mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-11-02 04:43:15 +00:00
Sophos Integration 
Sophos is an AntiVirus solution that can block malicious software from being executed on your endpoints. Alerts can be ingested via the Sophos Central Siem Integration and ingested into Wazuh. This intetragation assumes you have downloaded the Sohpos Central Siem Integration script found below.
Sophos Central Siem Integration Repo
Alerts will need to be ingested via a JSON format and written to a file that the Wazuh Manager is collecting for analysis.
Need Help?
SOCFortress - - info@socfortress.co