So we just deployed the lates OSSEC on CentOS. Happy days ahead. However, today (Day 2) we had a two false positive root-kit detections; both related to SUNRPC process(s) opening a random high port that was detected.
How do we avoid this ? Is there a way to limit how many ports the Rootkit check will test ? Or other voodoo magic ? Thanks Michael Grey Silver Spring Networks
