Appendix
We have now reached the Appendix chapter. Here, we will cover several custom Wazuh rules. Wazuh has already built thousands of rules to enhance its detection capabilities. However, we will write some important custom Wazuh rules to detect PowerShell, Linux Auditd, Kaspersky, and Symon-related alerts. This chapter covers the following topics:
- Custom PowerShell rules
- Custom Auditd rules
- Custom Kaspersky Endpoint Security rules
- Custom Sysmon rules