<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://xinux.net/index.php?action=history&amp;feed=atom&amp;title=HIDS_-_Neue_Techniken</id>
	<title>HIDS - Neue Techniken - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://xinux.net/index.php?action=history&amp;feed=atom&amp;title=HIDS_-_Neue_Techniken"/>
	<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;action=history"/>
	<updated>2026-08-23T18:32:55Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72346&amp;oldid=prev</id>
		<title>Thomas.will am 29. Juli 2026 um 15:16 Uhr</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72346&amp;oldid=prev"/>
		<updated>2026-07-29T15:16:19Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 29. Juli 2026, 15:16 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot; &gt;Zeile 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Wazuh-Agent auf Debian- und Rocky-Clients=&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Wazuh-Agent auf Debian- und Rocky-Clients=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) &amp;amp;mdash; der Agent liefert Host-Telemetrie ans SIEM und führt bei den letzten beiden POCs auch aktiv Gegenmaßnahmen aus (HIPS-Teil). Die Installation unterscheidet sich nur beim Paketmanager (apt vs. dnf), danach läuft auf beiden Distributionen exakt dieselbe Konfiguration. Manager in diesem Artikel: '''wazuh.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;dkbi&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;com&lt;/del&gt;'''.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) &amp;amp;mdash; der Agent liefert Host-Telemetrie ans SIEM und führt bei den letzten beiden POCs auch aktiv Gegenmaßnahmen aus (HIPS-Teil). Die Installation unterscheidet sich nur beim Paketmanager (apt vs. dnf), danach läuft auf beiden Distributionen exakt dieselbe Konfiguration. Manager in diesem Artikel: '''wazuh.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;it2XX&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;int&lt;/ins&gt;'''.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Agent-Installation auf Debian==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Agent-Installation auf Debian==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l18&quot; &gt;Zeile 18:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 18:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Agent installieren====&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Agent installieren====&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;und Namen &lt;/del&gt;installieren&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse installieren&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;dkbi&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;com&amp;quot; WAZUH_AGENT_NAME=&amp;quot;debian-host&lt;/del&gt;&amp;quot; apt install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;it2XX&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;int&lt;/ins&gt;&amp;quot; apt install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l52&quot; &gt;Zeile 52:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 52:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Agent installieren====&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Agent installieren====&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;und Namen &lt;/del&gt;installieren&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse installieren&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;dkbi&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;com&amp;quot; WAZUH_AGENT_NAME=&amp;quot;rocky-host&lt;/del&gt;&amp;quot; dnf install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;it2XX&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;int&lt;/ins&gt;&amp;quot; dnf install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72345&amp;oldid=prev</id>
		<title>Thomas.will am 29. Juli 2026 um 15:11 Uhr</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72345&amp;oldid=prev"/>
		<updated>2026-07-29T15:11:41Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;amp;diff=72345&amp;amp;oldid=72344&quot;&gt;Änderungen zeigen&lt;/a&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72344&amp;oldid=prev</id>
		<title>Thomas.will: /* Agent-Installation auf Rocky */</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72344&amp;oldid=prev"/>
		<updated>2026-07-29T15:07:22Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Agent-Installation auf Rocky&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 29. Juli 2026, 15:07 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l50&quot; &gt;Zeile 50:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 50:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse und Namen installieren&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse und Namen installieren&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.it2XX.int&amp;quot; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;WAZUH_AGENT_NAME=&amp;quot;rocky-host&amp;quot; &lt;/del&gt;dnf install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.it2XX.int&amp;quot; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/ins&gt;dnf install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72343&amp;oldid=prev</id>
		<title>Thomas.will: /* Agent installieren */</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72343&amp;oldid=prev"/>
		<updated>2026-07-29T15:06:03Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Agent installieren&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 29. Juli 2026, 15:06 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l16&quot; &gt;Zeile 16:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 16:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse und Namen installieren&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Agent mit Manager-Adresse und Namen installieren&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.it2XX.int&amp;quot; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;WAZUH_AGENT_NAME=&amp;quot;debian-host&amp;quot; &lt;/del&gt;apt install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;WAZUH_MANAGER=&amp;quot;wazuh.it2XX.int&amp;quot; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/ins&gt;apt install -y wazuh-agent&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Dienst aktivieren und starten&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l28&quot; &gt;Zeile 28:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 28:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;apt update&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;apt update&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Agent-Installation auf Rocky==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Agent-Installation auf Rocky==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Repository einrichten====&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;====Repository einrichten====&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72342&amp;oldid=prev</id>
		<title>Thomas.will am 29. Juli 2026 um 15:04 Uhr</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72342&amp;oldid=prev"/>
		<updated>2026-07-29T15:04:07Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;amp;diff=72342&amp;amp;oldid=72341&quot;&gt;Änderungen zeigen&lt;/a&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72341&amp;oldid=prev</id>
		<title>Thomas.will am 29. Juli 2026 um 14:59 Uhr</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72341&amp;oldid=prev"/>
		<updated>2026-07-29T14:59:09Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 29. Juli 2026, 14:59 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Zeile 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=Wazuh Server=&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;*[[Wazuh aufsetzen Template]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Wazuh-Agent auf Debian- und Rocky-Clients=&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Wazuh-Agent auf Debian- und Rocky-Clients=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) &amp;amp;mdash; der Agent liefert Host-Telemetrie ans SIEM und führt bei den letzten beiden POCs auch aktiv Gegenmaßnahmen aus (HIPS-Teil). Die Installation unterscheidet sich nur beim Paketmanager (apt vs. dnf), danach läuft auf beiden Distributionen exakt dieselbe Konfiguration. Manager in diesem Artikel: '''wazuh.dkbi.com'''.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) &amp;amp;mdash; der Agent liefert Host-Telemetrie ans SIEM und führt bei den letzten beiden POCs auch aktiv Gegenmaßnahmen aus (HIPS-Teil). Die Installation unterscheidet sich nur beim Paketmanager (apt vs. dnf), danach läuft auf beiden Distributionen exakt dieselbe Konfiguration. Manager in diesem Artikel: '''wazuh.dkbi.com'''.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72313&amp;oldid=prev</id>
		<title>Thomas.will: /* POC 1: Syscheck (FIM) auf sicherheitsrelevante Pfade */</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72313&amp;oldid=prev"/>
		<updated>2026-07-28T17:51:32Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;POC 1: Syscheck (FIM) auf sicherheitsrelevante Pfade&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 28. Juli 2026, 17:51 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l69&quot; &gt;Zeile 69:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 69:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=POC 1: Syscheck (FIM) auf sicherheitsrelevante Pfade=&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=POC 1: Syscheck (FIM) auf sicherheitsrelevante Pfade=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FIM überwacht &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;nicht nur Webserver-Uploads, sondern klassische Angriffsziele &lt;/del&gt;auf jedem Host&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;: &lt;/del&gt;SSH-Keys, Cron, sudoers&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;, &lt;/del&gt;die Passwort-/Shadow-Datei.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;FIM &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;(File Integrity Monitoring) &lt;/ins&gt;überwacht &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;die Integrität kritischer Dateien &lt;/ins&gt;auf jedem Host &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;– es erkennt, wenn Dateien wie &lt;/ins&gt;SSH-Keys, Cron&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;-Jobs&lt;/ins&gt;, sudoers &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;oder &lt;/ins&gt;die Passwort-/Shadow-Datei &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;unerwartet verändert werden. Das sind klassische Ziele, über die sich Angreifer dauerhaften Zugriff verschaffen oder Rechte ausweiten (z.B. ein zusätzlicher SSH-Key in authorized_keys, ein neuer Cron-Job als Persistenz-Mechanismus, oder eine manipulierte sudoers-Datei für Privilege Escalation)&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Ergänze in ''/var/ossec/etc/ossec.conf'' den syscheck-Block&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Ergänze in ''/var/ossec/etc/ossec.conf'' den syscheck-Block&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72261&amp;oldid=prev</id>
		<title>Thomas.will: Die Seite wurde neu angelegt: „=Wazuh-Agent auf Debian- und Rocky-Clients= Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) &amp;mdash; der Age…“</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=HIDS_-_Neue_Techniken&amp;diff=72261&amp;oldid=prev"/>
		<updated>2026-07-28T05:30:55Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „=Wazuh-Agent auf Debian- und Rocky-Clients= Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) — der Age…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Wazuh-Agent auf Debian- und Rocky-Clients=&lt;br /&gt;
Debian und Rocky sind hier reine Hardening-Übungsclients (kein Webserver, keine spezifische Rolle) &amp;amp;mdash; der Agent liefert Host-Telemetrie ans SIEM und führt bei den letzten beiden POCs auch aktiv Gegenmaßnahmen aus (HIPS-Teil). Die Installation unterscheidet sich nur beim Paketmanager (apt vs. dnf), danach läuft auf beiden Distributionen exakt dieselbe Konfiguration. Manager in diesem Artikel: '''wazuh.dkbi.com'''.&lt;br /&gt;
&lt;br /&gt;
==Agent-Installation auf Debian==&lt;br /&gt;
====Repository einrichten====&lt;br /&gt;
;GPG-Schlüssel importieren&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
curl -s https://packages.wazuh.com/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import&lt;br /&gt;
chmod 644 /usr/share/keyrings/wazuh.gpg&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Repository hinzufügen&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
echo &amp;quot;deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main&amp;quot; &amp;gt; /etc/apt/sources.list.d/wazuh.list&lt;br /&gt;
apt update&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
====Agent installieren====&lt;br /&gt;
;Agent mit Manager-Adresse und Namen installieren&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
WAZUH_MANAGER=&amp;quot;wazuh.dkbi.com&amp;quot; WAZUH_AGENT_NAME=&amp;quot;debian-host&amp;quot; apt install -y wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Dienst aktivieren und starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl daemon-reload&lt;br /&gt;
systemctl enable --now wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Repository deaktivieren (verhindert ungewollte Updates)&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sed -i &amp;quot;s/^deb /#deb /&amp;quot; /etc/apt/sources.list.d/wazuh.list&lt;br /&gt;
apt update&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Agent-Installation auf Rocky==&lt;br /&gt;
====Repository einrichten====&lt;br /&gt;
;GPG-Schlüssel importieren&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Repository hinzufügen&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
cat &amp;gt; /etc/yum.repos.d/wazuh.repo &amp;lt;&amp;lt; 'EOF'&lt;br /&gt;
[wazuh]&lt;br /&gt;
gpgcheck=1&lt;br /&gt;
gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH&lt;br /&gt;
enabled=1&lt;br /&gt;
name=EL-$releasever - Wazuh&lt;br /&gt;
baseurl=https://packages.wazuh.com/4.x/yum/&lt;br /&gt;
protect=1&lt;br /&gt;
EOF&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
====Agent installieren====&lt;br /&gt;
;Agent mit Manager-Adresse und Namen installieren&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
WAZUH_MANAGER=&amp;quot;wazuh.dkbi.com&amp;quot; WAZUH_AGENT_NAME=&amp;quot;rocky-host&amp;quot; dnf install -y wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Dienst aktivieren und starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl daemon-reload&lt;br /&gt;
systemctl enable --now wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Repository deaktivieren (verhindert ungewollte Updates)&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sed -i &amp;quot;s/^enabled=1/enabled=0/&amp;quot; /etc/yum.repos.d/wazuh.repo&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Kontrolle (beide Clients)====&lt;br /&gt;
* Öffne das Wazuh-Dashboard, gehe zu ''Agent Management &amp;amp;rarr; Summary'' und prüfe, ob '''debian-host''' und '''rocky-host''' mit Status '''Active''' erscheinen.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=POC 1: Syscheck (FIM) auf sicherheitsrelevante Pfade=&lt;br /&gt;
FIM überwacht nicht nur Webserver-Uploads, sondern klassische Angriffsziele auf jedem Host: SSH-Keys, Cron, sudoers, die Passwort-/Shadow-Datei.&lt;br /&gt;
;Ergänze in ''/var/ossec/etc/ossec.conf'' den syscheck-Block&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;syscheck&amp;gt;&lt;br /&gt;
  &amp;lt;directories check_all=&amp;quot;yes&amp;quot; report_changes=&amp;quot;yes&amp;quot; realtime=&amp;quot;yes&amp;quot;&amp;gt;/etc/ssh, /root/.ssh, /home/*/.ssh&amp;lt;/directories&amp;gt;&lt;br /&gt;
  &amp;lt;directories check_all=&amp;quot;yes&amp;quot; realtime=&amp;quot;yes&amp;quot;&amp;gt;/etc/cron.d, /etc/cron.daily, /var/spool/cron&amp;lt;/directories&amp;gt;&lt;br /&gt;
  &amp;lt;directories check_all=&amp;quot;yes&amp;quot; realtime=&amp;quot;yes&amp;quot;&amp;gt;/etc/sudoers.d&amp;lt;/directories&amp;gt;&lt;br /&gt;
  &amp;lt;directories check_all=&amp;quot;yes&amp;quot;&amp;gt;/etc/passwd, /etc/shadow, /etc/sudoers&amp;lt;/directories&amp;gt;&lt;br /&gt;
&amp;lt;/syscheck&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* ''realtime=&amp;quot;yes&amp;quot;'' funktioniert für Verzeichnisse (inotify) &amp;amp;mdash; einzelne Dateien wie ''/etc/passwd'' werden weiterhin nur im periodischen Scan geprüft (Standard: alle 12h), da inotify hier nicht greift.&lt;br /&gt;
* ''report_changes=&amp;quot;yes&amp;quot;'' zeigt bei Textdateien ein Diff im Alert &amp;amp;mdash; bei einer neuen ''authorized_keys''-Zeile siehst du sofort, welcher Key hinzugefügt wurde.&lt;br /&gt;
;Agent neu starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl restart wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
====Kontrolle====&lt;br /&gt;
* Test von der Konsole des Clients:&lt;br /&gt;
  &amp;lt;pre&amp;gt;&lt;br /&gt;
  echo &amp;quot;ssh-ed25519 AAAA...test angreifer@kali&amp;quot; &amp;gt;&amp;gt; /root/.ssh/authorized_keys&lt;br /&gt;
  &amp;lt;/pre&amp;gt;&lt;br /&gt;
* Öffne im Dashboard ''Threat Hunting'' und filtere auf ''rule.groups:syscheck''&lt;br /&gt;
* Alert &amp;quot;File modified&amp;quot; (Rule 550/554-Familie) für ''authorized_keys'' muss erscheinen, im Diff steht die neue Zeile.&lt;br /&gt;
&lt;br /&gt;
=POC 2: Rootcheck (Rootkit-/Anomalieerkennung)=&lt;br /&gt;
Rootcheck ist Wazuhs eingebauter Scanner für versteckte Prozesse/Ports und bekannte Trojaner-Signaturen &amp;amp;mdash; der Teil, der rkhunter/chkrootkit ersetzt. Er läuft standardmäßig aktiv, Frequenz und Umfang lassen sich anpassen.&lt;br /&gt;
;Prüfe/ergänze in ''/var/ossec/etc/ossec.conf''&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;rootcheck&amp;gt;&lt;br /&gt;
  &amp;lt;disabled&amp;gt;no&amp;lt;/disabled&amp;gt;&lt;br /&gt;
  &amp;lt;check_unixaudit&amp;gt;yes&amp;lt;/check_unixaudit&amp;gt;&lt;br /&gt;
  &amp;lt;check_files&amp;gt;yes&amp;lt;/check_files&amp;gt;&lt;br /&gt;
  &amp;lt;check_trojans&amp;gt;yes&amp;lt;/check_trojans&amp;gt;&lt;br /&gt;
  &amp;lt;check_dev&amp;gt;yes&amp;lt;/check_dev&amp;gt;&lt;br /&gt;
  &amp;lt;check_sys&amp;gt;yes&amp;lt;/check_sys&amp;gt;&lt;br /&gt;
  &amp;lt;check_pids&amp;gt;yes&amp;lt;/check_pids&amp;gt;&lt;br /&gt;
  &amp;lt;check_ports&amp;gt;yes&amp;lt;/check_ports&amp;gt;&lt;br /&gt;
  &amp;lt;frequency&amp;gt;3600&amp;lt;/frequency&amp;gt;&lt;br /&gt;
&amp;lt;/rootcheck&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* ''check_pids''/''check_ports'' vergleichen, was der Kernel meldet, gegen das, was Tools wie ''ps''/''netstat'' anzeigen &amp;amp;mdash; die klassische Rootkit-Erkennungsmethode (Prozess versteckt sich vor Userland-Tools, ist aber im Kernel sichtbar).&lt;br /&gt;
* ''check_trojans'' matcht Systembinaries gegen bekannte Trojaner-Signaturen (''/var/ossec/etc/shared/rootkit_trojans.txt'').&lt;br /&gt;
* ''frequency'' auf 3600s runtergesetzt, damit ihr in der Übung nicht 12h auf den nächsten Scan warten müsst.&lt;br /&gt;
;Agent neu starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl restart wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
====Kontrolle====&lt;br /&gt;
* Rootcheck lässt sich nicht einfach durch eine harmlose Aktion auslösen (das ist ja der Zweck) &amp;amp;mdash; zur Kontrolle reicht es, den erfolgreichen Scan-Lauf zu prüfen:&lt;br /&gt;
  &amp;lt;pre&amp;gt;&lt;br /&gt;
  tail -f /var/ossec/logs/ossec.log | grep rootcheck&lt;br /&gt;
  &amp;lt;/pre&amp;gt;&lt;br /&gt;
* Im Dashboard unter ''Threat Hunting'' filtere auf ''rule.groups:rootcheck'' &amp;amp;mdash; auf einem sauberen Client i.d.R. wenige/keine Alerts, das ist der Normalzustand.&lt;br /&gt;
&lt;br /&gt;
=POC 3: Security Configuration Assessment (SCA)=&lt;br /&gt;
SCA prüft die Systemkonfiguration gegen CIS-Benchmarks &amp;amp;mdash; für Debian und die RHEL-Familie (Rocky) gibt es jeweils eigene, mitgelieferte Policies.&lt;br /&gt;
;Verfügbare Policies prüfen&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ls /var/ossec/ruleset/sca/&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;SCA in ''/var/ossec/etc/ossec.conf'' aktivieren (Policy-Datei je nach Ausgabe des obigen Befehls anpassen)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;sca&amp;gt;&lt;br /&gt;
  &amp;lt;enabled&amp;gt;yes&amp;lt;/enabled&amp;gt;&lt;br /&gt;
  &amp;lt;scan_on_start&amp;gt;yes&amp;lt;/scan_on_start&amp;gt;&lt;br /&gt;
  &amp;lt;interval&amp;gt;12h&amp;lt;/interval&amp;gt;&lt;br /&gt;
  &amp;lt;policies&amp;gt;&lt;br /&gt;
    &amp;lt;policy&amp;gt;cis_debian_linux.yml&amp;lt;/policy&amp;gt;  &amp;lt;!-- auf Rocky entsprechend: cis_rhel9_linux.yml o.ä. --&amp;gt;&lt;br /&gt;
  &amp;lt;/policies&amp;gt;&lt;br /&gt;
&amp;lt;/sca&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
;Agent neu starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl restart wazuh-agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
====Kontrolle====&lt;br /&gt;
* Im Dashboard: ''Security Configuration Assessment'' &amp;amp;rarr; Agent auswählen&lt;br /&gt;
* Zeigt Pass/Fail-Quote pro Policy sowie jeden einzelnen Check (z.B. &amp;quot;Ensure permissions on /etc/passwd are configured&amp;quot;) mit Remediation-Hinweis&lt;br /&gt;
* Guter Vergleichspunkt Debian vs. Rocky: beide Policies prüfen ähnliche Punkte, aber mit unterschiedlichen Default-Ergebnissen (z.B. SELinux-Checks tauchen nur bei Rocky auf)&lt;br /&gt;
&lt;br /&gt;
=POC 4: Vulnerability Detection=&lt;br /&gt;
Anders als die vorherigen POCs wird dieses Modul zentral auf dem '''Manager''' aktiviert, nicht im Agent-''ossec.conf''. Es matched installierte Pakete gegen CVE-Feeds &amp;amp;mdash; bei Debian den Debian Security Tracker, bei Rocky die Red-Hat-OVAL-Daten.&lt;br /&gt;
;Auf dem Manager in ''/var/ossec/etc/ossec.conf'' prüfen/aktivieren&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;vulnerability-detection&amp;gt;&lt;br /&gt;
  &amp;lt;enabled&amp;gt;yes&amp;lt;/enabled&amp;gt;&lt;br /&gt;
  &amp;lt;index-status&amp;gt;yes&amp;lt;/index-status&amp;gt;&lt;br /&gt;
  &amp;lt;feed-update-interval&amp;gt;60m&amp;lt;/feed-update-interval&amp;gt;&lt;br /&gt;
&amp;lt;/vulnerability-detection&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
;Manager neu starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl restart wazuh-manager&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
====Kontrolle====&lt;br /&gt;
* Im Dashboard: ''Vulnerability Detection'' &amp;amp;rarr; Agent auswählen (debian-host bzw. rocky-host)&lt;br /&gt;
* Auf so gut wie jedem frisch installierten System stehen bereits einige CVEs in der Liste &amp;amp;mdash; kein künstlicher Test nötig, ihr müsst nur nach Severity (Critical/High) sortieren&lt;br /&gt;
* Guter Vergleichspunkt: dieselbe Software (z.B. OpenSSL) taucht bei Debian und Rocky ggf. mit unterschiedlichem Patch-Stand und damit unterschiedlichen CVEs auf&lt;br /&gt;
&lt;br /&gt;
=POC 5: Active Response &amp;amp;mdash; SSH-Brute-Force mit nftables blocken=&lt;br /&gt;
Das ist der eigentliche HIPS-Teil: Wazuh löst bei erkanntem Brute-Force selbstständig eine Gegenmaßnahme auf dem Client aus. Das mitgelieferte ''firewall-drop''-Skript zielt auf iptables &amp;amp;mdash; da ihr nftables nutzt, bauen wir ein eigenes Skript.&lt;br /&gt;
&lt;br /&gt;
====nftables-Grundgerüst auf dem Client====&lt;br /&gt;
;Set und Drop-Regel anlegen (falls noch nicht vorhanden)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
table inet filter {&lt;br /&gt;
    set blocklist {&lt;br /&gt;
        type ipv4_addr&lt;br /&gt;
        flags timeout&lt;br /&gt;
    }&lt;br /&gt;
    chain input {&lt;br /&gt;
        type filter hook input priority 0; policy accept;&lt;br /&gt;
        ip saddr @blocklist drop&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Active-Response-Skript auf dem Client====&lt;br /&gt;
;''/var/ossec/active-response/bin/nft-drop'' anlegen&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
read -r INPUT_JSON&lt;br /&gt;
COMMAND=$(echo &amp;quot;$INPUT_JSON&amp;quot; | jq -r .command)&lt;br /&gt;
IP=$(echo &amp;quot;$INPUT_JSON&amp;quot; | jq -r .parameters.alert.data.srcip)&lt;br /&gt;
&lt;br /&gt;
case ${COMMAND} in&lt;br /&gt;
  add)&lt;br /&gt;
    nft add element inet filter blocklist &amp;quot;{ ${IP} timeout 30m }&amp;quot;&lt;br /&gt;
    ;;&lt;br /&gt;
  delete)&lt;br /&gt;
    nft delete element inet filter blocklist &amp;quot;{ ${IP} }&amp;quot;&lt;br /&gt;
    ;;&lt;br /&gt;
esac&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
;Ausführbar machen&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
chmod 750 /var/ossec/active-response/bin/nft-drop&lt;br /&gt;
chown root:wazuh /var/ossec/active-response/bin/nft-drop&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Konfiguration auf dem Manager====&lt;br /&gt;
;''&amp;lt;command&amp;gt;'' und ''&amp;lt;active-response&amp;gt;'' in ''/var/ossec/etc/ossec.conf'' (Manager) ergänzen&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;command&amp;gt;&lt;br /&gt;
  &amp;lt;name&amp;gt;nft-drop&amp;lt;/name&amp;gt;&lt;br /&gt;
  &amp;lt;executable&amp;gt;nft-drop&amp;lt;/executable&amp;gt;&lt;br /&gt;
  &amp;lt;timeout_allowed&amp;gt;yes&amp;lt;/timeout_allowed&amp;gt;&lt;br /&gt;
&amp;lt;/command&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;active-response&amp;gt;&lt;br /&gt;
  &amp;lt;command&amp;gt;nft-drop&amp;lt;/command&amp;gt;&lt;br /&gt;
  &amp;lt;location&amp;gt;local&amp;lt;/location&amp;gt;&lt;br /&gt;
  &amp;lt;rules_id&amp;gt;5712&amp;lt;/rules_id&amp;gt;&lt;br /&gt;
  &amp;lt;timeout&amp;gt;1800&amp;lt;/timeout&amp;gt;&lt;br /&gt;
&amp;lt;/active-response&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Rule '''5712''' ist Wazuhs eingebaute Brute-Force-Regel: 8 fehlgeschlagene SSH-Logins von derselben Quell-IP innerhalb von 120 Sekunden.&lt;br /&gt;
* ''timeout_allowed=yes'' + ''&amp;lt;timeout&amp;gt;1800&amp;lt;/timeout&amp;gt;'' heißt: nach 30 Minuten entfernt Wazuh den Block automatisch selbst (ruft das Skript nochmal mit ''delete'' auf) &amp;amp;mdash; wichtig, damit sich niemand dauerhaft aussperrt.&lt;br /&gt;
;Manager neu starten&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
systemctl restart wazuh-manager&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Kontrolle====&lt;br /&gt;
* Von der Kali aus 8+ fehlgeschlagene SSH-Logins gegen den Client, z.B.:&lt;br /&gt;
  &amp;lt;pre&amp;gt;&lt;br /&gt;
  hydra -l root -P /usr/share/wordlists/rockyou.txt -t 4 -f ssh://&amp;lt;client-ip&amp;gt;&lt;br /&gt;
  &amp;lt;/pre&amp;gt;&lt;br /&gt;
* Auf dem Client: ''nft list set inet filter blocklist'' &amp;amp;rarr; Angreifer-IP muss mit Timeout auftauchen&lt;br /&gt;
* ''tail -f /var/ossec/logs/active-responses.log'' auf dem Client zeigt den ''add''-Aufruf&lt;br /&gt;
* Im Dashboard: ''Threat Hunting'' &amp;amp;rarr; ''rule.id:5712'' (Erkennung) und ''rule.id:651'' (Active-Response ausgelöst)&lt;br /&gt;
* Weiterer SSH-Versuch von der Kali muss jetzt ins Leere laufen (Connection timeout, kein Reset)&lt;br /&gt;
&lt;br /&gt;
[[Kategorie:WAZUH]]&lt;/div&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
</feed>