-
Notifications
You must be signed in to change notification settings - Fork 32
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
FIM System tests: 0203 - Whodata #528
Milestone
Comments
Configurations
.
.
.
<!-- File integrity monitoring -->
<syscheck>
<disabled>no</disabled>
<!-- Frequency that syscheck is executed default every 12 hours -->
<frequency>43200</frequency>
<scan_on_start>yes</scan_on_start>
<!-- Directories to check (perform all possible verifications) -->
<directories>/etc,/usr/bin,/usr/sbin</directories>
<directories>/bin,/sbin,/boot</directories>
<directories check_all="yes" whodata="yes">/opt/fim_testing</directories>
.
.
.
.
.
.
<!-- File integrity monitoring -->
<syscheck>
<disabled>no</disabled>
<!-- Frequency that syscheck is executed default every 12 hours -->
<frequency>43200</frequency>
<!-- Default files to be monitored. -->
<directories recursion_level="320" check_all="yes" whodata="yes">C:\fim_testing</directories>
<directories recursion_level="0" restrict="regedit.exe$|system.ini$|win.ini$">%WINDIR%</directories>
.
.
.
|
Test create files on Centos 7 AgentAuditctl configuration
Files generated and related audit logs:
Wazuh test audit using automated scripts
Manual tests
The manager shows less alerts than it should (1000):
Adding files with content
Alerts on Manager:
|
Test Whodata in Windows
Deleting root folder:
Deleting files
|
Done in #537 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Objective
This issue's aim is to implement scenario
203 - Whodata
as specified in #493.Configuration
ossec.conf
files: FIM System tests: 0203 - Whodata #528 (comment)Audit
installed on Centos 7 AgentWhodata
enabled on Windows and Centos 7 AgentsTests
Automated tests
5010 files
Windows: OK, Centos7: Failed FIM System tests: 0203 - Whodata #528 (comment) & FIM System tests: 0203 - Whodata #528 (comment)Manual tests
Execution using touch
1000 files
Centos7: Failed FIM System tests. 0204: Whodata - auditd not installed #520 (comment)Execution using echo
1000 files
Centos7: Failed FIM System tests. 0204: Whodata - auditd not installed #520 (comment)Conclusions
The alerts were not properly generated in Linux Agents even using different creation methods.
The alerts were properly, generated, modified and deleted in Windows agents. Removing root folder or removing files with
shift+del
generates fewer alerts than expectedRegards,
Jose M
The text was updated successfully, but these errors were encountered: