-
Notifications
You must be signed in to change notification settings - Fork 510
Open
Description
I am basically trying to implement a home cyber sec lab using wazuh's single node setup and a ubuntu's docker image with the wazuh-agent file. The agent is up and running, the connection between the wazuh's and ubuntu's container is well and good. But, no alerts are shown when I try to perform MIT&RE attacks like T1059, T1547, etc... which is not getting detected by wazuh. I then checked the logs from agent's side, it's all good and normal, and from the manager's side, it is also showing no errors. But, I guess there is some problem with wazuh-agent package as it's not collecting essential data like these attacks.
Please help me here!
Thanks in advance
Metadata
Metadata
Assignees
Labels
No labels