Exercise 1 – Using Wazuh to add Sysmon logging
As a first exercise for this chapter, we are going to add Sysmon logs to the Security Onion data, by installing the Sysmon driver on endpoints and having Wazuh forward to Security Onion the logs it creates for us.
The following passage is taken from the Sysinternals site (who created Sysmon—see https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon):
In...