Wish I could edit that last post!
I forgot a few lines.... complete local_decoder.xml below.
add the following to local_decoder.xml
<decoder name="pfsvc-auth">
<program_name>^pfsvc</program_name>
</decoder>
<decoder name="pfsvc-authentication">
<parent>pfsvc-auth</parent>
<regex offset="after_parent">Pfauth \w+ for user '(\S+)'. Call status:
(\S+) - "\w+\s+\w+|\w+\s+\w+\s+\w+\.".</regex>
<order>srcuser, status</order>
</decoder>
On Friday, December 5, 2014 11:51:18 AM UTC-8, Brent Morris wrote:
> Not exactly sure if this is the right place to post this, but it took me
> some time to get working decodes for Microsoft's Azure Multi-Factor
> Authentication (PhoneFactor.net).
>
> It's pretty cool multifactor authentication for on-prem RDP Gateway and
> OWA using your phone as the second factor.
>
> This was my first attempt to create my own decodes for an app that wasn't
> supported by OSSEC. OSSEC is so cool that I wanted to share these with
> others incase there might be one or two of you out there that could
> benefit. We're not using the APP or voice calls, but it shouldn't be to
> hard with the info below to setup the rest of the options for those.
>
> You could have the agent monitor the log files, or setup syslog inside the
> PhoneFactor app. I opted for syslog messages.
>
> And let me know if I'm posting in the wrong place, have an error in my
> decodes, or anything else helpful.
>
> Thanks!
>
> ---
>
>
>
> add the following to local_decoder.xml
>
> <decoder name="pfsvc-authentication">
> <parent>pfsvc-auth</parent>
> <regex offset="after_parent">Pfauth \w+ for user '(\S+)'. Call status:
> (\S+) - "\w+\s+\w+|\w+\s+\w+\s+\w+\.".</regex>
> <order>srcuser, status</order>
> </decoder>
>
> then add the following to local_rules.xml (tailor to your specific needs).
>
> <group name="syslog,pfauth,">
> <rule id="100140" level="0">
> <decoded_as>pfsvc-auth</decoded_as>
> <description>Phone Factor Authentication app group.</description>
> </rule>
> <rule id="100141" level="10">
> <if_sid>100140</if_sid>
> <match>FAILED_SMS_OTP_INCORRECT</match>
> <description>User Failed SMS Challenge/Response</description>
> </rule>
> </group>
>
> --end local_rules.xml
>
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.