4.4.0 - OSSEC

4.4.0

OSSEC changelog (4.4.0) support@atomicorp.com

Release Maintainers

Scott R. Shinn (https://www.atomicorp.com)

Contributors on this release

  • @atomicturtle
  • @ddpbsd
  • @bearxy123
  • @AdUser

Release Notes

OSSEC 4.4.0 adds three main capabilities; other enhancements and fixes are listed below.

  • Windows FIM attributes and ACLs — Opt-in check_attrs for Hidden/System/attribute change alerts and check_acl for NTFS DACL/ACE matrix alerts (#1352, #2285).
  • GeoIP via libmaxminddb — Replaces EOL GeoIP Legacy with GeoLite2 MMDB lookups, plus ASN/country enrichment and GeoIP IDS rules (#1828, #2259).
  • JSON syslog alerts — ossec-csyslogd forwards analysisd JSON alerts so agent_name is a first-class field. jsonout stays on when the XML tag is omitted; alerts rotation remains with monitord (#1907, #2302).

General

  • @atomicturtle – Add opt-in Windows FIM check_attrs for Hidden/System/attribute change alerts (#1352)
  • @atomicturtle – Add opt-in Windows FIM check_acl for NTFS DACL/ACE matrix alerts
  • @ddpbsd / @atomicturtle – PR 1828 – Replace EOL GeoIP Legacy with libmaxminddb (GeoLite2 MMDB) for analysisd GeoIP
  • @atomicturtle – GeoIP IDS rules (multi-country auth, impossible-travel) plus ASN/country enrichment; SSH invalid-user dstuser extraction; feed if_matched_group when sid_prev_matched is also set
  • @atomicturtle – PR 2302 – Forward analysisd JSON alerts over syslog so agent_name is a first-class field; keep jsonout on when undeclared

Bug Fixes

  • @AdUser / @atomicturtle – PR 2106 – Stop Dovecot lip= from capturing a trailing comma as dstip
  • @bearxy123 / @atomicturtle – PR 2107 – Check cdb mmap failure with MAP_FAILED instead of DJB x+1 idiom
  • @atomicturtle – PR 2303 – Stop remoted from writing the sender counter into agent 0 rids on key reload (#2065)
  • @atomicturtle – PR 2304 – Stop remoted from mapping a v4 local_ip onto a dual-stack IPv6 socket (#1611)
  • @atomicturtle – PR 2308 – Use a four-part win32ui manifest version so the Windows agent UI can start (#2307)

View on GitHub