Page 1 of 1

Rootkit_files.txt update

Posted: Thu Jan 06, 2022 10:18 am
by vlad$$$
Hello everyone.
I am testing OSSEC server + couple of agents.

How to keep rootkit_files.txt up to date for all agents?

I have made a simple bash cript to download this file from github to a server and put it to /var/ossec/etc/shared
But looks like this file isn't pushed to the agents.

Re: Rootkit_files.txt update

Posted: Fri Jan 07, 2022 10:13 am
by cponton
It's pushed to the agents inside a file called merged.mg in the /var/ossec/shared/default directory