Update README.md
This commit is contained in:
@@ -346,12 +346,8 @@ tail -f /var/ossec/logs/alerts/alerts.log
|
|||||||
|
|
||||||
## Known Gaps / Future Work
|
## Known Gaps / Future Work
|
||||||
|
|
||||||
- **XFF / real client IP** - Web traffic through NPM means web attack alerts attribute NPM's IP as the source. Custom XFF decoder not yet written.
|
|
||||||
- **Mailcow Postfix/rspamd rules** - Suppression rules are in place; detection rules (spam relay attempts, auth failures) not yet written.
|
- **Mailcow Postfix/rspamd rules** - Suppression rules are in place; detection rules (spam relay attempts, auth failures) not yet written.
|
||||||
- **Active response** - `firewall-drop` and `host-deny` commands are defined but no active response blocks are configured. Not enabled.
|
- **Active response** - `firewall-drop` and `host-deny` commands are defined but no active response blocks are configured. Not enabled.
|
||||||
- **Whitelist placeholder** - `WHITELISTED_IPs` in the second `<global>` block needs replacing with actual LAN ranges.
|
|
||||||
- **`WAZUH_SERVER_IP` placeholder** - syslog remote listener has a placeholder local IP that needs setting.
|
|
||||||
- **`email_from` placeholder** - `YOUR_EMAIL` in `ossec.conf` needs a real address.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user