github ossec/ossec-hids 4.4.0

4 hours ago

OSSEC changelog (4.4.0) support@atomicorp.com

Release Maintainers

Scott R. Shinn (https://www.atomicorp.com)

Contributors on this release

Release Notes

OSSEC 4.4.0 adds three main capabilities; other enhancements and fixes are listed below.

  • Windows FIM attributes and ACLs — Opt-in check_attrs for Hidden/System/attribute change alerts and check_acl for NTFS DACL/ACE matrix alerts (#1352, #2285).
  • GeoIP via libmaxminddb — Replaces EOL GeoIP Legacy with GeoLite2 MMDB lookups, plus ASN/country enrichment and GeoIP IDS rules (#1828, #2259).
  • JSON syslog alerts — ossec-csyslogd forwards analysisd JSON alerts so agent_name is a first-class field. jsonout stays on when the XML tag is omitted; alerts rotation remains with monitord (#1907, #2302).

General

  • @atomicturtle - Add opt-in Windows FIM check_attrs for Hidden/System/attribute change alerts (#1352)
  • @atomicturtle - Add opt-in Windows FIM check_acl for NTFS DACL/ACE matrix alerts
  • @ddpbsd / @atomicturtle - PR 1828 - Replace EOL GeoIP Legacy with libmaxminddb (GeoLite2 MMDB) for analysisd GeoIP
  • @atomicturtle - GeoIP IDS rules (multi-country auth, impossible-travel) plus ASN/country enrichment; SSH invalid-user dstuser extraction; feed if_matched_group when sid_prev_matched is also set
  • @atomicturtle - PR 2302 - Forward analysisd JSON alerts over syslog so agent_name is a first-class field; keep jsonout on when undeclared

Bug Fixes

Don't miss a new ossec-hids release

NewReleases is sending notifications on new releases.