github wazuh/wazuh-ruleset v3.5.0
Wazuh Ruleset 3.5.0

latest releases: v3.13.6, v3.13.5, v3.13.4...
6 years ago

Added

  • Rules for the new osquery integration.
  • Rule to ignore syscollector events.
  • CIS-CAT rules improved.
  • Rules and decoders for the new Kaspersky integration.
  • CIS rootchecks for Windows 2012 R2 (by @Bob-Andrews).
  • Extract port name for Sysmon event 3. (#127)
  • Improve Shellshock detection. (#115)

Changed

  • Decreased agent upgrade failure rules level.

Fixed

  • Windows rules: Fix SID syntax for group membership changes. (#125).
  • Windows decoders: Match "Subject :" format (#128).

Don't miss a new wazuh-ruleset release

NewReleases is sending notifications on new releases.