Wazuh (fork of OSSEC) has integrated osquery (<htt...
# general
d
Wazuh (fork of OSSEC) has integrated osquery (https://github.com/wazuh/wazuh/releases/tag/v3.5.0 )
s
interesting. I'm curious about why they selected OSSEC as their basis over osquery in the first place. I've used both and can't really think of an advantage OSSEC has.
I suppose osquery may not have existed when Wazuh started
d
Wazuh’s first release was in late 2015… Either way, for me, it was a pretty clear decision to move from OSSEC to osquery when I saw what I could do with osquery…. I still keep up with OSSEC/Wazuh, though…
👍 1
m
maybe they just really like xml 😉
😆 2
d
Security Onion uses OSSEC/Wazuh. I will be presenting this fall at the SO conference on integrating osquery with SO - trying to tie network & endpoint data more closely together.
m
oh cool! did you see @steffen’s talk at querycon about this?
d
I saw the GH repo but not the recording… Not up the on the site yet?
m
unfortunately steffen didn’t want the video posted.
d
ok, no worries…. Thanks!