What problem does it solve?
Deploying host-based intrusion detection across Windows and Linux endpoints is error-prone: agents enroll but never connect, realtime FIM silently falls back to scheduled scans, and custom rules sit below the alert threshold. This Skill provides a verified, end-to-end workflow for deploying Wazuh/OSSEC HIDS with file integrity monitoring, rootkit detection, and SIEM integration.
Core Features & Use Cases
- Agent Deployment: Step-by-step Wazuh agent installation for Windows (MSI) and Linux (APT) with manager enrollment on ports 1514/1515.
- FIM & Rootkit Configuration: Ready-to-adapt syscheck and rootcheck XML covering critical directories, Windows registry keys, and exclusion lists for noisy files.
- Custom Detection Rules & Active Response: Local rules for binary modification, temp-directory executables, and SSH config changes, plus automated IP blocking and account disabling.
- Use Case: A security engineer needs PCI DSS 11.5 file integrity monitoring across a mixed fleet; this Skill walks through agent rollout, FIM policy, alert verification with Atomic Red Team tests, and forwarding alerts to Splunk or OpenSearch.
Quick Start
Ask the AI to configure Wazuh file integrity monitoring with realtime alerts on /etc and Windows registry Run keys, then verify alerts reach the SIEM.