wazuh-ruleset icon indicating copy to clipboard operation
wazuh-ruleset copied to clipboard

Added Win2016 rootchecks

Open Bob-Andrews opened this issue 6 years ago • 3 comments

Bob-Andrews avatar Jan 18 '19 13:01 Bob-Andrews

Hi @Bob-Andrews ,

That is really nice work. We really appreciate your contribution.

I have to tell you that these policies files used by Rootcheck in older versions have been translated and enriched for a new module called Configuration Assessment which will be released in Wazuh v3.9.0. Here you can see an example of a new policy file.

I already opened an issue to translate and enrich the policies you provide us in this PR. Here you can track the issue progress: https://github.com/wazuh/wazuh/issues/2629

Thank you again for your contribution!

Regards.

chemamartinez avatar Feb 19 '19 09:02 chemamartinez

Hey guys, i'm translating it to CAS and also updating to version 1.1.0 of CIS Benchmark, 'cause some rules was removed or changed. As i'm doing it because i need it ASAP, and i don't know how you would do on your files, so, mine probably will have different IDs. If you need it, please ask me. I'll probably put here on Git, i just need to know how.

agnutzmann avatar Aug 20 '19 15:08 agnutzmann

Hey guys, i'm translating it to CAS and also updating to version 1.1.0 of CIS Benchmark, 'cause some rules was removed or changed. As i'm doing it because i need it ASAP, and i don't know how you would do on your files, so, mine probably will have different IDs. If you need it, please ask me. I'll probably put here on Git, i just need to know how.

Hi @agnutzmann,

We cannot determine when the Windows Server 2016 policies will be translated to YML. For Wazuh v3.10 an important refactor for the policies has been performed (#406) including policies for new OS such as Debian 9, so, we are continuously working on extending the SCA policies to support the most Windows versions as possible as well.

If you want to contribute to the project with your developed policies, it would be very nice. You just have to create a new pull request to this repository.

chemamartinez avatar Sep 09 '19 12:09 chemamartinez