From 82a33321aea7da2277ea7e3d8da8876fd55fc23f Mon Sep 17 00:00:00 2001 From: Lukas Kuap Date: Tue, 27 Jan 2026 18:23:01 +0000 Subject: [PATCH] Mense/Server/UBNT/DE495140SUBS01/ossec.conf aktualisiert --- Mense/Server/UBNT/DE495140SUBS01/ossec.conf | 246 ++++++++++++++++++++ 1 file changed, 246 insertions(+) diff --git a/Mense/Server/UBNT/DE495140SUBS01/ossec.conf b/Mense/Server/UBNT/DE495140SUBS01/ossec.conf index e69de29..3b8b927 100644 --- a/Mense/Server/UBNT/DE495140SUBS01/ossec.conf +++ b/Mense/Server/UBNT/DE495140SUBS01/ossec.conf @@ -0,0 +1,246 @@ + + + + + +
wazuh.jochheim-edv.de
+ 1514 + tcp +
+ ubuntu, ubuntu24, ubuntu24.04 + 20 + 60 + yes + aes + + yes + DE225680SBEZ01 + Autohaus-Mense + etc/authd.pass + +
+ + + + no + 5000 + 500 + + + + + no + yes + yes + yes + yes + yes + yes + yes + + + 43200 + + etc/shared/rootkit_files.txt + etc/shared/rootkit_trojans.txt + + yes + + /var/lib/containerd + /var/lib/docker/overlay2 + + + + yes + 1800 + 1d + yes + + wodles/java + wodles/ciscat + + + + + yes + yes + /var/log/osquery/osqueryd.results.log + /etc/osquery/osquery.conf + yes + + + + + no + 1h + yes + yes + yes + yes + yes + yes + yes + yes + yes + yes + yes + + + + 10 + + + + + yes + yes + 12h + yes + + + + + no + + + 43200 + + yes + + + /etc,/usr/bin,/usr/sbin + /bin,/sbin,/boot + /etc/ssh + /etc/cups + /var/spool/cups + + + /etc/mtab + /etc/hosts.deny + /etc/mail/statistics + /etc/random-seed + /etc/random.seed + /etc/adjtime + /etc/httpd/logs + /etc/utmpx + /etc/wtmpx + /etc/cups/certs + /etc/dumpdates + /etc/svc/volatile + + + .log$|.swp$ + + + /etc/ssl/private.key + + yes + yes + yes + yes + + + 10 + + + 50 + + + + yes + 5m + 10 + + + + + + command + df -P + 360 + + + + full_command + netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d + netstat listening ports + 360 + + + + full_command + last -n 20 + 360 + + + + + no + etc/wpk_root.pem + yes + + + + + plain + + +
+ + + + journald + journald + + + + syslog + /var/log/auth.log + + + + syslog + /var/ossec/logs/active-responses.log + + + + syslog + /var/log/cups/error_log + + + + syslog + /var/log/clamav/fullscan.log + + + + syslog + /var/log/clamav/quickscan.log + + + + syslog + /var/log/clamav/freshclam.log + + + + full_command + faillog -a + 360 + + + + syslog + /var/log/cups/access_log + + + + syslog + /var/log/dpkg.log + + +