LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 12-16-2023, 10:32 PM   #1
vuthanhtu
LQ Newbie
 
Registered: Dec 2023
Posts: 4

Rep: Reputation: 0
Samhain and Wazuh


Hello everyone
I am a student. My thesis is compare samhain and wazuh. my teacher said me to demonstrate an easy attack and detect with samhain and wazuh. but i dont have idea and my knowledge of samhain is very basic. Please hint me and help me to detect this (i will custom this)

Last edited by vuthanhtu; 12-16-2023 at 10:34 PM.
 
Old 12-16-2023, 11:46 PM   #2
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,454
Blog Entries: 7

Rep: Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557
Posting homework questions is against the rules here.
 
Old 12-19-2023, 09:43 AM   #3
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,864

Rep: Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311
don't forget to read the rules:
Do not post homework assignments verbatim. We're happy to assist if you have specific questions or have hit a stumbling point, however. Let us know what you've already tried and what references you have used (including class notes, books, and searches) and we'll do our best to help. Keep in mind that your instructor might also be an LQ member.
 
Old 12-19-2023, 10:09 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,637

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by vuthanhtu View Post
Hello everyone
I am a student. My thesis is compare samhain and wazuh. my teacher said me to demonstrate an easy attack and detect with samhain and wazuh. but i dont have idea and my knowledge of samhain is very basic. Please hint me and help me to detect this (i will custom this)
So if we look things up for you, and write things for you, you'll 'custom' it and turn it in?? When do you actually learn, if this is your 'thesis'???
 
Old 12-19-2023, 10:17 AM   #5
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,864

Rep: Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311Reputation: 7311
Quote:
Originally Posted by TB0ne View Post
So if we look things up for you, and write things for you, you'll 'custom' it and turn it in?? When do you actually learn, if this is your 'thesis'???
Don't be so harsh, it is Xmas time here.
As an example, my brother (as a geophysicist) helped his wife write her thesis (that is, he wrote it for her) on an interesting part of Chinese cultural history.
 
Old 12-19-2023, 10:24 AM   #6
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,637

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by pan64 View Post
Don't be so harsh, it is Xmas time here.
As an example, my brother (as a geophysicist) helped his wife write her thesis (that is, he wrote it for her) on an interesting part of Chinese cultural history.
The OP showed zero effort, and its far different helping ones spouse, rather than asking volunteers on a forum to not only research things, but write it up too. A hand up is different than a hand-out.
 
Old 12-19-2023, 10:32 AM   #7
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,309

Rep: Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326
Quote:
Originally Posted by TB0ne View Post
So if we look things up for you, and write things for you, you'll 'custom' it and turn it in?? When do you actually learn, if this is your 'thesis'???
In my days as an Electronics techie, I met far too many engineers who had got their degrees and their jobs that way. Then they hired a techie (me) to do their work.

My vote goes to letting him learn now. Otherwise, with no clue about his thesis, and passing his exams by Knowledge Bulimia (cram it for the test, forget it after), we would be complicit in giving him a counterfeit degree.

Last edited by business_kid; 12-19-2023 at 10:34 AM.
 
1 members found this post helpful.
Old 12-19-2023, 01:29 PM   #8
jkirchner
Member
 
Registered: Apr 2007
Location: West Virginia
Distribution: Pop!_OS
Posts: 945

Rep: Reputation: 297Reputation: 297Reputation: 297
Samhain and Wazuh, didn't they go with Bilbo to take down Smaug?
 
Old 12-19-2023, 11:24 PM   #9
vuthanhtu
LQ Newbie
 
Registered: Dec 2023
Posts: 4

Original Poster
Rep: Reputation: 0
Sorry for my question.
I done my thesis about 80%, Wazuh is can do it, but Samhain is difficult for me. I read Samhain documentation but I have no idea to compare with Wazuh.
 
Old 12-19-2023, 11:43 PM   #10
GentleThotSeaMonkey
Member
 
Registered: Dec 2016
Posts: 338
Blog Entries: 4

Rep: Reputation: 128Reputation: 128
ChatGPT will not be annoyed by you asking it homework questions!
Quote:
Samhain and Wazuh are both security tools, but they serve different purposes.

1. **Samhain:**
- **Type:** Host-based intrusion detection system (HIDS).
- **Functionality:** Monitors system logs, file integrity, and detects suspicious activity on individual hosts.
- **Use Cases:** Focuses on host-level security, providing alerts for potential intrusions or unauthorized changes on a specific system.
- **Features:** File integrity checking, log analysis, rootkit detection.

2. **Wazuh:**
- **Type:** Integrated security information and event management (SIEM) solution.
- **Functionality:** Offers a broader scope, collecting and analyzing logs from various sources across a network to provide a comprehensive security overview.
- **Use Cases:** Suitable for centralized monitoring and management of security events across multiple systems.
- **Features:** Log analysis, intrusion detection, vulnerability detection, threat intelligence.

In summary, Samhain is more focused on individual host security with an emphasis on file integrity and log analysis, while Wazuh is a comprehensive SIEM solution that covers a wider range of security aspects across a network. The choice between them depends on your specific security needs and the scale of your environment.
 
Old 12-20-2023, 01:08 AM   #11
vuthanhtu
LQ Newbie
 
Registered: Dec 2023
Posts: 4

Original Poster
Rep: Reputation: 0
I have install Diamorphine rootkit but Samhain can not detect that, only policy ADD FILE
(version 3.0.1 and Ubuntu 18.04).
Link references: https://www.linuxquestions.org/quest...logins-925639/

CRIT : [2023-12-20T13:33:06+0700] msg=<POLICY ADDED>, path=</usr/lib/git-core/mergetools/examdiff>, mode_new=<-rw-r--r-->, attr_new=<------------>, imode_new=<33188>, iattr_new=<0>, hardlinks_new=<1>, idevice_new=<0>, inode_new=<1055470>, owner_new=<root>, iowner_new=<0>, group_new=<root>, igroup_new=<0>, size_old=<0>, size_new=<336>, ctime_new=<[2023-12-20T06:28:00]>, atime_new=<[2023-12-20T06:29:14]>, mtime_new=<[2023-04-26T14:14:45]>, chksum_new=<1F9F0C042946EEBD8A49A62211A8A67F8375244F7AF0D659>
CRIT : [2023-12-20T13:33:06+0700] msg=<POLICY ADDED>, path=</usr/lib/git-core/mergetools/diffuse>, mode_new=<-rw-r--r-->, attr_new=<------------>, imode_new=<33188>, iattr_new=<0>, hardlinks_new=<1>, idevice_new=<0>, inode_new=<1055378>, owner_new=<root>, iowner_new=<0>, group_new=<root>, igroup_new=<0>, size_old=<0>, size_new=<248>, ctime_new=<[2023-12-20T06:28:00]>, atime_new=<[2023-12-20T06:29:14]>, mtime_new=<[2023-04-26T14:14:45]>, chksum_new=<7DFB9224107EA8B6DFBD106FEAD5EB6E03046E3E89A8F668>
CRIT : [2023-12-20T13:33:06+0700] msg=<POLICY ADDED>, path=</usr/lib/git-core/mergetools/ecmerge>, mode_new=<-rw-r--r-->, attr_new=<------------>, imode_new=<33188>, iattr_new=<0>, hardlinks_new=<1>, idevice_new=<0>, inode_new=<1055454>, owner_new=<root>, iowner_new=<0>, group_new=<root>, igroup_new=<0>, size_old=<0>, size_new=<306>, ctime_new=<[2023-12-20T06:28:00]>, atime_new=<[2023-12-20T06:29:14]>, mtime_new=<[2023-04-26T14:14:45]>, chksum_new=<796A3B0C62B28BF63AD39D97EB7FCD951B09532391629736>
CRIT : [2023-12-20T13:33:06+0700] msg=<POLICY ADDED>, path=</usr/lib/git-core/mergetools/gvimdiff3>, mode_new=<-rw-r--r-->, attr_new=<------------>, imode_new=<33188>, iattr_new=<0>, hardlinks_new=<1>, idevice_new=<0>, inode_new=<1055523>, owner_new=<root>, iowner_new=<0>, group_new=<root>, igroup_new=<0>, size_old=<0>, size_new=<29>, ctime_new=<[2023-12-20T06:28:00]>, atime_new=<[2023-12-20T06:29:14]>, mtime_new=<[2023-04-26T14:14:45]>, chksum_new=<7C99D84D63A772586BA0174BB87A7F0720C5B1EEEDB58D4A>
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] I am using wazuh and get alert SSH Configuration - Empty passwords permitted muqor Linux - Server 3 02-08-2019 08:20 AM
[SOLVED] Email Notification not working for AIDE, Samhain and OSSEC in Ubuntu metalaarif Linux - General 14 01-05-2012 11:19 AM
Intrusion Detection and File Integrity Monitoring on Amazon EC2 using samhain? sneakyimp Linux - Security 15 08-10-2011 05:46 PM
Can Samhain log my entries in /var/log/secure and /var/log/mesage to a central server abefroman Linux - Software 2 04-13-2008 04:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 12:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration