wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
10.34k stars 1.59k forks source link

Feature request: Increase Rootcheck capability by adding more default paths and make it configurable #9166

Open MiguelCasaresRobles opened 3 years ago

MiguelCasaresRobles commented 3 years ago
Wazuh version Component Install type Install method Platform
Latest Rootcheck Manager/Agent Packages/Sources Linux/Windows

Hello team,

I'm opening this issue to consider increasing Rootcheck malware detection capabilities. At this moment, those are the directories monitored by default: https://github.com/wazuh/wazuh/blob/master/src/rootcheck/check_rc_trojans.c#L26

It is not possible to configure Windows directories or more paths in Linux. Although it is possible to scan the whole system: https://documentation.wazuh.com/current/user-manual/reference/ossec-conf/rootcheck.html#scanall it is not giving enough flexibility to the user to configure its system.

It happens for the rootkits too: https://github.com/wazuh/wazuh/blob/master/src/rootcheck/check_rc_sys.c#L154

Reported by Johannes Segitz of SUSE

Regards,

Miguel Casares

TomasTurina commented 3 years ago

This issue applies for rootkit and malware detections.

Impact:

Probability:

Cost to fix it:

Estimated time: