Detecting Malicious C2 Server Traffic via Google Calendar Phishing Attack Using Wazuh & Suricata
ID: c3eedf16-0bfa-57a7-82b6-b69e5c887c86
STIX ID: report--c3eedf16-0bfa-57a7-82b6-b69e5c887c86
Feed Name: Detect FYI
This guide details configuring Wazuh Manager to execute an active response that isolates a Windows host when a 'certutil' download event (rule 92075) is detected, and provides a workaround to block a suspicious IP using a Bash script after difficulties aligning a Suricata-triggered response; the isolation disables all network traffic on the affected endpoint until manually reversed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
