From nobody Wed Jul 05 15:36:36 2023 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Qx3fr6CNpz4lLDb for ; Wed, 5 Jul 2023 15:36:36 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Qx3fr4bGDz49j4; Wed, 5 Jul 2023 15:36:36 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688571396; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Pw0QiNb0c27oSndDFBNnRjIrQnVAndFxO2Xyymq7ovM=; b=AVoL6vB+Xq4bJGcwfIbxKRVFP2HquKKy83G9UAEmE7l1C4lJfy3WYfkR8LFUUG7ulwM5tD 4nMC1xyVgGpBrTDR6cExTDNgUYxG1qOK+4t8xTXSTYXTAN5YO+DszX4HaIF5VvzIO8LnI5 dZ8soQ6/S1gDwwzG1TIS3o6csffST+PZ7WoR+PWvL8nABcM7o0r4kaYKvl9EbHkk5oXkRn g/Bb+tfNTWPK8odKflioNU1AHV2Mz1mXW8XStQzRyAxdyq8l/1m9aDVdQP/4Y3Y9N5sXX7 vOIQoEFOCkxaiSA8LUm+rPsrosYcctrkwnJkeUugywtaUxrjw4ioltAZRQDgOw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688571396; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Pw0QiNb0c27oSndDFBNnRjIrQnVAndFxO2Xyymq7ovM=; b=QQljt5f/zlnrM9UJGhFWMVJI3CNRg0yim/8TK+QPDLmNUnPJ1KKicLD9aI+h+oSBfZrWCx 1UbrPaKFDcf/bKPw5U3WMY2BURQLOm+CjDOoxfepOQAR5w71eno1RdZLjZANSJmTF1gosU Aj9UIiTR7JvuiyKxlOnPzEboQXlOSVltA5aWzsq53B4YyWk/tgQ2+sw2C0U5912UoIlgYI uFBw8g2az7YjFiQzE6O9FbgTKVhwCLWqer0hpVpjWEMDwTF4z0VvQoUZ8bCxeguj3LUb6n KdEqbv6MmQGhWoVQux7niO1x6JV9nBTcu933+kzD2Ap5Nb72V6zTkdQ/SH6BQw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1688571396; a=rsa-sha256; cv=none; b=TkQlcSoL54SZh3dAVcoehV0AP4exweYXef8F/2xmctHe1EyELHvGyvVkz3skMHw7ofuVwx JHbUT2nLH6bwFWVA3NpacqPS/BYq+rlqoWOEcUr8gDeJLnIzQemvAuHtrmOpnk8BRWVbUk nT7IeQhKJjpIcH9zSC2gcuz/gR4a549tFa1uvm5nrjFmMUgXoWg/1TQb+vr2GgUxbGBgLh es5C8pmflQBDld49vW9jKnMABWy9cjU98xW34580ufRDqVmqzzeo6MOrED/ms0FaBdV8iE jyc43aT/UKPAfR9J8GCi3pt4dYK6BMQo+rrStCY38iiz3dKw1q18D7+9j2pDdA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Qx3fr3GMmzKs7; Wed, 5 Jul 2023 15:36:36 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 365Faawa017423; Wed, 5 Jul 2023 15:36:36 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 365FaaaA017422; Wed, 5 Jul 2023 15:36:36 GMT (envelope-from git) Date: Wed, 5 Jul 2023 15:36:36 GMT Message-Id: <202307051536.365FaaaA017422@gitrepo.freebsd.org> To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org From: Lorenzo Salvadore Subject: git: 87bd216d39 - main - Status/2023Q2/wazuh.adoc Add report List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-doc-all@freebsd.org X-BeenThere: dev-commits-doc-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: salvadore X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 87bd216d39b0fb0b48075e04ed233d42ce58965c Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by salvadore: URL: https://cgit.FreeBSD.org/doc/commit/?id=87bd216d39b0fb0b48075e04ed233d42ce58965c commit 87bd216d39b0fb0b48075e04ed233d42ce58965c Author: José Alonso Cárdenas Márquez AuthorDate: 2023-07-05 15:27:26 +0000 Commit: Lorenzo Salvadore CommitDate: 2023-07-05 15:33:31 +0000 Status/2023Q2/wazuh.adoc Add report Reviewed by: status (Pau Amma ) Approved by: dbaio (mentor, implicit) --- .../en/status/report-2023-04-2023-06/wazuh.adoc | 40 ++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/website/content/en/status/report-2023-04-2023-06/wazuh.adoc b/website/content/en/status/report-2023-04-2023-06/wazuh.adoc new file mode 100644 index 0000000000..6d0589b5c6 --- /dev/null +++ b/website/content/en/status/report-2023-04-2023-06/wazuh.adoc @@ -0,0 +1,40 @@ +=== Wazuh on FreeBSD + +Links: + +link:https://www.wazuh.com/[Wazuh] URL: link:https://www.wazuh.com/[] + + +Contact: José Alonso Cárdenas Márquez + +Wazuh is a free and open source platform used for threat prevention, detection, and response. +It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. + +The Wazuh solution consists of an endpoint security agent, deployed to the monitored systems, and a management server, which collects and analyzes data gathered by the agents. +Besides, Wazuh has been fully integrated with the Elastic Stack or OpenSearch Stack, providing a search engine and data visualization tool that allows users to navigate through their security alerts. + +Wazuh porting to FreeBSD was started by mailto:m.muenz@gmail.com[Michael Muenz]. +The first Wazuh port he added to the FreeBSD ports tree was package:security/wazuh-agent[] in September 2021. +In July 2022, I took maintainership of this port and I started porting other Wazuh components. + +Currently, all Wazuh components are part of the FreeBSD ports tree. It includes package:security/wazuh-manager[], package:security/wazuh-agent[], +package:security/wazuh-server[], package:security/wazuh-indexer[] and package:security/wazuh-dashboard[] ports. + +On FreeBSD, package:security/wazuh-manager[] and package:security/wazuh-agent[] are compiled from Wazuh source code. +package:security/wazuh-indexer[] is an adapted package:textproc/opensearch[] used for storing agents data. +package:security/wazuh-server[] is a port for installing the package:security/wazuh-manager[], package:sysutils/beats8[] (filebeat), and package:sysutils/logstash8[] components. +It includes adapted configuration files to work on FreeBSD. +package:security/wazuh-dashboard[] uses an adapted package:textproc/opensearch-dashboards[] and the wazuh-kibana-app plugin generated from wazuh-kibana-app source code for FreeBSD. + +The main goal of this work is enhancing visibility of FreeBSD as a useful platform for information security or cybersecurity. + +Additionally, you can test a Wazuh single-node infrastructure (All-in-one) easily using link:https://github.com/alonsobsd/wazuh-makejail[] or link:https://github.com/AppJail-makejails/wazuh[] from link:https://github.com/DtxdF/AppJail[AppJail]. +AppJail is a good tool for managing jail containers from the command line. + +People interested in helping with the project are welcome. + +Current version: 4.4.4 + +TODO + +* Add Wazuh cluster-mode infrastructure makejail (Work in progress) +* Add FreeBSD to platforms officially supported by Wazuh Inc; see link:https://github.com/wazuh/wazuh-kibana-app/pull/5413[] +* Add FreeBSD SCA Policy (Work in progress)