<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.1.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>OSSEC Home</title>
	<link>http://www.ossec.net/main</link>
	<description>OSSEC's Home</description>
	<pubDate>Thu, 02 Jul 2009 18:20:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.3</generator>
	<language>en</language>
			<item>
		<title>OSSEC v2.1 released</title>
		<link>http://www.ossec.net/main/ossec-v21-released</link>
		<comments>http://www.ossec.net/main/ossec-v21-released#comments</comments>
		<pubDate>Tue, 30 Jun 2009 12:14:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v21-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 2.1.
This new version is the first one with support for centralized configurations and realtime integrity monitoring on Linux. It also includes many other features and bug fixes:

Centralized configuration - The agent.conf file was introduced to allow granular configuration of the agents directly on the [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="/main/downloads/">version 2.1</a>.<br />
This new version is the first one with support for centralized configurations and realtime integrity monitoring on Linux. It also includes many other features and bug fixes:</p>
<ul>
<li><strong>Centralized configuration</strong> - The <em>agent.conf</em> file was introduced to allow granular configuration of the agents directly on the manager side. </li>
<li><strong>Remote agent restart</strong> - Functionality was added to restart the agents remotely using the <em>agent_control</em> tool.</li>
<li><strong>Real time integrity checking</strong> - Real time integrity checking was added to Linux systems.</li>
<li><strong>New Log Rules Support</strong> - We added support for Windows DHCP logs and fixed/improved many of the other rules for different messages.</li>
</ul>
<p>And much more&#8230; Check the <a href="/announcements/v2.1-2009-06-30.txt">changelog</a> to see all changes and contributors.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p><em>Special thanks to Chris Bailes, Matt Goldsberry, phishphreek, Michael Starks, Danny Fullerton, Slava Semushin and Peter Wolanin for helping with this release.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v21-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>I (HEART) OSSEC</title>
		<link>http://www.ossec.net/main/i-heart-ossec</link>
		<comments>http://www.ossec.net/main/i-heart-ossec#comments</comments>
		<pubDate>Fri, 19 Jun 2009 13:07:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/i-heart-ossec</guid>
		<description><![CDATA[This is a guest article by Justin Foster of  DevelopingSecurity.com


In the open source world some projects have taken on beloved status by their loyal user base. OSSEC is one of them, and for good reason.
For those of you unfamiliar, OSSEC (pronounced Oh-Sec) is an Open Source Host-based Intrusion Detection System. It performs log analysis, [...]]]></description>
			<content:encoded><![CDATA[<p><em>This is a guest article by <strong>Justin Foster</strong> of <a target="_blank" href="http://developingsecurity.com"> DevelopingSecurity.com</a></em>
</p>
<p><img alt="Iheartossec" src="http://www.developingsecurity.com/.a/6a011279135bcf28a40115702e2a59970c-250wi" style="margin: 0px 0px 5px 5px; width: 220px;" align="right" /></p>
<p>In the open source world some projects have taken on beloved status by their loyal user base. OSSEC is one of them, and for good reason.</p>
<p>For those of you unfamiliar, <a href="http://www.ossec.net/main/" target="_blank">OSSEC</a> (pronounced Oh-Sec) is an Open Source Host-based Intrusion Detection System. It performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. </p>
<p>Over a year and a half ago I was tasked to review OSSEC as a potential acquisition for Third Brigade. I was of course, sufficiently impressed with OSSEC&#8217;s capabilities, but I was surprised at the level of respect it had developed in the community. I was curious as to why OSSEC had such a solid reputation.</p>
<p>Recently I have gotten to know the man who literally wrote <a href="http://www.amazon.com/OSSEC-Host-Based-Intrusion-Detection-Guide/dp/159749240X/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1245324171&amp;sr=8-1"target="_blank">the book</a> on OSSEC, <a href="http://www.andrewhay.ca/" target="_blank">Andrew Hay</a>. Andrew is a well respected figure in the security community and has authored several security texts in addition to his <a href="http://www.andrewhay.ca/" target="_blank">daily blogs</a>.  He thinks, &#8220;The key drivers to the product are 1) the cost, 2) the ease to deploy, and 3) the community wrapped around it&#8221;. </p>
<p>It&#8217;s true, like other popular open source security projects (like <a href="http://www.snort.org/" target="_blank">Snort</a>), OSSEC has a strong community. Its members get involved by contributing to <a href="http://www.ossec.net/wiki/index.php/OSSEC" target="_blank">the wiki</a>, communicating on the <a href="http://groups.google.com/group/ossec-list" target="_blank">mailing-list</a>, and discussing OSSEC on <a href="http://search.twitter.com/search?q=ossec" target="_blank">Twitter</a> (where Andrew <a href="https://twitter.com/andrewsmhay/status/2121136131" target="_blank">tries</a> to get anyone who mentions OSSEC to buy his book). </p>
<p>I asked Wim Remes, who recently posted <a href="http://blog.remes-it.be/?p=231" target="_blank">OSSEC in a Nutshell</a> on his blog, and he said OSSEC succeeds because &#8220;it&#8217;s cross-platform, it&#8217;s free (the software is &#8230; not the implementation), it&#8217;s giga-flexible, it does what it promises to do&#8221;. &#8216;Giga-flexible&#8217;, I like that word. I&#8217;ll have to trademark it before Wim does! :) These sentiments are shared by many who have given OSSEC a try. </p>
<p>The acclaim for OSSEC extends to the press as well. In &#8216;07 LinuxWorld named OSSEC the <a href="http://www.linuxworld.com/news/2007/031207-top-5-security.html" target="_blank">#1 Open Source Security Tool</a>. They explained, &#8220;The OSSEC HIDS project has been gaining widespread use and is quickly being deployed within organizations around the world as a method of protecting systems at the host level after attacks have made it past network defenses&#8221;. Recently <a href="http://www.zdnetasia.com/techguide/opensource/0,39044899,62052219,00.htm" target="_blank">ZDnet</a> also covered OSSEC saying, &#8220;Danen singles out OSSEC as a solid, cross-platform tool for intrusion detection&#8221;. The OSSEC website has a large list of <a href="http://www.ossec.net/main/awards/" target="_blank">awards and reviews</a>.</p>
<p>Clearly OSSEC is a solid, cross-platform piece of software at an unbeatable price, but it takes more than that to build a loyal following.</p>
<p>I think the <strong>real reason</strong> for OSSEC&#8217;s success is its creator <a href="http://www.linkedin.com/pub/daniel-cid/0/324/465" target="_blank">Daniel Cid</a>, and his roots. </p>
<p>The seeds for OSSEC were planted back when Daniel was a security engineer. He found that in his job he lacked information about the hosts he was protecting and started writing scripts that would give him a better picture of the state of the network. Because Daniel came from an operations background rather than a pure development background, he writes software to solve real problems he actually faced. </p>
<p>Still, it takes more than a problem solver. When I first met Daniel he was working a full time job, OSSEC was a side project. It was clear that he really cared about the project and supporting OSSEC users event if it meant many grueling nights and weekends. Users would send him new log samples to deal with and on his own time Daniel would dissect the logs, create decoders and rank the security relevant events. Daniel answers every email, deals with every bug, and considers every enhancement request. It doesn&#8217;t hurt that he&#8217;s a genuinely nice guy too! </p>
<p>So OSSEC&#8217;s real popularity comes from the fact that it does what users want it to do. That sounds like an incredibly obvious attribute which all software should strive for, but it&#8217;s much more attainable when it&#8217;s developed by someone who has been there and listens to feedback. This is something to keep in mind for all of the commercial software developers out there, <a href="http://www.developingsecurity.com" target="_blank">like myself</a>. </p>
<p><strong>We need to walk a mile in the shoes of the end-user and listen when they have feedback.</strong></p>
<p>Because of the positive experiences using OSSEC it continues to grow in popularity. Largely through word of mouth, OSSEC has grown to over 10,000 downloads a month! </p>
<p>Have you tried OSSEC? Maybe you&#8217;ll find that you&#8217;ll (HEART) OSSEC too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/i-heart-ossec/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Splunk + OSSEC Integration</title>
		<link>http://www.ossec.net/main/splunk-ossec-integration</link>
		<comments>http://www.ossec.net/main/splunk-ossec-integration#comments</comments>
		<pubDate>Tue, 02 Jun 2009 18:15:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/splunk-ossec-integration</guid>
		<description><![CDATA[This is a guest article by Dale Neufeld - canuck.eh at gmail.com
The status of the next version of the OSSEC web interface is one of the more commonly asked questions on the mailing list and is currently #2 on the community requested feature list (http://ossec.uservoice.com).
While web interfaces are nice to have, many of us suffer [...]]]></description>
			<content:encoded><![CDATA[<p><em>This is a guest article by <strong>Dale Neufeld</strong> - canuck.eh at gmail.com</em></p>
<p>The status of the next version of the OSSEC web interface is one of the more commonly asked questions on the mailing list and is currently #2 on the community requested feature list (<a href="http://ossec.uservoice.com">http://ossec.uservoice.com</a>).</p>
<p>While web interfaces are nice to have, many of us suffer from information island overload by having dedicated web interfaces for each application.  This is why I was stoked when the <em>syslog ouput</em> feature was announced last summer (<a href="http://www.ossec.net/dcid/?p=139">http://www.ossec.net/dcid/?p=139</a>) and officially added in <a href="http://www.ossec.net/announcements/1.6-2008-09-02.txt">version 1.6</a>.  Now I can incorporate OSSEC alerts into my SIM/SIEM or log management tool of choice, which not only eliminates the need for a dedicated OSSEC web interface but also allows for simplified incident analysis through aggregation and correlation.</p>
<p>In my environment, we chose <a href="http://www.splunk.com">Splunk</a> based on its quick search and endless customization.  Getting <strong>OSSEC</strong> alerts into Splunk is a breeze.  Just grab the free license version of Splunk, install the Splunk for OSSEC app, and point the OSSEC syslog output to your Splunk server.  BAM! Instant<em> wui 0.4</em>.</p>
<p>The Splunk-for-OSSEC application is a community project that was started by myself and Elazar Broad.  The initial goal of this application was to provide the same set of reports that can be obtained through <em>ossec-reportd</em>.  From there we&#8217;ve also added several other useful features:</p>
<ol>
<li>Top rules last 24 hrs</li>
<li>Top source IP last 24 hrs</li>
<li>Top user last 24 hrs</li>
<li>Bruteforce top source IP last 24 hrs</li>
<li>OSSEC rules for last hour</li>
<li>OSSEC alert levels for last 24 hrs</li>
<li>IP Geolocation lookups</li>
<li>whois lookups</li>
<li>rDNS lookups</li>
<li>web attack and bruteforce tags.</li>
</ol>
<p><strong>Screenshots:</strong></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-4.png' title='Splunk 4'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-4.thumbnail.png' alt='Splunk 4' /></a></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-2.png' title='splunk 2'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-2.thumbnail.png' alt='splunk 2' /></a></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-3.png' title='Splunk 3'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-3.thumbnail.png' alt='Splunk 3' /></a></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-1.png' title='Splunk 1'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-1.thumbnail.png' alt='Splunk 1' /></a></p>
<p><strong>OSSEC and Splunk configuration instructions</strong></p>
<p>More details at the <a href="http://www.ossec.net/wiki/index.php/OSSEC_%26_Splunk">ossec wiki</a>.</p>
<ol>
<li>Inside ossec.conf add a <em>syslog_output</em> block specifying your Splunk system IP address and the port it is listening on:<br />
<blockquote><p>
 &lt;syslog_output&gt;<br />
   &lt;server&gt;172.10.2.3&lt;/server&gt;<br />
   &lt;port&gt;10002&lt;/port&gt;<br />
 &lt;/syslog_output&gt;</p></blockquote>
</li>
<li>Now you need to enable the syslog_output module and restart OSSEC:<br />
<blockquote><p>
 #/var/ossec/bin/ossec-control enable client-syslog<br />
 #/var/ossec/bin/ossec-control restart
</p></blockquote>
</li>
<li>On the Splunk side, add this stanza to inputs.conf:<br />
<blockquote><p> $SPLUNK_HOME/etc/system/local/inputs.conf</p>
<p> [udp://172.10.2.4:10002] #IP address of OSSEC server<br />
 disabled = false<br />
 sourcetype = ossec</p></blockquote>
<p>By setting the sourcetype as OSSEC you&#8217;re ready to take advantage of the Splunk for OSSEC app which can be found here: <a href="http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC">http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC</a>.</p>
</li>
<li>Make sure you update any local or network firewalls that this communication is traversing and then restart Splunk.<br />
<blockquote><p># $SPLUNK_HOME/bin/splunk restart</p></blockquote>
</li>
</ol>
<p><strong>Splunk:</strong><br />
<a href="http://www.splunk.com/download">http://www.splunk.com/download</a></p>
<p><strong>Splunk-for-OSSEC:</strong><br />
<a href="http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC#">http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC#</a></p>
<p>Feedback and feature requests are much appreciated!</p>
<p>If you&#8217;ve used the syslog ouput to send alerts to another SIM/SIEM or log management tool, we would love to hear from you so we can add configuration details to the wiki.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/splunk-ossec-integration/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trend Micro to Acquire Third Brigade</title>
		<link>http://www.ossec.net/main/trend-micro-to-acquire-third-brigade</link>
		<comments>http://www.ossec.net/main/trend-micro-to-acquire-third-brigade#comments</comments>
		<pubDate>Wed, 29 Apr 2009 12:45:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/trend-micro-to-acquire-third-brigade</guid>
		<description><![CDATA[

What was announced?


On April 29, 2009 Trend Micro announced a definitive agreement to acquire the business of Third Brigade, a privately-held security and compliance software company headquartered in Ottawa, Canada that owns the OSSEC project. The acquisition is subject to customary approvals and is expected to close in the 2nd quarter of 2009.  
&#160;


Who [...]]]></description>
			<content:encoded><![CDATA[<ol>
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>What was announced?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm"><font color="#000000">On April 29, 2009 Trend Micro announced a definitive agreement to acquire the business of Third Brigade, a privately-held security and compliance software company headquartered in Ottawa, Canada that owns the OSSEC project. The acquisition is subject to customary approvals and is expected to close in the 2nd quarter of 2009.  </font></p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="2">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>Who is Trend Micro?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm"><font color="#000000">Trend Micro Incorporated is a pioneer in secure content and threat management. Founded in 1988, Trend Micro provides individuals and organizations of all sizes with award-winning security software, hardware and services. With headquarters in Tokyo and operations in more than 30 countries, Trend Micro solutions are sold through corporate and value-added resellers and service providers worldwide. For additional information and evaluation copies of Trend Micro products and services, visit our Web site at </font><font color="#0000ff"><u><a href="http://www.trendmicro.com/">www.trendmicro.com</a></p>
<p></u></font><font color="#000000">.</font></p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm"><font color="#000000"> </font></p>
<ol start="3">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>Will 	OSSEC continue to be an open source project?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">Yes.  Trend Micro is committed to maintaining OSSEC as an open source project.</p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="4">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>What 	impact will this acquisition have on an OSSEC user?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">We don’t anticipate there will be any impact on OSSEC users from this acquisition.  Like Third Brigade, Trend will help create broader awareness and further ensure the success of this thriving open source community through ongoing dedicated resources and extended support necessary for larger enterprise deployments.</p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="5">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>Will 	Trend Micro continue to offer commercial support for OSSEC? </strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">Yes, technical support will continue to be offered via the same two channels:</p>
<ul>
<li>
<p style="margin-bottom: 0cm">Telephone: 8:00 am and 8:00 pm 	(Eastern Time), Monday to Friday.</p>
</li>
<li>
<p style="margin-bottom: 0cm">Email: Third Brigade provides an 	initial response to a customer support request within one business 	day.</p>
</li>
</ul>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="6">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>How does an OSSEC user buy support? </strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">OSSEC users that would like to purchase support should continue to contact Third Brigade sales, at 1.866.684.7332 or <font color="#0000ff"><u><a href="mailto:ossec.purchase@thirdbrigade.com">ossec.purchase@thirdbrigade.com</a></u></font>.</p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="7">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>How are 	OSSEC support requests handled? </strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">Requests for OSSEC support should continue to be directed to Third Brigade Support at 1.866.343.8077, and <font color="#0000ff"><u><a href="mailto:ossec.support@thirdbrigade.com">ossec.support@thirdbrigade.com</a></u></font></p>
<p></p>
<p>Thanks!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/trend-micro-to-acquire-third-brigade/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Rootcheck updated to v2.0</title>
		<link>http://www.ossec.net/main/rootcheck-updated-to-v20</link>
		<comments>http://www.ossec.net/main/rootcheck-updated-to-v20#comments</comments>
		<pubDate>Fri, 06 Mar 2009 14:09:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/rootcheck-updated-to-v20</guid>
		<description><![CDATA[Rootcheck is responsible for the rootkit detection, system auditing and policy monitoring parts of OSSEC. However, if you want to check your systems without installing the whole OSSEC package, you can run Rootcheck separately to give you an quick status on how your system is going.
The rootcheck page is http://www.ossec.net/rootcheck/.
How to use it
   [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ossec.net/en/rootcheck.html">Rootcheck</a> is responsible for the rootkit detection, system auditing and policy monitoring parts of OSSEC. However, if you want to check your systems without installing the whole OSSEC package, you can run Rootcheck separately to give you an quick status on how your system is going.</p>
<p>The rootcheck page is <a href="http://www.ossec.net/en/rootcheck.html">http://www.ossec.net/rootcheck/</a>.</p>
<h3 class="my">How to use it</h3>
<p>    Rootcheck is a very simple software. Just download, unpack, compile and execute it. It will scan the system and print if it found or not anything.</p>
<p>            [root@ossec ~]# <strong>wget http://www.ossec.net/rootcheck/files/rootcheck-2.0.tar.gz</strong><br />
            [root@ossec ~]# <strong>tar -zxvf rootcheck-2.0.tar.gz</strong><br />
            [root@ossec ~]# <strong>cd rootcheck-2.0</strong><br />
            [root@ossec ~]#  <strong>make all</strong><br />
            [root@ossec ~]# <strong>./ossec-rootcheck</strong><br />
            ..</p>
<h3 class="my">Downloads</h3>
<p>    <a href="/rootcheck/files/rootcheck-2.0.tar.gz">v2.0</a>&nbsp;&nbsp; &nbsp; <a href="/rootcheck/files/rootcheck-2.0_checksum.txt">md5sum</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/rootcheck-updated-to-v20/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v2.0 released</title>
		<link>http://www.ossec.net/main/ossec-v20-released</link>
		<comments>http://www.ossec.net/main/ossec-v20-released#comments</comments>
		<pubDate>Fri, 27 Feb 2009 19:02:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v20-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 2.0.
This new version is the first one with support for agentless monitoring and include many others new features and bug fixes:

Centralized configuration - The agent.conf file was introduced to allow granular configuration of the agents directly on the manager side. 
Remote agent restart - [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="/main/downloads/">version 2.0</a>.<br />
This new version is the first one with support for agentless monitoring and include many others new features and bug fixes:</p>
<ul>
<li><strong>Centralized configuration</strong> - The <em>agent.conf</em> file was introduced to allow granular configuration of the agents directly on the manager side. </li>
<li><strong>Remote agent restart</strong> - Functionality was added to restart the agents remotely using the <em>agent_control</em> tool.</li>
<li><strong>Real time integrity checking</strong> - Real time integrity checking was added to Linux systems</li>
<li><strong>New Log Rules Support</strong> - We added support for Windows DHCP logs and fixed/improved many of the other rules for different messages.</li>
</ul>
<p>And much more&#8230; Check the <a href="/announcements/v2.1-2009-06-30.txt">changelog</a> to see all changes and contributors.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p><em>Special thanks to Chris Bailes, Matt Goldsberry, phishphreek, Michael Starks, Danny Fullerton, Slava Semushin and Peter Wolanin for helping with this release.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v20-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>v2.0 - What is coming</title>
		<link>http://www.ossec.net/main/v20-what-is-coming</link>
		<comments>http://www.ossec.net/main/v20-what-is-coming#comments</comments>
		<pubDate>Tue, 20 Jan 2009 17:10:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/v20-what-is-coming</guid>
		<description><![CDATA[What’s new in 2.0 and when will it be released ?

New features that will be introduced in version 2.0 are:

Compiled Rules - Per popular demand, we are introducing the capability in the product to be able to use pre-compiled rules written in “C”. Customers who felt that the XML format for writing rules was very [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What’s new in 2.0 and when will it be released ?<br />
</strong></p>
<p>New features that will be introduced in version 2.0 are:</p>
<ul>
<li><strong>Compiled Rules</strong> - Per popular demand, we are introducing the capability in the product to be able to use pre-compiled rules written in “C”. Customers who felt that the XML format for writing rules was very limiting, can now use the strong programming capabilities of C. </li>
<li><strong>Agentless Monitoring</strong> - Lot of enterprises are faced with the requirement to monitor devices where there are restrictions on Agents to be installed either because of scalability requirements or due to the lack of the native operating system support.  In version 2.0, Ossec customers can perform integrity checking and real time logs inspection on remote systems (such as Linux  based devices, firewall devices such as PIX and routers etc).</li>
<li><strong>New Language Support</strong> - In version 2.0, we will also start supporting Dutch</li>
<li><strong>New Log Rules Support</strong> - In version 2.0, we added support for Yum logs and fixed/improved many current rules for different messages.</li>
<li><strong>New reporting tool</strong> - In version 2.0, we added a new tool to create and help generate reports</li>
</ul>
<p>Here is your opportunity to help shape the next release. We solicit and welcome your feedback. If there are features you will like to see in the version 2.0, Please send us an e-mail at <strong>features-request@ossec.net</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/v20-what-is-coming/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v1.6.1 released</title>
		<link>http://www.ossec.net/main/ossec-v161-released</link>
		<comments>http://www.ossec.net/main/ossec-v161-released#comments</comments>
		<pubDate>Thu, 09 Oct 2008 19:09:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v161-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 1.6.1. This is a small version with bug fixes for some issues found on v1.6.
For a list of features in the version 1.6, please visit: OSSEC v1.6 released.
For a list of issues that were solved, visit the Changelog.
Download it from: http://www.ossec.net/main/downloads .
Thanks!
&#8211;
Daniel B. Cid [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="http://www.ossec.net/main/downloads/">version 1.6.1</a>. This is a small version with bug fixes for some issues found on <a href="http://www.ossec.net/main/ossec-v16-released">v1.6</a>.</p>
<p>For a list of features in the version 1.6, please visit: <a href="http://www.ossec.net/main/ossec-v16-released">OSSEC v1.6 released</a>.</p>
<p>For a list of issues that were solved, visit the <a href="http://www.ossec.net/announcements/v1.6.1-2008-10-10.txt">Changelog</a>.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p>Thanks!</p>
<p>&#8211;<br />
Daniel B. Cid (in name of the <a href="http://www.ossec.net/main/ossecteam/">OSSEC team</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v161-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v1.6 released</title>
		<link>http://www.ossec.net/main/ossec-v16-released</link>
		<comments>http://www.ossec.net/main/ossec-v16-released#comments</comments>
		<pubDate>Mon, 01 Sep 2008 19:08:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v16-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 1.6.
This new version delivers the most comprehensive update to OSSEC in its history, with numerous new features and bug fixes, including:

New multi-server architecture
New platform support for Microsoft Vista (and Server 2008)
New platform support for VMware ESX
Added active response module for Windows
CIS benchmarks on Linux [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="/main/downloads/">version 1.6</a>.<br />
This new version delivers the most comprehensive update to OSSEC in its history, with numerous new features and bug fixes, including:</p>
<ul>
<li>New multi-server architecture</li>
<li>New platform support for Microsoft Vista (and Server 2008)</li>
<li>New platform support for VMware ESX</li>
<li>Added active response module for Windows</li>
<li>CIS benchmarks on Linux (through the policy auditing)</li>
<li>Added the VMWare Security hardening guideline to the policy auditing</li>
<li>Added support for McAfee VirusScan Enterprise logs</li>
<li>Added support for VMware ESX hostd logs</li>
<li>Added support for Mac OS FTP server logs</li>
<li>New tools to better manage the data stored (syscheck_control, rootcheck_control, log_test)</li>
</ul>
<p>And much more&#8230; Check the <a href="/announcements/v1.6-2008-09-02.txt">changelog</a> to see all changes and contributors.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p>Press release from Third Brigade: <a href="http://www.thirdbrigade.com/news_events.aspx?id=803">http://www.thirdbrigade.com/news_events.aspx?id=803</a></p>
<p><em>Special thanks to Michael Starks, Chris Buechler and Joachim Vorrath for the contributions and ChuckD (mdmonk), Daniel Medianero and John Ives for beta testing this release.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v16-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v1.5.1 released</title>
		<link>http://www.ossec.net/main/ossec-v151-released</link>
		<comments>http://www.ossec.net/main/ossec-v151-released#comments</comments>
		<pubDate>Thu, 19 Jun 2008 16:19:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v151-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 1.5.1. This is the first version under Third Brigade and contain fixes for bugs found so far on the version 1.5. For a list of features in the version 1.5, please visit: OSSEC v1.5 released.
For a list of issues that were solved, visit the [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="http://www.ossec.net/main/downloads/">version 1.5.1</a>. This is the first version under <a href="http://www.thirdbrigade.com">Third Brigade</a> and contain fixes for bugs found so far on the version 1.5. For a list of features in the version 1.5, please visit: <a href="http://www.ossec.net/main/ossec-v15-released">OSSEC v1.5 released</a>.</p>
<p>For a list of issues that were solved, visit the <a href="http://www.ossec.net/announcements/v1.5.1-2008-06-19.txt">Changelog</a>.</p>
<p>For information on the Third Brigade Acquisiton, visit: <a href="http://www.ossec.net/main/ossec-project-acquired">OSSEC Project Acquired</a>.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p><em>Thanks to Dennis Golden, Chris Buechler, Andrew Storms and Doug Floer for the bug reports.</em></p>
<p>Thanks!</p>
<p>&#8211;<br />
Daniel B. Cid (in name of the <a href="http://www.ossec.net/main/ossecteam/">OSSEC team</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v151-released/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
