Skip to content

Add Vestrix physical-security integration - #111

Open
dev-rehaann wants to merge 1 commit into
wazuh:mainfrom
dev-rehaann:add-vestrix-integration
Open

Add Vestrix physical-security integration#111
dev-rehaann wants to merge 1 commit into
wazuh:mainfrom
dev-rehaann:add-vestrix-integration

Conversation

@dev-rehaann

Copy link
Copy Markdown

Summary

Adds integrations/vestrix_integration/ for JSON physical-security events emitted by Vestrix, a WiFi CSI physical-intrusion detection system.

The decoder selects records with "source":"vestrix" and preserves the vestrix decoder name while using Wazuh's built-in JSON_Decoder. The rules cover high-confidence physical intrusion, sensor tampering, an externally finalized missing PACS/badge event, and correlation with supported OpenSSH authentication anomalies.

Contents

  • ruleset/decoders/0585-vestrix_decoders.xml
  • ruleset/rules/1000-vestrix_rules.xml
  • ruleset/testing/test.ini
  • installation, testing, provenance, maintenance, and component-status documentation

Active response, SCA, and threat-intelligence content are not applicable and are documented as such. A dashboard is not included.

Testing

  • Parsed both XML files successfully before submission.
  • The decoder and rules were previously loaded and exercised with wazuh-logtest on wazuh/wazuh-manager:4.14.5.
  • The included test.ini covers a positive detection, a negative non-match, and the JSON decoder-name regression.

Only Wazuh 4.14.5 has been tested. Rules 100210 and 100211 depend on built-in OpenSSH rule IDs 5712 and 5763. The submitted 100200-100211 IDs are in Wazuh's documented custom range and can be adjusted if maintainers require a different allocation.

@leonfullxr
leonfullxr requested a lite review from Copilot August 31, 2026 06:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants