Endpoint Detection Lab
Wazuh file monitoring with YARA
A published walkthrough combining file-change monitoring with rule-based malware scanning.
Wazuh FIMYARA
Why this matters to a team
Scanning files as they change helps a team notice suspicious files sooner.
Problem
File-change alerts alone do not say whether a new file is malicious.
Documented approach
- 01Enable Wazuh file integrity monitoring on selected paths.
- 02Trigger YARA scans on changed files.
- 03Raise alerts on rule matches.
My contribution
Built the lab and published the walkthrough.
Evidence
Limitations
Lab walkthrough; no detection-rate figures are claimed.