Setting Up Virus Total With Wazuh For Windows Endpoint

Поділитися
Вставка
  • Опубліковано 29 вер 2024

КОМЕНТАРІ • 20

  • @kandikhan-y2b
    @kandikhan-y2b 4 місяці тому

    I am really thankful to you. I have successfully deployed Virus Total with Wazuh.. thanks once again

  • @gbaneousmane935
    @gbaneousmane935 Місяць тому +1

    Thanks very helpfull

  • @anthonykendall3969
    @anthonykendall3969 8 місяців тому +5

    Thank you! This was very helpful in the setup process. I was able to successful see the deleted attempts in Wazuh after the modifying of the python script.

  • @johnharrison712
    @johnharrison712 Місяць тому

    I would like to see how you would do this for an msp like a multi tenant.

  • @victorgarcia6661
    @victorgarcia6661 4 місяці тому +1

    hey and to save the step of putting the user name you can add a rule to the group windows for example
    C:\Users downloads

  • @anaselhabchi8064
    @anaselhabchi8064 4 місяці тому +1

    Hi thanks for this amazing video. I follow all the steps but i see no alert or deleted attempt in wazuh.

    • @anaselhabchi8064
      @anaselhabchi8064 4 місяці тому

      2024/05/12 18:59:07 wazuh-integratord: ERROR: Unable to run integration for -> integrations
      2024/05/12 18:59:07 wazuh-integratord: ERROR: While running virustotal -> in. Output: exception
      2024/05/12 18:59:07 wazuh-integratord: ERROR: Exit status was: 4

  • @papijelly
    @papijelly 7 місяців тому +3

    Thanks for the info. But can this be set up from the server ? what if I had 200 hundred machines.

    • @ReasonableITService
      @ReasonableITService  4 місяці тому +2

      ua-cam.com/video/D4L6BDmV82E/v-deo.htmlsi=ro7HJhB8N1XKxYBb

    • @eriknilsen_trainingday
      @eriknilsen_trainingday Місяць тому

      The free version would be using a PowerShell script to automate the deployment of the Wazuh agent across multiple Windows Instances.
      You can run this script locally on each system, or you can use PowerShell remoting "Invoke-Command" system.
      It would login inn with admin rights, then have the script invoke a webrequest to download and install the agent, start the service.
      Good practice is also running Remove-Item to clean up things after yourself.
      Using Deply tools is only really needed if you want to keep a lot of software updated across a fleet of systems. Otherwise highly overkill.

    • @ReasonableITService
      @ReasonableITService  26 днів тому +1

      @@eriknilsen_trainingday Yes and no. PDQ Deploy offers a completely free version that can easily be used to deploy custom scripts. Plus, it provides a convenient deployment progress status in the UI-something you’d struggle to replicate in a PowerShell script, especially if you’re not well-versed in PowerShell. PDQ Deploy isn’t overkill; in fact, it’s incredibly user-friendly and can handle a lot of the heavy lifting for you, especially if scripting isn’t your strong suit. It’s also worth noting that not everyone is comfortable with PowerShell. Getting PowerShell to work smoothly across a domain environment, especially with even basic security controls in place, can be an uphill battle due to issues like language mode, execution policy, etc.

    • @eriknilsen_trainingday
      @eriknilsen_trainingday 25 днів тому

      @@ReasonableITService just looked through the free tier again, and you’re right, it should do what you need in this instance. Might be a lot easier if not well versed in maintenance of the environment yes.

  • @explorerreviews5675
    @explorerreviews5675 7 місяців тому +1

    question: When i already have a windows machine connected to internet and able to download a free antivirus which not only covers all folders and memory from virus then why do i need this that on covers download folder ?

    • @ReasonableITService
      @ReasonableITService  7 місяців тому

      That's a good question and the short answer is, you don't. Matter of fact windows os has been coming with a built in Anti-virus since about Windows 8. BUT, the point is, a tool like this can grant you all kinds of further granular control and monitoring of your systems from a cyber-security perspective.

    • @Chris-mr8ef
      @Chris-mr8ef 4 місяці тому

      Windows defender can feed its logs to wazuh server , this is the best use case combining both.

  • @stevehoover6073
    @stevehoover6073 Місяць тому

    Thought this was going to be helpfull. I followed along a few times. but what came out wasn't an .exe file. Not sure if something has changed or a step was left out of this video that prevented me from getting the same results. I would enter this: pyinstaller -F
    emove-threat.py But I kept getting: Script file '\
    emove-threat.py' does not exist, while I was running P.S. from the folder with the file as you did here. I tried both with and without the header you mentioned having issues with.

    • @ReasonableITService
      @ReasonableITService  26 днів тому

      Try this:
      - Ensure your .py file name is exactly: remove-threat.py
      - Stick your remove-threat.py file on your desktop
      - Run powershell as admin
      - Type and run this command: cd c:\users\yourusername\desktop
      (be sure to replace 'yourusername' with your actual username)
      - Type and run this command: pyinstaller -F
      emove-threat.py