Data Loss Prevention Lab

Data Loss Prevention Lab Question 4

There seems to be a problem with this lab question as nothing shows up when searching for *PAN*

Nothing is given in the current data range which the lab does not even mention.

It can take a minute or so for PowerShell to find the PAN data on Windows. In the lab guide we state the following:

image

I just ran the lab and indeed, at first there are no results. Then after 60 seconds I do see a hit on PAN data.

If I wait longer the search script runs periodically and I get multiple hits:

No change on my end. I waited well over 60 secs.

Also checked and verified code placing

And restarted both the Windows Wazuh and Ubuntu wazuh services.

Windows conf file.

Windows stop and restart a bunch of times

Ok. I noticed that the Wazuh ossec.conf file needed to be complete with all of the code indexes. I originally just started on the last part as i restarted the lab and immediately started on Part 3. I’d be cool if some of these parts can be done separately.

1 Like