As it clarify with name that it is host based intrusion detention system we need to set it up in host/server which we want to monitor.
Features
File Integrity checking
Log Monitoring
Rootkit detection
Active response
Log Monitoring
Rootkit detection
Active response
Compliance Requirements - PCI and HIPAA
Multi platform
Real-time and Configurable Alerts
Integration with current infrastructure
Centralized management
Agent and agentless monitoring
Multi platform
Real-time and Configurable Alerts
Integration with current infrastructure
Centralized management
Agent and agentless monitoring
Configuration
I did in Ubuntu so here are commands I used
sudo apt get update -y
sudo apt-get install apache2 -y
sudo apt-get install build-essential -y
sudo apt get update -y
wget https://github.com/ossec/ossec-hids/archive/2.9.2.tar.gz
sudo tar -zxvf 2.9.2.tar.gz
cd ossec-hids-2.9.2/
sudo ./install.sh
sudo /var/ossec/bin/ossec-control start
cd /home/ubuntu
wget https://github.com/ossec/ossec-wui/archive/master.zip
sudo apt-get install unzip -y
sudo unzip master.zip
mv ossec-wui-master /var/www/html/ossec
cd /var/www/html/ossec
./setup.sh
systemctl restart apache2
sudo apt-get update -y
sudo apt-get install php -y
sudo apt-get install build-essential gcc make apache2 libapache2-mod-php7.0 php7.0 php7.0-cli php7.0-common apache2-utils unzip wget sendmail inotify-tools -y
Comments
Post a Comment