~5m27:29
Taylor Walton

Auto Remove Malware With Wazuh Active Response! - Let's Build a Host Intrusion Detection System

May 12, 2021

Read: ~5m · You save: 22 min

Auto Remove Malware With Wazuh Active Response!

Automate malware removal with Wazuh Active Response! Detect and delete threats proactively. Build your own host intrusion detection system.

This article details the configuration of Wazuh to automatically remove detected malware using its Active Response feature, integrating with VirusTotal for threat intelligence. This approach aims to provide immediate response to malicious file introductions without manual intervention.

Previous Configuration and Current Objective

Previously, a Wazuh manager was configured to query VirusTotal via API calls upon file modifications or additions detected by Wazuh agents. This process involved retrieving a file's hash, submitting it to VirusTotal, and receiving threat intelligence. While this provided alerts about malicious files, it lacked an automated removal mechanism. The current objective is to implement an Active Response script that proactively removes identified malware, thereby reducing the window of opportunity for the malware to execute.

Configuration Steps

Achieving this automated removal requires several key configuration components on both the Wazuh manager and agent.

Wazuh Manager Configuration

  1. Decoder and Rule Creation:

    • A custom decoder is added to localdecoder.xml to log active response messages in active-response.log. This decoder specifically looks for the string "remove positive threat located in".
    • A new rule is added to local_rules.xml. This rule, with ID 1000092 and level 12, is triggered when signature ID 607 fires. Signature ID 607 is a built-in Wazuh rule that fires when an active response script is executed. The new rule further refines this by matching the decoded string "remove positive" from the custom decoder, correlating it with a file removal due to a VirusTotal positive detection. The rule's description dynamically includes the file path of the removed file.
  2. Active Response Script Integration:

    • A custom script, named custom-remove-threat, is created and placed in the /var/ossec/integrations/ directory on the Wazuh manager. This script enables the Wazuh manager to send an event to the agent via an AR socket, utilizing kernel modules for interaction with the Linux agent.
    • Permissions for this script are set to executable (chmod +x) and ownership is changed to root:ossec (chown root:ossec).
  3. ossec.conf Configuration:

    • The ossec.conf file on the manager is modified to define the active response command and integration.
    • Command Definition: A <command> block is added to define a new command named remove-threat. This command points to the executable remove-threat.sh (which will reside on the agent) and expects a file_name variable.
    • Active Response Definition: An <active-response> block is configured. It specifies the command name as remove-threat, sets the location to local (meaning it runs on the agent that triggered the response), and is not disabled.
    • Integration Definition: An <integration> block is added for custom-remove-threat. This integration is configured to run when rule ID 87105 fires, which is the built-in Wazuh rule for VirusTotal positive detections. The alert format is set to json.
  4. Manager Restart: After applying these changes, the Wazuh manager must be restarted for the configurations to take effect.

Wazuh Agent Configuration

  1. Active Response Script Deployment:

    • A bash script named remove-threat.sh is created in the /var/ossec/active-response/bin/ directory on the Wazuh agent.
    • The script uses the rm -f command to forcefully remove a specified file.
    • Upon successful removal, it logs "remove positive threat" followed by the file path. If an error occurs, it logs an error message.
    • Permissions are set to executable (chmod +x) and ownership to root:ossec (chown root:ossec).
  2. ossec.conf Configuration (Agent):

    • Within the agent's ossec.conf, the syscheck configuration is reviewed.
    • The realtime setting within the syscheck configuration must be set to yes. This ensures that the Wazuh agent monitors directories in real-time, allowing for immediate detection and response when new files are added. If realtime is disabled, syscheck scans occur at intervals (defaulting to every 12 hours), which would delay the detection and removal of malware.
    • The Wazuh agent must be restarted after enabling realtime monitoring.

Testing the Configuration

To test the automated removal process:

  1. Tail Active Response Log: On the Wazuh manager, tail the active-response.log file (tail -f /var/ossec/logs/active-response.log).
  2. Download Malware Sample: On the Wazuh agent, download a known malware sample. For testing purposes, the website dosmalware.eu is suggested as a source for malware samples. A wget command can be used to download a .zip file containing malware.
  3. Observe Results:
    • The Wazuh manager should receive the VirusTotal alert (rule ID 87105).
    • The manager will then trigger the remove-threat.sh active response script on the agent.
    • The malicious file should be automatically removed from the agent's file system.
    • The active-response.log on the manager will show the execution of the remove-threat.sh script.
    • An ls command on the agent's directory where the file was downloaded should confirm the file's absence.

Conclusion and Caution

This configuration enables Wazuh to act as a basic anti-virus solution by automatically removing detected malicious files. This automation provides immediate response capabilities, significantly reducing the risk posed by newly introduced malware.

However, users are advised to exercise caution with any automation. There is a potential for active response scripts to inadvertently remove critical system or application files if not configured precisely. It is crucial to ensure that the active response script targets only known malicious files and does not pose a risk to legitimate system operations.

The scripts and configuration syntax for this setup are available in the provided GitHub repository.

Introduction and Recap

The video begins by referencing a previous setup where Wazuh manager was configured to query VirusTotal for file hashes detected on agents. This process alerts users to malicious files but lacks automated removal capabilities.

  • Previous video configured Wazuh manager to API call VirusTotal on file changes.
  • Wazuh manager reads hash values of modified or added files.
  • Wazuh queries VirusTotal to check for known threats associated with the hash.
  • VirusTotal dashboard displays malicious file information and links.
  • Current setup only alerts on malicious files, lacking automated removal.

Automated Malware Removal with Active Response

The core of this video is enabling Wazuh's Active Response to automatically remove detected malicious files, thereby reducing the need for manual intervention by security teams and improving response times.

  • Goal: Enable Active Response to proactively remove malicious files.
  • Automation eliminates the need for personnel to manually log onto servers.
  • Wazuh manager and agent handle the file removal process.
  • Achieves immediate response time once a file is deemed malicious.
  • Script is called via Active Response to remove the file before malware can execute.

Configuration Overview

Setting up automated malware removal requires configuring the Wazuh manager with an integration and adding it to Active Response, and creating a bash script on the agent that Active Response will execute.

  • Key configuration pieces: manager integration and agent-side bash script.
  • Manager side: Build integration, add to Active Response.
  • Agent side: Build bash script for Active Response to call locally.
  • Configuration changes are available on the presenter's GitHub repo.

Wazuh Manager Configuration: Rules and Decoders

The process involves creating a decoder and a rule on the Wazuh manager to detect positive VirusTotal alerts, which then triggers the Active Response script.

  • Need to build a decoder and rule to know when to call the script.
  • Script is called upon receiving a positive VirusTotal alert.
  • Decoder created in decoder.xml to log Active Response messages.
  • Rule created in local_rules.xml to detect positive VirusTotal hits.
  • Rule ID 100092 fires if signature ID 607 fires, which in turn fires if signature ID 600 fires.
  • Rule 600 uses a built-in ar_log decoder and matches the string 'remove positive threat located in'.
  • Rule 607 indicates Active Response fired and ran a specific script.
  • The new rule (100092) matches the string 'removed positive' to correlate with file removal due to VirusTotal.

Wazuh Manager Configuration: Integration Script

A custom script, `custom-remove-threat`, is placed in the Wazuh manager's integrations directory, and its permissions are set. This script enables the manager to send events to the agent via an AR socket.

  • Script custom-remove-threat placed in /var/ossec/integrations/ on the manager.
  • This script enables Wazuh manager to send an event to the agent on an AR socket.
  • Uses kernel modules for Linux agents to interact and remove files.
  • Script needs to be made executable (chmod +x).
  • Ownership changed to root:ossec for the manager to run it.

Wazuh Manager Configuration: ossec.conf

The `ossec.conf` file on the manager is updated to define the `remove-threat` command and configure the Active Response settings, linking the command to the agent-side script and specifying local execution.

  • Edit ossec.conf on the manager via the web UI or console.
  • Define the command: name remove-threat, executable remove-threat.sh (on agent), expects file_name variable.
  • Configure Active Response: command remove-threat, location local (runs on any triggering agent).
  • Add integration tag: name custom-remove-threat, runs when rule ID 87105 (VirusTotal positive) fires, alert format json.

Wazuh Agent Configuration: Active Response Script

The `remove-threat.sh` script is deployed to the Wazuh agent's `active-response/dat/bin` directory, made executable, and its ownership is set correctly. This script performs the actual file removal.

  • Deploy remove-threat.sh to /var/ossec/active-response/dat/bin/ on the agent.
  • Script uses rm -f to force removal of the specified file.
  • Logs 'remove positive threat' upon successful removal, correlating with manager rules.
  • Logs an error message if removal fails.
  • Set script as executable (chmod +x).
  • Change ownership to root:ossec for the agent to run it.

Wazuh Agent Configuration: Syscheck Real-time Monitoring

A crucial setting in the agent's `ossec.conf` is ensuring `syscheck` real-time monitoring is enabled (`real-time=yes`) for directories to be scanned, allowing immediate detection and response to new files.

  • In agent's ossec.conf, locate syscheck configuration.
  • Ensure real-time is set to yes for monitored directories.
  • Real-time monitoring allows immediate detection of file additions.
  • Default syscheck scan interval is 12 hours, which is too slow for malware.
  • Enabling real-time ensures immediate alerting and Active Response triggering.
  • Restart the Wazuh agent after making changes.

Testing the Automated Removal Process

The setup is tested by downloading a known malware sample using `wget`. The process is observed: VirusTotal detects the file, Wazuh manager triggers Active Response, and the agent removes the file, confirmed by `ls` command.

  • Test site: dos-malware.eu used for malware samples.
  • Simulate attacker downloading a malware file (.zip) using wget.
  • Observe active-response.log on the manager.
  • Wazuh manager receives VirusTotal alert (11 engines detected malicious).
  • Manager calls remove-threat.sh via Active Response.
  • Agent removes the malicious file.
  • Verification: ls command shows the file no longer exists.
  • Repeating the download attempt also results in the file being removed immediately.

Conclusion and Cautionary Notes

The video concludes by highlighting that this setup provides antivirus-like protection using open-source tools and Wazuh, but cautions users about the potential risks of automated actions and advises careful configuration.

  • Wazuh, Active Response, and VirusTotal integration provide free antivirus protection.
  • Automated removal prevents malware execution before it can run.
  • Caution: Automation carries risks; unintended file deletion is possible.
  • Ensure Active Response does not accidentally remove critical application files.
  • Scripts and syntax will be posted in the video description.