Wazuh and Sysinternals Integration, Part II — Scanning and Analysing Executable Files by their hash + VirusTotal

Introduction

Sysinternals — Sigcheck

SOCFortress Integration

Sigcheck + VirusTotal Summary
File Signature status and direct link to VirusTotal File Scan Results
Sigcheck Scan Events

--

--

SOCFortress is a SaaS company that unifies Observability, Security Monitoring, Threat Intelligence and Security Orchestration, Automation, and Response (SOAR).

Love podcasts or audiobooks? Learn on the go with our new app.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
SOCFortress

SOCFortress is a SaaS company that unifies Observability, Security Monitoring, Threat Intelligence and Security Orchestration, Automation, and Response (SOAR).