Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

T1166_Seuid_and_Setgid rules triggered by Zabbix agent #3

Open
j91321 opened this issue Mar 5, 2020 · 2 comments
Open

T1166_Seuid_and_Setgid rules triggered by Zabbix agent #3

j91321 opened this issue Mar 5, 2020 · 2 comments
Assignees
Labels
bug Something isn't working

Comments

@j91321
Copy link
Owner

j91321 commented Mar 5, 2020

Zabbix agents when executing custom scripts as extensions will trigger a lot of T1166_Seuid_and_Setgid rules. Since Zabbix agent usually has a lot of various checks done by custom scripts this should be excluded.

Adding

-F uid!=zabbix

to these rules should be enough (correctly installed agent should have zabbix user) to stop the rules from spamming.

@j91321 j91321 added the bug Something isn't working label Mar 5, 2020
@j91321 j91321 self-assigned this Mar 5, 2020
@j91321 j91321 changed the title High triggering of T1166_Seuid_and_Setgid rules by Zabbix agent T1166_Seuid_and_Setgid rules triggered by Zabbix agent Mar 5, 2020
@j91321
Copy link
Owner Author

j91321 commented Mar 5, 2020

Same filtering should be applied to wazuh/ossec agents. Based on group name "ossec".

@rado-van
Copy link

Zabbix triggered also rule T1059.006_5, that led into a lot of spam

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants