mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 08:12:16 +00:00
Sysmon For Linux 
Sysmon for Linux to collect more endpoint telemetry. MUST INCLUDE the decoder-linux-sysmon.xml file under /var/ossec/etc/decoders/ or the Manager will fail to restart.
- DNS Queries
- File Hashes
- Network Connections
- And More!
Need Help?
SOCFortress - - info@socfortress.co