Skip to content

Latest commit

 

History

History
11 lines (6 loc) · 847 Bytes

File metadata and controls

11 lines (6 loc) · 847 Bytes

Custom Rules

There are many rules that are included in Wazuh that will alert you about all sorts of activity. However, its always a good idea to know how to create and implement custom rules. In this example, with the help of ai, I created a rule to track when a guest user account was enabled on a Windows machine. The guest account is disabled by default, but attackers might want to enable them so they can use them to gain privilege on a machine.

Here is an example of my custom rule in Wazuh:

Screenshot of the rule added to the custom rules section in Wazuh.

After creating the rule and adding it to the Wazuh server, I then enabled the guest account myself to check that the rule would generate the event.

Screenshot of the event created by the custom rule in Wazuh.