~5m27:29Auto Remove Malware With Wazuh Active Response! - Let's Build a Host Intrusion Detection System
May 12, 2021
Read: ~5m · You save: 22 min
Auto Remove Malware With Wazuh Active Response!
Automate malware removal with Wazuh Active Response! Detect and delete threats proactively. Build your own host intrusion detection system.
This article details the configuration of Wazuh to automatically remove detected malware using its Active Response feature, integrating with VirusTotal for threat intelligence. This approach aims to provide immediate response to malicious file introductions without manual intervention.
Previous Configuration and Current Objective
Previously, a Wazuh manager was configured to query VirusTotal via API calls upon file modifications or additions detected by Wazuh agents. This process involved retrieving a file's hash, submitting it to VirusTotal, and receiving threat intelligence. While this provided alerts about malicious files, it lacked an automated removal mechanism. The current objective is to implement an Active Response script that proactively removes identified malware, thereby reducing the window of opportunity for the malware to execute.
Configuration Steps
Achieving this automated removal requires several key configuration components on both the Wazuh manager and agent.
Wazuh Manager Configuration
-
Decoder and Rule Creation:
- A custom decoder is added to
localdecoder.xmlto log active response messages inactive-response.log. This decoder specifically looks for the string "remove positive threat located in". - A new rule is added to
local_rules.xml. This rule, with ID1000092and level12, is triggered when signature ID607fires. Signature ID607is a built-in Wazuh rule that fires when an active response script is executed. The new rule further refines this by matching the decoded string "remove positive" from the custom decoder, correlating it with a file removal due to a VirusTotal positive detection. The rule's description dynamically includes the file path of the removed file.
- A custom decoder is added to
-
Active Response Script Integration:
- A custom script, named
custom-remove-threat, is created and placed in the/var/ossec/integrations/directory on the Wazuh manager. This script enables the Wazuh manager to send an event to the agent via an AR socket, utilizing kernel modules for interaction with the Linux agent. - Permissions for this script are set to executable (
chmod +x) and ownership is changed toroot:ossec(chown root:ossec).
- A custom script, named
-
ossec.confConfiguration:- The
ossec.conffile on the manager is modified to define the active response command and integration. - Command Definition: A
<command>block is added to define a new command namedremove-threat. This command points to the executableremove-threat.sh(which will reside on the agent) and expects afile_namevariable. - Active Response Definition: An
<active-response>block is configured. It specifies the command name asremove-threat, sets the location tolocal(meaning it runs on the agent that triggered the response), and is not disabled. - Integration Definition: An
<integration>block is added forcustom-remove-threat. This integration is configured to run when rule ID87105fires, which is the built-in Wazuh rule for VirusTotal positive detections. The alert format is set tojson.
- The
-
Manager Restart: After applying these changes, the Wazuh manager must be restarted for the configurations to take effect.
Wazuh Agent Configuration
-
Active Response Script Deployment:
- A bash script named
remove-threat.shis created in the/var/ossec/active-response/bin/directory on the Wazuh agent. - The script uses the
rm -fcommand to forcefully remove a specified file. - Upon successful removal, it logs "remove positive threat" followed by the file path. If an error occurs, it logs an error message.
- Permissions are set to executable (
chmod +x) and ownership toroot:ossec(chown root:ossec).
- A bash script named
-
ossec.confConfiguration (Agent):- Within the agent's
ossec.conf, thesyscheckconfiguration is reviewed. - The
realtimesetting within thesyscheckconfiguration must be set toyes. This ensures that the Wazuh agent monitors directories in real-time, allowing for immediate detection and response when new files are added. Ifrealtimeis disabled, syscheck scans occur at intervals (defaulting to every 12 hours), which would delay the detection and removal of malware. - The Wazuh agent must be restarted after enabling
realtimemonitoring.
- Within the agent's
Testing the Configuration
To test the automated removal process:
- Tail Active Response Log: On the Wazuh manager, tail the
active-response.logfile (tail -f /var/ossec/logs/active-response.log). - Download Malware Sample: On the Wazuh agent, download a known malware sample. For testing purposes, the website
dosmalware.euis suggested as a source for malware samples. Awgetcommand can be used to download a.zipfile containing malware. - Observe Results:
- The Wazuh manager should receive the VirusTotal alert (rule ID
87105). - The manager will then trigger the
remove-threat.shactive response script on the agent. - The malicious file should be automatically removed from the agent's file system.
- The
active-response.logon the manager will show the execution of theremove-threat.shscript. - An
lscommand on the agent's directory where the file was downloaded should confirm the file's absence.
- The Wazuh manager should receive the VirusTotal alert (rule ID
Conclusion and Caution
This configuration enables Wazuh to act as a basic anti-virus solution by automatically removing detected malicious files. This automation provides immediate response capabilities, significantly reducing the risk posed by newly introduced malware.
However, users are advised to exercise caution with any automation. There is a potential for active response scripts to inadvertently remove critical system or application files if not configured precisely. It is crucial to ensure that the active response script targets only known malicious files and does not pose a risk to legitimate system operations.
The scripts and configuration syntax for this setup are available in the provided GitHub repository.
Introduction and Recap
The video begins by referencing a previous setup where Wazuh manager was configured to query VirusTotal for file hashes detected on agents. This process alerts users to malicious files but lacks automated removal capabilities.
- Previous video configured Wazuh manager to API call VirusTotal on file changes.
- Wazuh manager reads hash values of modified or added files.
- Wazuh queries VirusTotal to check for known threats associated with the hash.
- VirusTotal dashboard displays malicious file information and links.
- Current setup only alerts on malicious files, lacking automated removal.
Automated Malware Removal with Active Response
The core of this video is enabling Wazuh's Active Response to automatically remove detected malicious files, thereby reducing the need for manual intervention by security teams and improving response times.
- Goal: Enable Active Response to proactively remove malicious files.
- Automation eliminates the need for personnel to manually log onto servers.
- Wazuh manager and agent handle the file removal process.
- Achieves immediate response time once a file is deemed malicious.
- Script is called via Active Response to remove the file before malware can execute.
Configuration Overview
Setting up automated malware removal requires configuring the Wazuh manager with an integration and adding it to Active Response, and creating a bash script on the agent that Active Response will execute.
- Key configuration pieces: manager integration and agent-side bash script.
- Manager side: Build integration, add to Active Response.
- Agent side: Build bash script for Active Response to call locally.
- Configuration changes are available on the presenter's GitHub repo.
Wazuh Manager Configuration: Rules and Decoders
The process involves creating a decoder and a rule on the Wazuh manager to detect positive VirusTotal alerts, which then triggers the Active Response script.
- Need to build a decoder and rule to know when to call the script.
- Script is called upon receiving a positive VirusTotal alert.
- Decoder created in
decoder.xmlto log Active Response messages. - Rule created in
local_rules.xmlto detect positive VirusTotal hits. - Rule ID 100092 fires if signature ID 607 fires, which in turn fires if signature ID 600 fires.
- Rule 600 uses a built-in
ar_logdecoder and matches the string 'remove positive threat located in'. - Rule 607 indicates Active Response fired and ran a specific script.
- The new rule (100092) matches the string 'removed positive' to correlate with file removal due to VirusTotal.
Wazuh Manager Configuration: Integration Script
A custom script, `custom-remove-threat`, is placed in the Wazuh manager's integrations directory, and its permissions are set. This script enables the manager to send events to the agent via an AR socket.
- Script
custom-remove-threatplaced in/var/ossec/integrations/on the manager. - This script enables Wazuh manager to send an event to the agent on an AR socket.
- Uses kernel modules for Linux agents to interact and remove files.
- Script needs to be made executable (
chmod +x). - Ownership changed to
root:ossecfor the manager to run it.
Wazuh Manager Configuration: ossec.conf
The `ossec.conf` file on the manager is updated to define the `remove-threat` command and configure the Active Response settings, linking the command to the agent-side script and specifying local execution.
- Edit
ossec.confon the manager via the web UI or console. - Define the command: name
remove-threat, executableremove-threat.sh(on agent), expectsfile_namevariable. - Configure Active Response: command
remove-threat, locationlocal(runs on any triggering agent). - Add integration tag: name
custom-remove-threat, runs when rule ID87105(VirusTotal positive) fires, alert formatjson.
Wazuh Agent Configuration: Active Response Script
The `remove-threat.sh` script is deployed to the Wazuh agent's `active-response/dat/bin` directory, made executable, and its ownership is set correctly. This script performs the actual file removal.
- Deploy
remove-threat.shto/var/ossec/active-response/dat/bin/on the agent. - Script uses
rm -fto force removal of the specified file. - Logs 'remove positive threat' upon successful removal, correlating with manager rules.
- Logs an error message if removal fails.
- Set script as executable (
chmod +x). - Change ownership to
root:ossecfor the agent to run it.
Wazuh Agent Configuration: Syscheck Real-time Monitoring
A crucial setting in the agent's `ossec.conf` is ensuring `syscheck` real-time monitoring is enabled (`real-time=yes`) for directories to be scanned, allowing immediate detection and response to new files.
- In agent's
ossec.conf, locatesyscheckconfiguration. - Ensure
real-timeis set toyesfor monitored directories. - Real-time monitoring allows immediate detection of file additions.
- Default
syscheckscan interval is 12 hours, which is too slow for malware. - Enabling real-time ensures immediate alerting and Active Response triggering.
- Restart the Wazuh agent after making changes.
Testing the Automated Removal Process
The setup is tested by downloading a known malware sample using `wget`. The process is observed: VirusTotal detects the file, Wazuh manager triggers Active Response, and the agent removes the file, confirmed by `ls` command.
- Test site: dos-malware.eu used for malware samples.
- Simulate attacker downloading a malware file (
.zip) usingwget. - Observe
active-response.logon the manager. - Wazuh manager receives VirusTotal alert (11 engines detected malicious).
- Manager calls
remove-threat.shvia Active Response. - Agent removes the malicious file.
- Verification:
lscommand shows the file no longer exists. - Repeating the download attempt also results in the file being removed immediately.
Conclusion and Cautionary Notes
The video concludes by highlighting that this setup provides antivirus-like protection using open-source tools and Wazuh, but cautions users about the potential risks of automated actions and advises careful configuration.
- Wazuh, Active Response, and VirusTotal integration provide free antivirus protection.
- Automated removal prevents malware execution before it can run.
- Caution: Automation carries risks; unintended file deletion is possible.
- Ensure Active Response does not accidentally remove critical application files.
- Scripts and syntax will be posted in the video description.