logo

Detecting Malicious C2 Server Traffic via Google Calendar Phishing Attack Using Wazuh & Suricata

ID: c3eedf16-0bfa-57a7-82b6-b69e5c887c86

STIX ID: report--c3eedf16-0bfa-57a7-82b6-b69e5c887c86

Feed Name: Detect FYI

Date Published: 2025-06-03

Date Updated: 2026-04-19

Author: Justin Duru

...
...

This guide details configuring Wazuh Manager to execute an active response that isolates a Windows host when a 'certutil' download event (rule 92075) is detected, and provides a workaround to block a suspicious IP using a Bash script after difficulties aligning a Suricata-triggered response; the isolation disables all network traffic on the affected endpoint until manually reversed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.