Threat Hunting
APT:
TTPs:
Detection and Prevention:
Schedule Task Creation:
Installing Sysmon:
Wazuh Server config for Sysmon:
Creating an Active Response Script:
Configure Wazuh Agent to Monitor Response Log:


Now test to see if the scheduled-tasks.log is created
Creating the Rule:
Finished Product

Brute Force Attacks:
Wazuh Server setup:
Testing:
Final Output:

Phishing Emails:
Last updated