Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wazuh Agent Integration #32

Open
kgoode517 opened this issue Oct 7, 2023 · 0 comments
Open

Wazuh Agent Integration #32

kgoode517 opened this issue Oct 7, 2023 · 0 comments

Comments

@kgoode517
Copy link

kgoode517 commented Oct 7, 2023

At a high level -- can you summarize your request?
I would very much like to be able to send the data from mac monitor to my wazuh server xdr/siem for analysis. This would require a custom decoder and rules
and shipping off from the agent. Wazuh already supports macos formated logs

What is the current alternative solution?
On a Mac? Very little Defender/Intune maybe there is no sysmon or auditd for macs like this appears to be.

Are there "In-the-Wild" threats or corresponding ATT&CK techniques that exist for which this telemetry would be helpful?
So many threats have been emerging for apple products lately this kind of enhanced telemetry would really give defenders an advantage in detection as sysmon does for windows systems.

Anything else?
N/A

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants