ClamAV and Wazuh: Sending Malware Alerts to Wazuh
This article details the integration of ClamAV, an open-source antivirus engine, with the Wazuh security monitoring platform to provide real-time alerts for detected malware on endpoints. The process leverages ClamAV's on-access scanning capabilities and Wazuh's log analysis and alerting features to automate malware detection and response.
Prerequisites
The setup assumes that a Wazuh agent is already installed and configured on the endpoint where ClamAV is running. ClamAV is configured for on-access scanning, meaning it automatically scans files as they are accessed.
Wazuh Agent Configuration for ClamAV Logs
Wazuh agents are designed to collect and forward log data from monitored systems. ClamAV, when configured for syslog, outputs its messages to /var/log/messages. The Wazuh agent, by default, is configured to forward this log file. This can be confirmed by examining the ossec.conf file on the agent, where the /var/log/messages file is typically included in the log forwarding configuration.
Wazuh Decoder Configuration
Wazuh includes pre-built rules and decoders for ClamAV. These are essential for parsing ClamAV log entries and triggering appropriate alerts. A critical aspect of this configuration is the program name that ClamAV uses when logging. By default, ClamAV logs often identify the program as clamd.
To verify or adjust this, one must access the Wazuh manager. The relevant decoder file is located at /var/ossec/etc/decoders/0075-clamav_decoder.xml. Within this file, the decoder is configured to match the program name clamd. If ClamAV was started with a different user or configuration, resulting in a different program name in the logs, this decoder must be updated to accurately reflect the logged program name. Failure to align the decoder with the actual logged program name will prevent Wazuh from correctly identifying and alerting on ClamAV findings.
Initiating Malware Detection and Alerts
Once ClamAV and Wazuh are configured, the process of detecting malware involves starting ClamAV's daemon and its on-access scanning service.
- Start ClamAV Daemon: The
clamddaemon is initiated to enable scanning services. - Start On-Access Scanning: The on-access scanning service is activated, typically configured to monitor a specific directory, such as
/ops. - Trigger Scan: A test file, such as a known malware sample (e.g., EICAR test file), is downloaded or created within the monitored directory. For instance, using
wgetto download a sample and thenunzipto extract it. - Observe ClamAV Output: ClamAV automatically scans the extracted file. Its detection is logged to
/var/log/messages. - Wazuh Alert Generation: The Wazuh agent monitors
/var/log/messages. Upon detecting a ClamAV log entry indicating malware, it forwards this information to the Wazuh manager. The manager processes the log using the ClamAV decoder and rules, generating a security event. - Alert Verification: The generated alert, typically titled "Virus ClamAV virus detected," can be viewed in the Wazuh interface under the "Security Events" tab. Parsing the alert reveals details such as the detected malware name (e.g., "Win.Adware").
Automated Malware Removal and Quarantine
ClamAV offers options for automated handling of detected malware:
Auto-Removal
By adding the --remove flag when starting the on-access scanning service, ClamAV will automatically delete detected malicious files.
- Configure Auto-Removal: The ClamAV on-access scanning service is restarted with the
--removeflag. - Trigger Scan: A malware sample is extracted in the monitored directory.
- Observe Removal: ClamAV detects the file and automatically removes it. The action is logged.
- Wazuh Alert: A corresponding alert is generated in Wazuh.
Caution: Automatic removal can be risky due to the possibility of false positives. ClamAV might incorrectly flag legitimate system files, leading to system instability.
Quarantine
A safer approach is to configure ClamAV to move detected files to a quarantine directory.
- Configure Quarantine: The on-access scanning service is restarted with the
--moveflag, specifying a quarantine directory (e.g.,/tmp/malicious). - Trigger Scan: A malware sample is extracted.
- Observe Quarantine: ClamAV detects the file, removes it from its original location, and places it in the specified quarantine directory.
- Wazuh Alert: A Wazuh alert is generated, indicating the malware detection.
Security Best Practice: It is recommended to set the ownership of the quarantine directory to the root user only. This prevents a compromised user account (without root privileges) from executing the quarantined malware.
Advantages of ClamAV and Wazuh Integration
This integration provides several benefits:
- Proactive Protection: ClamAV's on-access scanning operates at the kernel level, enabling proactive detection and prevention of malware execution before it can cause harm. This is more effective than post-execution analysis methods.
- Automation: The combined system automates the detection, alerting, and optional removal or quarantine of malware, reducing manual intervention and response times.
- Enhanced Security Stack: ClamAV complements existing security measures by providing a robust endpoint-level antivirus solution integrated with a comprehensive security monitoring platform like Wazuh.
- Streamlined Incident Response: Alerts generated by Wazuh can be further integrated with Security Orchestration, Automation, and Response (SOAR) tools or sent via email to security teams, facilitating rapid incident response.
In summary, the integration of ClamAV with Wazuh offers a powerful, automated solution for detecting and responding to malware threats on endpoints, significantly enhancing an organization's security posture.
Facts extraction failed. Please try again later.
