Help Needed: SIEM Detection and Alerting Guided Excercise Task # 3

  1. What is the flag for this exercise?

I need help the Flag is for Remote Desktop but “Hint:***********#” and I am not able to find anything with # in whole excersice

You get the flag by running sudo ./lab.sh from the Desktop of the Wazuh server. Note that you have to complete Part 3 of the lab (editing rules) before you run the script as it checks your work.

image

1 Like

Thank you !! I run this script but only follow that all are correct :slight_smile:
Thank again!

image