|
1 |
| - <%- if @kernel == 'windows' -%> |
2 |
| - <syscheck> <!-- Default files to be monitored - system32 only. --> |
3 |
| - <directories check_all="yes">%WINDIR%/win.ini</directories> |
4 |
| - <directories check_all="yes">%WINDIR%/system.ini</directories> |
5 |
| - <directories check_all="yes">C:\autoexec.bat</directories> |
6 |
| - <directories check_all="yes">C:\config.sys</directories> |
7 |
| - <directories check_all="yes">C:\boot.ini</directories> |
8 |
| - <directories check_all="yes">%WINDIR%/System32/CONFIG.NT</directories> |
9 |
| - <directories check_all="yes">%WINDIR%/System32/AUTOEXEC.NT</directories> |
10 |
| - <directories check_all="yes">%WINDIR%/System32/at.exe</directories> |
11 |
| - <directories check_all="yes">%WINDIR%/System32/attrib.exe</directories> |
12 |
| - <directories check_all="yes">%WINDIR%/System32/cacls.exe</directories> |
13 |
| - <directories check_all="yes">%WINDIR%/System32/debug.exe</directories> |
14 |
| - <directories check_all="yes">%WINDIR%/System32/drwatson.exe</directories> |
15 |
| - <directories check_all="yes">%WINDIR%/System32/drwtsn32.exe</directories> |
16 |
| - <directories check_all="yes">%WINDIR%/System32/edlin.exe</directories> |
17 |
| - <directories check_all="yes">%WINDIR%/System32/eventcreate.exe</directories> |
18 |
| - <directories check_all="yes">%WINDIR%/System32/eventtriggers.exe</directories> |
19 |
| - <directories check_all="yes">%WINDIR%/System32/ftp.exe</directories> |
20 |
| - <directories check_all="yes">%WINDIR%/System32/net.exe</directories> |
21 |
| - <directories check_all="yes">%WINDIR%/System32/net1.exe</directories> |
22 |
| - <directories check_all="yes">%WINDIR%/System32/netsh.exe</directories> |
23 |
| - <directories check_all="yes">%WINDIR%/System32/rcp.exe</directories> |
24 |
| - <directories check_all="yes">%WINDIR%/System32/reg.exe</directories> |
25 |
| - <directories check_all="yes">%WINDIR%/regedit.exe</directories> |
26 |
| - <directories check_all="yes">%WINDIR%/System32/regedt32.exe</directories> |
27 |
| - <directories check_all="yes">%WINDIR%/System32/regsvr32.exe</directories> |
28 |
| - <directories check_all="yes">%WINDIR%/System32/rexec.exe</directories> |
29 |
| - <directories check_all="yes">%WINDIR%/System32/rsh.exe</directories> |
30 |
| - <directories check_all="yes">%WINDIR%/System32/runas.exe</directories> |
31 |
| - <directories check_all="yes">%WINDIR%/System32/sc.exe</directories> |
32 |
| - <directories check_all="yes">%WINDIR%/System32/subst.exe</directories> |
33 |
| - <directories check_all="yes">%WINDIR%/System32/telnet.exe</directories> |
34 |
| - <directories check_all="yes">%WINDIR%/System32/tftp.exe</directories> |
35 |
| - <directories check_all="yes">%WINDIR%/System32/tlntsvr.exe</directories> |
36 |
| - <directories check_all="yes">%WINDIR%/System32/drivers/etc</directories> |
37 |
| - <directories check_all="yes" realtime="yes">C:\Documents and Settings/All Users/Start Menu/Programs/Startup</directories> |
38 |
| - <directories check_all="yes" realtime="yes">C:\Users/Public/All Users/Microsoft/Windows/Start Menu/Startup</directories> |
39 |
| - <ignore type="sregex">.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$</ignore> |
| 1 | +<%- if @kernel == 'windows' -%> |
| 2 | +<syscheck> <!-- Default files to be monitored - system32 only. --> |
| 3 | + <directories check_all="yes">%WINDIR%/win.ini</directories> |
| 4 | + <directories check_all="yes">%WINDIR%/system.ini</directories> |
| 5 | + <directories check_all="yes">C:\autoexec.bat</directories> |
| 6 | + <directories check_all="yes">C:\config.sys</directories> |
| 7 | + <directories check_all="yes">C:\boot.ini</directories> |
| 8 | + <directories check_all="yes">%WINDIR%/System32/CONFIG.NT</directories> |
| 9 | + <directories check_all="yes">%WINDIR%/System32/AUTOEXEC.NT</directories> |
| 10 | + <directories check_all="yes">%WINDIR%/System32/at.exe</directories> |
| 11 | + <directories check_all="yes">%WINDIR%/System32/attrib.exe</directories> |
| 12 | + <directories check_all="yes">%WINDIR%/System32/cacls.exe</directories> |
| 13 | + <directories check_all="yes">%WINDIR%/System32/debug.exe</directories> |
| 14 | + <directories check_all="yes">%WINDIR%/System32/drwatson.exe</directories> |
| 15 | + <directories check_all="yes">%WINDIR%/System32/drwtsn32.exe</directories> |
| 16 | + <directories check_all="yes">%WINDIR%/System32/edlin.exe</directories> |
| 17 | + <directories check_all="yes">%WINDIR%/System32/eventcreate.exe</directories> |
| 18 | + <directories check_all="yes">%WINDIR%/System32/eventtriggers.exe</directories> |
| 19 | + <directories check_all="yes">%WINDIR%/System32/ftp.exe</directories> |
| 20 | + <directories check_all="yes">%WINDIR%/System32/net.exe</directories> |
| 21 | + <directories check_all="yes">%WINDIR%/System32/net1.exe</directories> |
| 22 | + <directories check_all="yes">%WINDIR%/System32/netsh.exe</directories> |
| 23 | + <directories check_all="yes">%WINDIR%/System32/rcp.exe</directories> |
| 24 | + <directories check_all="yes">%WINDIR%/System32/reg.exe</directories> |
| 25 | + <directories check_all="yes">%WINDIR%/regedit.exe</directories> |
| 26 | + <directories check_all="yes">%WINDIR%/System32/regedt32.exe</directories> |
| 27 | + <directories check_all="yes">%WINDIR%/System32/regsvr32.exe</directories> |
| 28 | + <directories check_all="yes">%WINDIR%/System32/rexec.exe</directories> |
| 29 | + <directories check_all="yes">%WINDIR%/System32/rsh.exe</directories> |
| 30 | + <directories check_all="yes">%WINDIR%/System32/runas.exe</directories> |
| 31 | + <directories check_all="yes">%WINDIR%/System32/sc.exe</directories> |
| 32 | + <directories check_all="yes">%WINDIR%/System32/subst.exe</directories> |
| 33 | + <directories check_all="yes">%WINDIR%/System32/telnet.exe</directories> |
| 34 | + <directories check_all="yes">%WINDIR%/System32/tftp.exe</directories> |
| 35 | + <directories check_all="yes">%WINDIR%/System32/tlntsvr.exe</directories> |
| 36 | + <directories check_all="yes">%WINDIR%/System32/drivers/etc</directories> |
| 37 | + <directories check_all="yes" realtime="yes">C:\Documents and Settings/All Users/Start Menu/Programs/Startup</directories> |
| 38 | + <directories check_all="yes" realtime="yes">C:\Users/Public/All Users/Microsoft/Windows/Start Menu/Startup</directories> |
| 39 | + <ignore type="sregex">.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$</ignore> |
40 | 40 |
|
41 |
| - <!-- Windows registry entries to monitor. --> |
42 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\batfile</windows_registry> |
43 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\cmdfile</windows_registry> |
44 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\comfile</windows_registry> |
45 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\exefile</windows_registry> |
46 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\piffile</windows_registry> |
47 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects</windows_registry> |
48 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Directory</windows_registry> |
49 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Folder</windows_registry> |
50 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Protocols</windows_registry> |
51 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Policies</windows_registry> |
52 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Security</windows_registry> |
53 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer</windows_registry> |
54 |
| - <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services</windows_registry> |
55 |
| - <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs</windows_registry> |
56 |
| - <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg</windows_registry> |
57 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</windows_registry> |
58 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce</windows_registry> |
59 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</windows_registry> |
60 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL</windows_registry> |
61 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies</windows_registry> |
62 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows</windows_registry> |
63 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</windows_registry> |
64 |
| - <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components</windows_registry> |
| 41 | + <!-- Windows registry entries to monitor. --> |
| 42 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\batfile</windows_registry> |
| 43 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\cmdfile</windows_registry> |
| 44 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\comfile</windows_registry> |
| 45 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\exefile</windows_registry> |
| 46 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\piffile</windows_registry> |
| 47 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects</windows_registry> |
| 48 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Directory</windows_registry> |
| 49 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Folder</windows_registry> |
| 50 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Protocols</windows_registry> |
| 51 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Policies</windows_registry> |
| 52 | + <windows_registry>HKEY_LOCAL_MACHINE\Security</windows_registry> |
| 53 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer</windows_registry> |
| 54 | + <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services</windows_registry> |
| 55 | + <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs</windows_registry> |
| 56 | + <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg</windows_registry> |
| 57 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</windows_registry> |
| 58 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce</windows_registry> |
| 59 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</windows_registry> |
| 60 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL</windows_registry> |
| 61 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies</windows_registry> |
| 62 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows</windows_registry> |
| 63 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</windows_registry> |
| 64 | + <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components</windows_registry> |
65 | 65 |
|
66 |
| - <!-- Windows files to ignore (static) --> |
67 |
| - <ignore>%WINDIR%/System32/LogFiles</ignore> |
68 |
| - <ignore>%WINDIR%/Debug</ignore> |
69 |
| - <ignore>%WINDIR%/WindowsUpdate.log</ignore> |
70 |
| - <ignore>%WINDIR%/iis6.log</ignore> |
71 |
| - <ignore>%WINDIR%/system32/wbem/Logs</ignore> |
72 |
| - <ignore>%WINDIR%/system32/wbem/Repository</ignore> |
73 |
| - <ignore>%WINDIR%/Prefetch</ignore> |
74 |
| - <ignore>%WINDIR%/PCHEALTH/HELPCTR/DataColl</ignore> |
75 |
| - <ignore>%WINDIR%/SoftwareDistribution</ignore> |
76 |
| - <ignore>%WINDIR%/Temp</ignore> |
77 |
| - <ignore>%WINDIR%/system32/config</ignore> |
78 |
| - <ignore>%WINDIR%/system32/spool</ignore> |
79 |
| - <ignore>%WINDIR%/system32/CatRoot</ignore> |
| 66 | + <!-- Windows files to ignore (static) --> |
| 67 | + <ignore>%WINDIR%/System32/LogFiles</ignore> |
| 68 | + <ignore>%WINDIR%/Debug</ignore> |
| 69 | + <ignore>%WINDIR%/WindowsUpdate.log</ignore> |
| 70 | + <ignore>%WINDIR%/iis6.log</ignore> |
| 71 | + <ignore>%WINDIR%/system32/wbem/Logs</ignore> |
| 72 | + <ignore>%WINDIR%/system32/wbem/Repository</ignore> |
| 73 | + <ignore>%WINDIR%/Prefetch</ignore> |
| 74 | + <ignore>%WINDIR%/PCHEALTH/HELPCTR/DataColl</ignore> |
| 75 | + <ignore>%WINDIR%/SoftwareDistribution</ignore> |
| 76 | + <ignore>%WINDIR%/Temp</ignore> |
| 77 | + <ignore>%WINDIR%/system32/config</ignore> |
| 78 | + <ignore>%WINDIR%/system32/spool</ignore> |
| 79 | + <ignore>%WINDIR%/system32/CatRoot</ignore> |
80 | 80 |
|
81 |
| - <!-- Windows registry entries to ignore. --> |
82 |
| - <registry_ignore>HKEY_LOCAL_MACHINE\Security\Policy\Secrets</registry_ignore> |
83 |
| - <registry_ignore>HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users</registry_ignore> |
84 |
| - <registry_ignore type="sregex">\Enum$</registry_ignore> |
85 |
| - </syscheck> |
| 81 | + <!-- Windows registry entries to ignore. --> |
| 82 | + <registry_ignore>HKEY_LOCAL_MACHINE\Security\Policy\Secrets</registry_ignore> |
| 83 | + <registry_ignore>HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users</registry_ignore> |
| 84 | + <registry_ignore type="sregex">\Enum$</registry_ignore> |
| 85 | +</syscheck> |
86 | 86 |
|
87 |
| - <%- else -%> |
88 |
| - <syscheck> |
89 |
| - <%- if @ossec_syscheck_disabled -%> |
90 |
| - <disabled><%= @ossec_syscheck_disabled %></disabled> |
91 |
| - <%- end -%> |
92 |
| - <%- if @ossec_syscheck_frequency -%> |
93 |
| - <frequency><%=@ossec_syscheck_frequency%></frequency> |
94 |
| - <%- end -%> |
95 |
| - <%- if @ossec_syscheck_scan_on_start -%> |
96 |
| - <scan_on_start><%=@ossec_syscheck_scan_on_start%></scan_on_start> |
97 |
| - <%- end -%> |
98 |
| - <%- if @ossec_syscheck_alert_new_files -%> |
99 |
| - <alert_new_files><%=@ossec_syscheck_alert_new_files%></alert_new_files> |
100 |
| - <%- end -%> |
101 |
| - <%- if @ossec_syscheck_auto_ignore -%> |
102 |
| - <auto_ignore frequency="10" timeframe="3600"><%=@ossec_syscheck_auto_ignore%></auto_ignore> |
103 |
| - <%- end -%> |
104 |
| - <%- if @ossec_syscheck_directories_1 -%> |
105 |
| - <directories check_all="yes"><%=@ossec_syscheck_directories_1%></directories> |
106 |
| - <%- end -%> |
107 |
| - <%- if @ossec_syscheck_directories_2 -%> |
108 |
| - <directories check_all="yes"><%=@ossec_syscheck_directories_2%></directories> |
109 |
| - <%- end -%> |
110 |
| - <%- if @ossec_syscheck_ignore_list -%> |
111 |
| - <%- @ossec_syscheck_ignore_list.each do |ignore_element| -%> |
112 |
| - <ignore><%= ignore_element %></ignore> |
113 |
| - <%- end -%> |
114 |
| - <%- end -%> |
115 |
| - <%- if @ossec_syscheck_ignore_type_1 -%> |
116 |
| - <ignore type="sregex"><%=@ossec_syscheck_ignore_type_1%></ignore> |
117 |
| - <%- end -%> |
118 |
| - <%- if @ossec_syscheck_ignore_type_2 -%> |
119 |
| - <ignore type="sregex"><%=@ossec_syscheck_ignore_type_2%></ignore> |
120 |
| - <%- end -%> |
121 |
| - <%- if @ossec_syscheck_nodiff -%> |
122 |
| - <nodiff><%=@ossec_syscheck_nodiff%></nodiff> |
123 |
| - <%- end -%> |
124 |
| - <%- if @ossec_syscheck_skip_nfs -%> |
125 |
| - <skip_nfs><%=@ossec_syscheck_skip_nfs%></skip_nfs> |
126 |
| - <%- end -%> |
127 |
| - </syscheck> |
| 87 | +<%- else -%> |
| 88 | +<syscheck> |
| 89 | + <%- if @ossec_syscheck_disabled -%> |
| 90 | + <disabled><%= @ossec_syscheck_disabled %></disabled> |
| 91 | + <%- end -%> |
| 92 | + <%- if @ossec_syscheck_frequency -%> |
| 93 | + <frequency><%=@ossec_syscheck_frequency%></frequency> |
| 94 | + <%- end -%> |
| 95 | + <%- if @ossec_syscheck_scan_on_start -%> |
| 96 | + <scan_on_start><%=@ossec_syscheck_scan_on_start%></scan_on_start> |
| 97 | + <%- end -%> |
| 98 | + <%- if @ossec_syscheck_alert_new_files -%> |
| 99 | + <alert_new_files><%=@ossec_syscheck_alert_new_files%></alert_new_files> |
| 100 | + <%- end -%> |
| 101 | + <%- if @ossec_syscheck_auto_ignore -%> |
| 102 | + <auto_ignore frequency="10" timeframe="3600"><%=@ossec_syscheck_auto_ignore%></auto_ignore> |
| 103 | + <%- end -%> |
| 104 | + <%- if @ossec_syscheck_directories_1 -%> |
| 105 | + <directories check_all="yes" whodata=<%=@ossec_syscheck_whodata%> realtime=<%=@ossec_syscheck_realtime%>><%=@ossec_syscheck_directories_1%></directories> |
| 106 | + <%- end -%> |
| 107 | + <%- if @ossec_syscheck_directories_2 -%> |
| 108 | + <directories check_all="yes" whodata=<%=@ossec_syscheck_whodata%> realtime=<%=@ossec_syscheck_realtime%>><%=@ossec_syscheck_directories_2%></directories> |
128 | 109 | <%- end -%>
|
| 110 | + <%- if @ossec_syscheck_ignore_list -%> |
| 111 | + <%- @ossec_syscheck_ignore_list.each do |ignore_element| -%> |
| 112 | + <ignore><%= ignore_element %></ignore> |
| 113 | + <%- end -%> |
| 114 | + <%- end -%> |
| 115 | + <%- if @ossec_syscheck_ignore_type_1 -%> |
| 116 | + <ignore type="sregex"><%=@ossec_syscheck_ignore_type_1%></ignore> |
| 117 | + <%- end -%> |
| 118 | + <%- if @ossec_syscheck_ignore_type_2 -%> |
| 119 | + <ignore type="sregex"><%=@ossec_syscheck_ignore_type_2%></ignore> |
| 120 | + <%- end -%> |
| 121 | + <%- if @ossec_syscheck_nodiff -%> |
| 122 | + <nodiff><%=@ossec_syscheck_nodiff%></nodiff> |
| 123 | + <%- end -%> |
| 124 | + <%- if @ossec_syscheck_skip_nfs -%> |
| 125 | + <skip_nfs><%=@ossec_syscheck_skip_nfs%></skip_nfs> |
| 126 | + <%- end -%> |
| 127 | + </syscheck> |
| 128 | +<%- end -%> |
0 commit comments