Skip to content

fusuyfusuy/wazuh_local_rules

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

As a graduation project, we created an EDR system using Sysmon and Wazuh. Creating logs and getting them to Wazuh server were easy. The problem was to generate alerts and mapping logs to MITRE ATT&CK framework. Wazuh needs custom rules to generate alerts.

We parsed and edited the rules to add MITRE ATT&CK mapping.

About

Wazuh rules to add sysmon support

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages