Earlier this year there was an interchange about getting Trend Micro
OfficeScan notices into OSSEC. There is a rule file for this
(trend-osce_rules.xml) but it seems not to be triggered, perhaps owing
to the fact that OfficeScan no longer puts these into an ASCII file
anymore, but does put them into a database. OfficeScan can also be
configured to put its notifications into the Windows Event logs. Here is
one example, from the server's application log:

Event Type:     Warning
Event Source:   Trend Micro OfficeScan Server
Event Category: System
Event ID:       10
Date:           1/25/2011
Time:           16:49:33
User:           NT AUTHORITY\SYSTEM
Computer:       VIRUSSCAN1
Description:
Virus/Malware: Eicar_test_file
Computer: IT114909
Domain: Boco
File: C:\DOCUME~1\scastle\LOCALS~1\Temp\JU5oa5aH.zip.part (eicar.com)
Date/Time: 1/25/2011 16:49:31
Result: Virus successfully detected, cannot perform the Clean action
(Delete)

These should be decoded by the Windows Event log decoder, but they don't
seem to be picked up by the rules in trend-osce_rules.xml. What needs to
change so that this can happen? I'm willing to do the work; I just need
to be pointed in the right direction.

-- 
Shane Castle
Data Security Mgr, Boulder County IT
CISSP GSEC GCIH


Reply via email to