
Description
Someone quietly edits a system file, a registry key changes, and an alert sits unread in a log. By the time you notice, it is already after the fact. The OSSEC Windows agent is the pair of eyes you install on each monitored machine, watching for tampered files and traces of rootkits so you do not have to.
It is the client half of the OSSEC host-based intrusion detection system: the agent runs on every machine while policies and alerts are managed centrally by the server. Enter the server address and the authentication key and it is connected; there is no daily UI to babysit, because all configuration lives in a single text file.
File integrity checking: Compares system folders on a schedule and reports which file changed.
Registry monitoring: Spots changes in the sensitive registry areas without manual diffing.
Rootkit detection: Looks for traces left behind by rootkits.
Real-time event log: Watches the Windows event log and streams suspicious events such as odd logins or service changes to the server.
Configuration check: Compares the machine against policy and points out what is not compliant.
Pick your components: Choose only what you need during setup, for example IIS log monitoring or the integrity module.
Plain-text configuration: Every parameter sits in one config file, easy to roll out in bulk and keep under version control.
It is the client half of the OSSEC host-based intrusion detection system: the agent runs on every machine while policies and alerts are managed centrally by the server. Enter the server address and the authentication key and it is connected; there is no daily UI to babysit, because all configuration lives in a single text file.
Features
File integrity checking: Compares system folders on a schedule and reports which file changed.
Registry monitoring: Spots changes in the sensitive registry areas without manual diffing.
Rootkit detection: Looks for traces left behind by rootkits.
Real-time event log: Watches the Windows event log and streams suspicious events such as odd logins or service changes to the server.
Configuration check: Compares the machine against policy and points out what is not compliant.
Pick your components: Choose only what you need during setup, for example IIS log monitoring or the integrity module.
Plain-text configuration: Every parameter sits in one config file, easy to roll out in bulk and keep under version control.
