Showing posts with label roundup. Show all posts
Showing posts with label roundup. Show all posts

Monday, October 24, 2011

Third Annual Week of OSSEC

I'm a bit late to the party, but the Third Annual Week of OSSEC has begun. Michael Starks has planned a nice week, with some awesome blog posts. I've got a few I'm working on (hopefully I finish them).

Here's Michael's email to the ossec-list about the upcoming week. Sunday was day 1, so today is day 2:
"Tell your story. How has OSSEC helped you?"
 
For Day 2's blog post, Michael Starks posted 3WoO Day 2: Calculating Your EPS. He includes a little script to calculate your Events Per Second.
Knowing an estimate of your EPS is very important in specing out hardware, and preparing the network for the extra load created by OSSEC.
Usually when I want an idea of how many EPS I'm getting I look at this:
I'll edit the post if there's anything more today.
 
More contributions:
Xavier Mertens posted on how he's creating maps with OSSEC and AfterGlow.
 
Update 2:
Daniel Cid posts about a new feature in OSSEC! 

Saturday, October 23, 2010

Second Annual Week of OSSEC Roundup: Day 7

It's the weekend, and I'm lazy so I haven't read these yet. No commentary.

2WoO Day 7: Supporting New Applications the Right Way by Michael Starks

WoO Day 7 : Tidbits by Jason Frisvold

My contribution: OSSEC Rules 101

The mailing list discussion: Day 7: Making it happen: who, what, when and how?

So what did everyone think of this year's Week of OSSEC? A big thanks to Michael Starks for making this happen!

Friday, October 22, 2010

Second Annual Week of OSSEC Roundup: Day 6

 2WoO Day 6: Running Multiple Instances on One Box by Michael Starks

WoO Day 6 : Layin' Down The Law by Jason Frisvold

Video of a web tool to view OSSEC alerts by @tatehansen. It looks pretty neat to me. Here is his email to the ossec list explaining that it's ruby on rails and mongodb.

Thursday, October 21, 2010

Second Annual Week of OSSEC Roundup: Day 5

A few weeks ago Mischael Starks msg'd me on IRC (#ossec on freenode!) about a crazy idea he had. He wanted to present Daniel Cid (creator of OSSEC, but you knew that) with a plaque to thank him for all of the work he's done. Here's dcid's blog post with information about the plaque: OSSEC Award daemon

Showing appreciation for the developers of your favorite projects is important. They work hard, often using their precious free time to make their creation the best that it can be. Most of the time they see the reported problems, critical blog posts, or angry tweets. They probably don't see a lot of the good stories, and I bet it can be a bit of a drag. So send them a thank you email, or submit a patch, buy them something from their Amazon wish list, or get them a beverage of their choice the next time you see them at a conference. I hear buying them pizza is a good idea.

I know I owe the OSSEC developers a big big thank you to a lot of developers for a lot of projects, but this post is about OSSEC. So a big thank you to dcid, jrossi, mstarks, atomicturtle, and others I can't think of at the moment! OSSEC's great because of you guys. OSSEC Team CONTRIBUTORS

2WoO Day 5: Taming File Integrity Alerts by Michael Starks has some great information on syscheck alerts. The syscheck_control -u kind of helps you create a new baseline. Although this will leave a window of time when syscheck won't be able to help you.
WoO Day 5 : Decoders Unite! by Jason Frisvold is a nice basic introduction to OSSEC decoders. I just want to remind everyone that we love user contributions! Feel free to send changes and additions to the mailing list, that's how OSSEC gets support for more logs.

OSSEC got a mention in the Internet Storm Center's Tools updates - Oct 2010 post! Thanks to Jim Clausing and the rest of the ISC handlers for the great resource!

And last but not least, here's the mailing list discussion for the day. The topic is '2WoO Day 5: Shared intelligence: what does an attack.' I'd love to see the OSSEC logs from a real penetration test (or even a real attack), but I doubt anyone would release that kind of information. Maybe in the future one of the capture the flag (CTF) competitions would do us the favor of installing OSSEC on a target?

If I see anything else posted, I'll update.

Tuesday, October 19, 2010

Second Annual Week of OSSEC Roundup: Day 3

Abusing OSSEC the Countermeasures - Michael Starks showed us how to break OSSEC yesterday, today he's showing us how to protect against these attacks.

Contributing to OSSEC - A post by Daniel Cid on giving back to the OSSEC community specifically, but the principles are probably the same for all Open Source/Free Software projects.

Meet the Agent by Jason Frisvold gives a great introduction to configuring agents through ossec.conf and shared/agent.conf

These next 2 posts seem to be the "go to" source for Bigfix and OSSEC integration:
Using Bigfix for Mass Deployments of OSSEC agents for Windows  by Shawn Jefferson

Monitoring your OSSEC installation with Bigfix also by by Shawn Jefferson

My contribution: OSSEC Decoders 101

EDIT:
And here's another just sent to the list: OSSEC to the rescue

The discussion topic of the day: 2WoO Day 3: Time to share: rules, configs, tips and tricks.

Monday, October 18, 2010

Second Week of OSSEC Roundup: Day 1

This is just a roundup of the Second Week of OSSEC (2WoO) posts on (or before) day 1:

Week of OSSEC: Day -2: Syngress released a few chapters of the OSSEC book, and is offering 30%.

PaloAlto Firewall Threat Monitoring Using OSSEC: @xme explains and posts a decoder and sample rules for a PaloAlto firewall.

2WoO Day 1: Crowdsourcing Log Integrity & Non-repudiation: Michael Starks discusses the idea of making hashes public to help prove logs weren't tampered with.

WoO Day 1 : Introduction: Jason Frisvold gives a quick introduction to what OSSEC is.

If I missed any, please let me know!