diff --git a/roles/debian/wazuh/files/custom_wazuh_rules.xml b/roles/debian/wazuh/files/custom_wazuh_rules.xml index 8b9728ada..8248f3013 100644 --- a/roles/debian/wazuh/files/custom_wazuh_rules.xml +++ b/roles/debian/wazuh/files/custom_wazuh_rules.xml @@ -1,18 +1,14 @@ - - - - - HTTP 401 response code - web-accesslog - " 401 - - - - - 100100 + + + + 31101 - Multiple 401 errors from same source IP (possible brute force attempt) - no_full_log + Multiple web server 400 error codes + from the same source IP. + + T1595.002 + + web_scan,recon,pci_dss_6.5,pci_dss_11.4,gdpr_IV_35.7.d,nist_800_53_SA.11,nist_800_53_SI.4,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,