You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, when an Indicator of Compromise (IOC) is detected and classified as "Malware" in Wazuh (via YARA, Snort, Wazuh), no immediate alert is displayed on the client agent itself. This means end users might remain unaware of critical security threats affecting their system until they check logs or reports manually.
To enhance security awareness and speed up response times, this feature will add a real-time alert mechanism that triggers a pop-up notification on the client agent whenever an IOC classified as "Malware" is detected.
Expected Behavior
When Wazuh, Snort, or YARA rules detect an IOC categorized as "Malware", the client agent should trigger a notification or pop-up alert.
Description
Currently, when an Indicator of Compromise (IOC) is detected and classified as "Malware" in Wazuh (via YARA, Snort, Wazuh), no immediate alert is displayed on the client agent itself. This means end users might remain unaware of critical security threats affecting their system until they check logs or reports manually.
To enhance security awareness and speed up response times, this feature will add a real-time alert mechanism that triggers a pop-up notification on the client agent whenever an IOC classified as "Malware" is detected.
Expected Behavior
Possible Implementation Approaches
Client-Side Notification System
notify-send
for GNOME-based environments).Wazuh & Snort Integration
active-response/bin/custom-response.sh
to trigger a pop-up.wazuh-alerts.log
for malware events and send local notifications.User Configuration Options
Additional Considerations
The text was updated successfully, but these errors were encountered: