2e49221) ![disk_used_(mb)_plot](https://github.com/user-attachments/assets/be4bba7e-af37-4cab-8590-0de9b454f99b) ![memory_percent_plot](https://github.com/user-attachments/assets/92e17466-236f-4487-a69b-4b103bc3e341) ![memory_used_(mb)_plot](https://github.com/user-attachments/assets/83e23eb2-8749-45d7-b005-2f96341c2833) ![ProcessesCPU](https://github.com/user-attachments/assets/981837a6-8b80-4e82-881a-71bfee6deb26) ![ProcessesCPU_Change_Point](https://github.com/user-attachments/assets/e643889f-735c-4958-aec1-c873efa04433) ![ProcessesCPUlegend](https://github.com/user-attachments/assets/0314ed2e-8267-48c8-b350-4dc81667b7df) ![ProcessesRAM](https://github.com/user-attachments/assets/67b79262-ca57-4052-a81a-b65d3b2bb406) ![ProcessesRAM_Change_Point](https://github.com/user-attachments/assets/be02651f-6a5b-4c84-ba9c-72ccfb8fe645) ![ProcessesRAMlegend](https://github.com/user-attachments/assets/40139181-4ffd-4919-834b-f2e0b08e76d5) ![swap_percent_plot](https://github.com/user-attachments/assets/9d86216f-254c-48ee-ab72-9b2cdd9b1b61) ![swap_used_(mb)_plot](https://github.com/user-attachments/assets/10a9b1db-b35c-477d-b589-68c29a6bb331)
SCA logs ````console 2024/08/11 12:40:27 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/11 12:40:27 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/08/11 12:40:31 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/08/11 12:40:31 sca: INFO: Security Configuration Assessment scan finished. Duration: 4 seconds. 2024/08/11 12:45:27 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/11 12:45:27 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/08/11 12:45:30 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/08/11 12:45:30 sca: INFO: Security Configuration Assessment scan finished. Duration: 3 seconds. 2024/08/11 12:50:27 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/11 12:50:27 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/08/11 12:50:30 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012r2.yml' 2024/08/11 12:50:30 sca: INFO: Security Configuration Assessment scan finished. Duration: 3 seconds. ````

metrics.zip

Agent running on new SCA (Windows server 2012 R2 SCA Rework)

Endpoint spec

CPU/RAM ````console >systeminfo Host Name: WIN-4UH3B19KVBF OS Name: Microsoft Windows Server 2012 Standard Evaluation OS Version: 6.2.9200 N/A Build 9200 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Server OS Build Type: Multiprocessor Free Registered Owner: Vagrant Registered Organization: Vagrant Product ID: 00183-90000-00001-AA422 Original Install Date: 8/11/2024, 7:38:20 PM System Boot Time: 8/11/2024, 7:39:16 PM System Manufacturer: innotek GmbH System Model: VirtualBox System Type: x64-based PC Processor(s): 1 Processor(s) Installed. [01]: Intel64 Family 6 Model 142 Stepping 10 GenuineIntel ~2112 Mhz BIOS Version: innotek GmbH VirtualBox, 12/1/2006 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume1 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (UTC) Coordinated Universal Time Total Physical Memory: 4,024 MB Available Physical Memory: 3,165 MB Virtual Memory: Max Size: 7,608 MB Virtual Memory: Available: 6,789 MB Virtual Memory: In Use: 819 MB Page File Location(s): C:\pagefile.sys ````
Disk ````console >wmic logicaldisk get size,freespace,caption C a p t i o n F r e e S p a c e S i z e C : 1 8 1 2 8 4 9 8 6 8 8 4 2 5 8 0 5 7 0 1 1 2 ````

Footprint test results

Metrics ![cpu_percent_plot](https://github.com/user-attachments/assets/1e4c64e6-09e9-4fce-9a01-b1b2442075af) ![disk_percent_plot](https://github.com/user-attachments/assets/27693ef1-484d-48ae-afc9-588ca20cbcfd) ![disk_used_(mb)_plot](https://github.com/user-attachments/assets/dea13f28-622c-4b11-93a9-2d2aaf6eb5fe) ![memory_percent_plot](https://github.com/user-attachments/assets/79b4c5fb-890c-4a14-b4d0-7df1adb62911) ![memory_used_(mb)_plot](https://github.com/user-attachments/assets/68d86fa1-1b3e-4997-9af3-f0a2717fc33e) ![ProcessesCPU](https://github.com/user-attachments/assets/7491d1c1-2286-4f05-a114-4c1c51293bef) ![ProcessesCPU_Change_Point](https://github.com/user-attachments/assets/e01e3cb7-7be0-48df-81b2-5162d27b5d38) ![ProcessesCPUlegend](https://github.com/user-attachments/assets/f2cfda26-c626-4753-bd7f-c40ae93fd07e) ![ProcessesRAM](https://github.com/user-attachments/assets/67431517-d987-49dc-8291-9915ab68325b) ![ProcessesRAMlegend](https://github.com/user-attachments/assets/0bdf384c-d842-43d3-ba7a-f816b325d056) ![ProcessesRAMlegend](https://github.com/user-attachments/assets/a8eec920-8126-49f4-bf53-05af188f5b37) ![swap_percent_plot](https://github.com/user-attachments/assets/0373a905-caf1-44ff-8a2a-04ec07182b9f) ![swap_used_(mb)_plot](https://github.com/user-attachments/assets/36a9b963-ba07-4c13-9f7e-07c44af33166)
SCA logs ````console 20:57:00 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/11 20:57:04 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/11 20:57:04 sca: INFO: Security Configuration Assessment scan finished. Duration: 4 seconds. 2024/08/11 21:02:00 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/11 21:02:00 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/11 21:02:04 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/11 21:02:04 sca: INFO: Security Configuration Assessment scan finished. Duration: 4 seconds. 2024/08/11 21:07:00 sca: INFO: Starting Security Configuration Assessment scan. 2024/08/11 21:07:00 sca: INFO: Starting evaluation of policy: 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/11 21:07:04 sca: INFO: Evaluation finished for policy 'C:\Program Files (x86)\ossec-agent\ruleset\sca\cis_win2012_non_r2.yml' 2024/08/11 21:07:04 sca: INFO: Security Configuration Assessment scan finished. Duration: 4 seconds. ````

metrics.zip

Analysis

Β  Benchmark (Win server 2012 R2 SCA) New SCA (Win server 2012 nonR2) Difference
CPU Β  Β  Β 
wazuh-agent.exeΒ average CPU percent 1.2 0.9 -0.3
Overall average CPU percent 0.4 4.6 4.2
Overall peak CPU percent 0.8 7.8 7
Memory Β  Β  Β 
wazuh-agent.exe average memory (MB) 0.02 0.02 0
Overall average memory used (MB) 1162.15 841.29 -320.86
Overall peak memory used peak (MB) 1162.23 841.86 -320.37
Disk Β  Β  Β 
Overall average disk used (MB) 19193.59 23325.89 4132.3
Overall peak disk used (MB) 19193.59 23325.89 4132.3
Overall average disk read bytes 1019.89 0 -1019.89
Overall peak disk read bytes 1019.89 0 -1019.89
Overall average disk write bytes 342.36 4.11 -338.25
Overall peak disk write bytes 342.45 4.2 -338.25
ooniagbi commented 1 month ago

LGTM!

ooniagbi commented 1 month ago

Pending: https://github.com/wazuh/wazuh-packages/issues/3073#issuecomment-2296630654

ooniagbi commented 1 month ago

Merged to 4.10.0