You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At a high level -- can you summarize your request?
I would very much like to be able to send the data from mac monitor to my wazuh server xdr/siem for analysis. This would require a custom decoder and rules and shipping off from the agent. Wazuh already supports macos formated logs
What is the current alternative solution?
On a Mac? Very little Defender/Intune maybe there is no sysmon or auditd for macs like this appears to be.
Are there "In-the-Wild" threats or corresponding ATT&CK techniques that exist for which this telemetry would be helpful?
So many threats have been emerging for apple products lately this kind of enhanced telemetry would really give defenders an advantage in detection as sysmon does for windows systems.
Anything else?
N/A
The text was updated successfully, but these errors were encountered:
At a high level -- can you summarize your request?
I would very much like to be able to send the data from mac monitor to my wazuh server xdr/siem for analysis. This would require a custom decoder and rules
and shipping off from the agent. Wazuh already supports macos formated logs
What is the current alternative solution?
On a Mac? Very little Defender/Intune maybe there is no sysmon or auditd for macs like this appears to be.
Are there "In-the-Wild" threats or corresponding ATT&CK techniques that exist for which this telemetry would be helpful?
So many threats have been emerging for apple products lately this kind of enhanced telemetry would really give defenders an advantage in detection as sysmon does for windows systems.
Anything else?
N/A
The text was updated successfully, but these errors were encountered: