Use Case
Last updated
Last updated
Execute step 12.
Open your Wazuh page (https://<your_ip>).
It would be appear an event about VirusTotal detect the malware, the deletion of the file, and the activated response regarding to the malware, illustrated in Figure 23.
We can also check in the IRIS to see the ticket that automatic created.
Execute step 13.
Before simulate the web defacement, open the given link (http://<your_ip>:3000) in your browser. It will direct you to the example website that created by the script.
Then, start the web defacement. It will change the website appearance.
We can see in the Wazuh for the detection of file content changes. The rule id is 550 with the description is Integrity Checksum Changed.