From f02fd29599ba9ebfd9ef2270b1c93c222e78695b Mon Sep 17 00:00:00 2001 From: Lukas Kuap Date: Fri, 23 Jan 2026 16:55:33 +0000 Subject: [PATCH] =?UTF-8?q?Mense/Server/UBNT/DE225680SBEZ01/ossec.conf=20h?= =?UTF-8?q?inzugef=C3=BCgt?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- Mense/Server/UBNT/DE225680SBEZ01/ossec.conf | 207 ++++++++++++++++++++ 1 file changed, 207 insertions(+) create mode 100644 Mense/Server/UBNT/DE225680SBEZ01/ossec.conf diff --git a/Mense/Server/UBNT/DE225680SBEZ01/ossec.conf b/Mense/Server/UBNT/DE225680SBEZ01/ossec.conf new file mode 100644 index 0000000..c081810 --- /dev/null +++ b/Mense/Server/UBNT/DE225680SBEZ01/ossec.conf @@ -0,0 +1,207 @@ + + + + + +
wazuh.jochheim-edv.de
+ 1514 + tcp +
+ ubuntu, ubuntu24, ubuntu24.04 + 20 + 60 + yes + aes + + yes + DE225680SBEZ01 + Autohaus-Mense + etc/authd.pass + +
+ + + + no + 5000 + 500 + + + + + no + yes + yes + yes + yes + yes + yes + yes + + + 43200 + + etc/shared/rootkit_files.txt + etc/shared/rootkit_trojans.txt + + yes + + /var/lib/containerd + /var/lib/docker/overlay2 + + + + yes + 1800 + 1d + yes + + wodles/java + wodles/ciscat + + + + + yes + yes + /var/log/osquery/osqueryd.results.log + /etc/osquery/osquery.conf + yes + + + + + no + 1h + yes + yes + yes + yes + yes + yes + yes + yes + yes + yes + yes + + + + 10 + + + + + yes + yes + 12h + yes + + + + + no + + + 43200 + + yes + + + /etc,/usr/bin,/usr/sbin + /bin,/sbin,/boot + + + /etc/mtab + /etc/hosts.deny + /etc/mail/statistics + /etc/random-seed + /etc/random.seed + /etc/adjtime + /etc/httpd/logs + /etc/utmpx + /etc/wtmpx + /etc/cups/certs + /etc/dumpdates + /etc/svc/volatile + + + .log$|.swp$ + + + /etc/ssl/private.key + + yes + yes + yes + yes + + + 10 + + + 50 + + + + yes + 5m + 10 + + + + + + command + df -P + 360 + + + + full_command + netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d + netstat listening ports + 360 + + + + full_command + last -n 20 + 360 + + + + + no + etc/wpk_root.pem + yes + + + + + plain + + +
+ + + + journald + journald + + + + syslog + /var/ossec/logs/active-responses.log + + + + syslog + /var/log/dpkg.log + + +