Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #263349 > unrolled thread

it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

Started byAlbretch Mueller <lbrtchx@gmail.com>
First post2023-11-11 02:30 +0100
Last post2023-11-11 12:20 +0100
Articles 5 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  it would be nice is Debian live includes the Wazuh unified XDR and  SIEM protection framework ... Albretch Mueller <lbrtchx@gmail.com> - 2023-11-11 02:30 +0100
    Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... <tomas@tuxteam.de> - 2023-11-11 07:30 +0100
    Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... Marco <mm@dorfdsl.de> - 2023-11-11 08:40 +0100
      Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... Albretch Mueller <lbrtchx@gmail.com> - 2023-11-11 10:40 +0100
        Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... Michael Kjörling <2695bd53d63c@ewoof.net> - 2023-11-11 12:20 +0100

#263349 — it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2023-11-11 02:30 +0100
Subjectit would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...
Message-ID<HyKYV-4z9j-1@gated-at.bofh.it>
 the politics behind the "cloud trial" may not be compatible with
Debian, but I don't know if there is a way to work around such issues
or just use the other parts of it:

 https://wazuh.com/

// __ this Cybersecurity Platform is FREE

 https://www.youtube.com/watch?v=i68atPbB8uQ
~
 lbrtchx

[toc] | [next] | [standalone]


#263353 — Re: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

From<tomas@tuxteam.de>
Date2023-11-11 07:30 +0100
SubjectRe: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...
Message-ID<HyPFf-4C29-1@gated-at.bofh.it>
In reply to#263349

[Multipart message — attachments visible in raw view] — view raw

On Sat, Nov 11, 2023 at 01:26:46AM +0000, Albretch Mueller wrote:

[...]

> // __ this Cybersecurity Platform is FREE

In which case you aren't the customer, but the cattle.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#263356 — Re: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

FromMarco <mm@dorfdsl.de>
Date2023-11-11 08:40 +0100
SubjectRe: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...
Message-ID<HyQKZ-4CK4-11@gated-at.bofh.it>
In reply to#263349
Am 11.11.2023 01:26 schrieb Albretch Mueller:

>  the politics behind the "cloud trial" may not be compatible with
> Debian, but I don't know if there is a way to work around such issues
> or just use the other parts of it:

Why can't you install it manually, maybe with a script?

[toc] | [prev] | [next] | [standalone]


#263357 — Re: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

FromAlbretch Mueller <lbrtchx@gmail.com>
Date2023-11-11 10:40 +0100
SubjectRe: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...
Message-ID<HySD7-4DZz-1@gated-at.bofh.it>
In reply to#263356
On 11/11/23, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> In which case you aren't the customer, but the cattle.

 Once we go into exposed mode (go online), we tacitly become all
cattle, don't we? What I am talking about is being more of an
unleashed cattle, a leashed one that is aware.

On 11/11/23, Marco <mm@dorfdsl.de> wrote:
> Am 11.11.2023 01:26 schrieb Albretch Mueller:
>
>>  the politics behind the "cloud trial" may not be compatible with
>> Debian, but I don't know if there is a way to work around such issues
>> or just use the other parts of it:
>
> Why can't you install it manually, maybe with a script?

 Yes, of course, you can always do so. I meant it would be best if
certain security issues are dealt on a hardware level. It may sound as
"paranoid", "crazy" to you, but I always go into exposed mode using a
Debian Live DVD, basically:

 1) boot up
 2) mount local drive (reset my home dir ...)
 3) mount USB pen with extra stuff I need
 4) customize my run by using dpkg to install packages from the USB pen drive
 5) unmount, remove pen drive
 6) physically plug in Internet enabling hardware
 7) install the drivers to be able to connect to the Internet ...
...
 (n-2)) disconnect yourself from the internet (software + hardware by
removing the wifi USB dongle or cable) ...
 (n-1)) run script to check which files were changed during your run and how
 n) shutdown

 Yes, it is cumbersome, but it is the only way I can access the
Internet with some reliability.

 It is not just about soft- and hardware level measures, "hackers" as
part of their modus operandi need "persistence". They would not spend
their while and expertise knowing well that by shutting down your
computer you would be effortlessly erasing all their cr@p, along with
all cookies and all of that and they are smart enough to realize that
they would risk exposing their rear end to the four winds. If they
continue doing such thing you will know the kinds of "legally
protected" hackers that would not mind such risk.

 lbrtchx

[toc] | [prev] | [next] | [standalone]


#263361 — Re: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

FromMichael Kjörling <2695bd53d63c@ewoof.net>
Date2023-11-11 12:20 +0100
SubjectRe: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...
Message-ID<HyUbT-4EYL-7@gated-at.bofh.it>
In reply to#263357
On 11 Nov 2023 09:35 +0000, from lbrtchx@gmail.com (Albretch Mueller):
> On 11/11/23, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
>> In which case you aren't the customer, but the cattle.
> 
>  Once we go into exposed mode (go online), we tacitly become all
> cattle, don't we?

Believe it or not, but there actually are companies which provide
online (marketing speak: "cloud") services which _don't_ treat you as
the product to be sold. Generally those tend to be more expensive than
options which monetize the person using the service (generally by in
various ways selling that person's attention to advertisers).


> On 11/11/23, Marco <mm@dorfdsl.de> wrote:
>> Why can't you install it manually, maybe with a script?
> 
>  Yes, of course, you can always do so. I meant it would be best if
> certain security issues are dealt on a hardware level. It may sound as
> "paranoid", "crazy" to you, but I always go into exposed mode using a
> Debian Live DVD, basically:

If you want your live environment to contain additional things, such
as the "extra stuff [you] need" and "the drivers to be able to connect
to the Internet", nothing prevents you from customizing your live
image to include those.

The live images distributed by the Debian project are intended
primarily to cater to a typical user who wants to try out Debian in a
low-risk manner. They aren't really intended for situations where one
needs every last bit of something, whatever that is.

If you want to customize the live image to better meet your particular
needs, here are a few links to get you started. I found all of these
with a web search for "customize debian live cd".

https://wiki.debian.org/DebianLive
https://live-team.pages.debian.net/live-manual/html/live-manual/customizing-package-installation.en.html#449
https://wiki.debian.org/DebianInstaller/Modify/CD
https://wiki.debian.org/LiveCD

If you need more help with this, I recommend checking out the
debian-live mailing list at https://lists.debian.org/debian-live/

-- 
Michael Kjörling                     🔗 https://michael.kjorling.se
“Remember when, on the Internet, nobody cared that you were a dog?”

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web