http://ossec-docs.readthedocs.org/en/latest/manual/index.html
http://ossec-docs.readthedocs.org/en/latest/syntax/head_ossec_config.active-response.html
1.How would you configure activeresponse to send the block to all agents?
2.When would you block a user vs blockan IP (host-deny.sh vs firewall-drop.sh)? When would you want touse both in conjunction?
3.Looking in the rules directory for sshd, how would you add athreshold so that the server does not block on 1 failed loginattempt? What do you believe would be the proper amount of
Expert Answer
An answer will be send to you shortly. . . . .