[
MAINHACK
]
Mail Test
BC
Config Scan
HOME
Create...
New File
New Folder
Viewing / Editing File: ossec_alert.py
File is not writable. Editing disabled.
""" Generates SensorAlert from ossec incidents with high severity """ from defence360agent.contracts.plugins import MessageSink, MessageSource, \ expect from defence360agent.contracts.messages import MessageType class OssecAlert(MessageSink, MessageSource): MIN_ALERT_LEVEL = 6 FIELDS = ('plugin_id', 'attackers_ip', 'rule', 'user', 'timestamp') async def create_sink(self, loop): self._loop = loop async def create_source(self, loop, sink): self._loop = loop self._sink = sink @expect(MessageType.SensorIncident, plugin_id='ossec') async def generate_alert(self, msg): if (msg['severity'] >= self.MIN_ALERT_LEVEL) \ and ('attackers_ip' in msg): alert = MessageType.SensorAlert( **{field: msg[field] for field in self.FIELDS if field in msg} ) await self._sink.process_message(alert)
Save Changes
Cancel / Back
Close ×
Server Info
Hostname: server05.hostinghome.co.in
Server IP: 192.168.74.40
PHP Version: 7.4.33
Server Software: Apache
System: Linux server05.hostinghome.co.in 3.10.0-962.3.2.lve1.5.81.el7.x86_64 #1 SMP Wed May 31 10:36:47 UTC 2023 x86_64
HDD Total: 1.95 TB
HDD Free: 691.14 GB
Domains on IP: N/A (Requires external lookup)
System Features
Safe Mode:
Off
disable_functions:
None
allow_url_fopen:
On
allow_url_include:
Off
magic_quotes_gpc:
Off
register_globals:
Off
open_basedir:
None
cURL:
Enabled
ZipArchive:
Disabled
MySQLi:
Enabled
PDO:
Enabled
wget:
Yes
curl (cmd):
Yes
perl:
Yes
python:
Yes
gcc:
Yes
pkexec:
No
git:
Yes
User Info
Username: itsweb
User ID (UID): 1619
Group ID (GID): 1621
Script Owner UID: 1619
Current Dir Owner: N/A