Greetings: Looking at the files in the active-response/bin directory I noticed they are owned by root, and group owned by ossec.
Is your file group owned by ossec? I also noticed that every one had "#!/bin/sh" at the start, and /bin/ sh was present in the file system as a valid shell. Our active-response works, so I know overall yours should work too, but it may require some tweaking. Thank you.
