agent - Cyber-JL/SEC-350-01 GitHub Wiki

   /var/ossec
           β”œβ”€β”€/active-response
           |     └──/bin
           |         β”œβ”€β”€ /default-firewall-drop
           |         β”œβ”€β”€ /disable-account
           |         β”œβ”€β”€ /firewalld-drop
           |         β”œβ”€β”€ /firewall-drop
           |         β”œβ”€β”€ /host-deny
           |         β”œβ”€β”€ /ip-customblock
           |         β”œβ”€β”€ /ipfw
           |         β”œβ”€β”€ /kaspersky
           |         β”œβ”€β”€ /kaspersky.py
           |         β”œβ”€β”€ /npf
           |         β”œβ”€β”€ /pf
           |         β”œβ”€β”€ /restart.sh
           |         β”œβ”€β”€ /restart-wazuh
           |         β”œβ”€β”€ /route-null
           |         └── /wazuh-slack
           β”œβ”€β”€/agentless
           |    β”œβ”€β”€ main.epx
           |    β”œβ”€β”€ register_host.sh
           |    β”œβ”€β”€ ssh_asa-fwsmconfig_diff
           |    β”œβ”€β”€ ssh.exp
           |    β”œβ”€β”€ ssh_foundry_diff
           |    β”œβ”€β”€ ssh_generic_diff
           |    β”œβ”€β”€ ssh_integrity_check_bsd
           |    β”œβ”€β”€ ssh_integrity_check_linux
           |    β”œβ”€β”€ sshlogin.exp
           |    β”œβ”€β”€ ssh_nopass.exp
           |    β”œβ”€β”€ ssh_pixconfig_diff
           |    └── su.exp
           β”œβ”€β”€/backup
           β”œβ”€β”€/bin
           |    β”œβ”€β”€ agent-auth
           |    β”œβ”€β”€ manage_agents
           |    β”œβ”€β”€ wazuh-agentd
           |    β”œβ”€β”€ wazuh-control
           |    β”œβ”€β”€ wazuh-execd
           |    β”œβ”€β”€ wazuah-logcollector
           |    β”œβ”€β”€ wazuah-modulesd
           |    └── wazuh-syscheckd
           β”œβ”€β”€/etc
           |    β”œβ”€β”€ client.keys
           |    β”œβ”€β”€ internal_options.conf
           |    β”œβ”€β”€ local_internal_options.conf
           |    β”œβ”€β”€ localtime
           |    β”œβ”€β”€ ossec.conf
           |    β”œβ”€β”€ /shared
           |    |    β”œβ”€β”€ agent.conf
           |    |    β”œβ”€β”€ ar.conf
           |    |    └── merged.mg
           |    └── wpk_root.pem
           β”œβ”€β”€/lib
           |    β”œβ”€β”€ libdbsync.so
           |    β”œβ”€β”€ librsync.so
           |    β”œβ”€β”€ libsyscollector.so
           |    β”œβ”€β”€ libsysinfo.so
           |    β”œβ”€β”€ libwazuhext.so
           |    └── libwazuhshared.so
           β”œβ”€β”€/logs
           |    β”œβ”€β”€active-response.log
           |    β”œβ”€β”€ossec.log
           |    └──/wazuh
           β”œβ”€β”€/queue
           |    β”œβ”€β”€/alerts
           |    |   β”œβ”€β”€/cfgaq
           |    |   └──/execq
           |    β”œβ”€β”€/diff
           |    β”œβ”€β”€/fim
           |    |   └──/db
           |    |       β”œβ”€β”€fim.db
           |    |       └──fim.db-journal
           |    β”œβ”€β”€/logcollector
           |    |   └──file_status.json
           |    β”œβ”€β”€/rids
           |    |   β”œβ”€β”€/001
           |    |   └──/sender_counter
           |    β”œβ”€β”€/sockets
           |    |   β”œβ”€β”€/com
           |    |   β”œβ”€β”€/control
           |    |   β”œβ”€β”€/logcollector
           |    |   β”œβ”€β”€/queue
           |    |   β”œβ”€β”€/syscheck
           |    |   β”œβ”€β”€/upgrade
           |    |   └──/wmodules
           |    └──/syscollector
           |        β”œβ”€β”€db
           |        |   └──local.db
           |        └──norm.config.json
           β”œβ”€β”€/ruleset
           |    └──/sca
           |        └──cis_centos8_linux.yml
           β”œβ”€β”€/tmp
           β”œβ”€β”€/var
           |    β”œβ”€β”€/incoming
           |    β”œβ”€β”€/run
           |    |   β”œβ”€β”€wazuh-agentd-10672.pid
           |    |   β”œβ”€β”€wazuh-agentd.state
           |    |   β”œβ”€β”€wazuh-execd-10660.pid
           |    |   β”œβ”€β”€wazuh-logcollector-10700.pid
           |    |   β”œβ”€β”€wazuh-logcollector.state
           |    |   β”œβ”€β”€wazuh-modulesd-10718.pid
           |    |   └──wazuh-syscheckd-10687.pid
           |    β”œβ”€β”€/syslinux
           |    |   └──wazuh.pp
           |    β”œβ”€β”€/upgrade
           |    └──/wodles
           └──/wodles
               β”œβ”€β”€/aws
               |   └──/aws-s3
               β”œβ”€β”€/docker
               |   └──DockerListener
               β”œβ”€β”€/gcloud
               |   β”œβ”€β”€/buckets
               |   |   β”œβ”€access_logs.py
               |   |   └──bucket.py
               |   β”œβ”€β”€/gcloud
               |   β”œβ”€β”€integration.py
               |   β”œβ”€β”€/pubsub
               |   |   └──subscriber.py
               |   β”œβ”€β”€tools.py
               β”œβ”€β”€__init__.py
               └──utils.py