diff --git a/build-docker-images/wazuh-manager/Dockerfile b/build-docker-images/wazuh-manager/Dockerfile
index 1da3d314..d4e433f7 100644
--- a/build-docker-images/wazuh-manager/Dockerfile
+++ b/build-docker-images/wazuh-manager/Dockerfile
@@ -1,27 +1,22 @@
# Wazuh Docker Copyright (C) 2021 Wazuh Inc. (License GPLv2)
-FROM centos:7
+FROM ubuntu:focal
+ARG WAZUH_VERSION=4.3.0
+ARG TEMPLATE_VERSION=4.3
ARG FILEBEAT_CHANNEL=filebeat-oss
ARG FILEBEAT_VERSION=7.10.2
-ARG WAZUH_VERSION=4.3.0-1
-ARG TEMPLATE_VERSION="master"
ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.1.tar.gz"
-# Set repositories.
-RUN rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH
+RUN apt-get update && apt install curl apt-transport-https lsb-release gnupg -y
-COPY config/wazuh.repo /etc/yum.repos.d/wazuh.repo
+RUN apt-key adv --fetch-keys https://packages-dev.wazuh.com/key/GPG-KEY-WAZUH && \
+ echo "deb https://packages.wazuh.com/4.x/apt/ stable main" | tee -a /etc/apt/sources.list.d/wazuh.list && \
+ apt-get update && \
+ apt-get install wazuh-manager=${WAZUH_VERSION}-1
-RUN yum --enablerepo=updates clean metadata && \
- yum upgrade -y && \
- yum -y install openssl which expect openssh-clients && yum install wazuh-manager-${WAZUH_VERSION} -y && \
- sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo && \
- yum clean all && rm -rf /var/cache/yum
-
-RUN curl -L -O https://packages.wazuh.com/4.x/yum/${FILEBEAT_CHANNEL}-${FILEBEAT_VERSION}-x86_64.rpm &&\
- rpm -i ${FILEBEAT_CHANNEL}-${FILEBEAT_VERSION}-x86_64.rpm && rm -f ${FILEBEAT_CHANNEL}-${FILEBEAT_VERSION}-x86_64.rpm
-
-RUN curl -s https://packages.wazuh.com/4.x/filebeat/${WAZUH_FILEBEAT_MODULE} | tar -xvz -C /usr/share/filebeat/module
+RUN curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/${FILEBEAT_CHANNEL}-${FILEBEAT_VERSION}-amd64.deb &&\
+ dpkg -i ${FILEBEAT_CHANNEL}-${FILEBEAT_VERSION}-amd64.deb && rm -f ${FILEBEAT_CHANNEL}-${FILEBEAT_VERSION}-amd64.deb && \
+ curl -s https://packages.wazuh.com/4.x/filebeat/${WAZUH_FILEBEAT_MODULE} | tar -xvz -C /usr/share/filebeat/module
RUN curl -L https://github.com/aelsabbahy/goss/releases/latest/download/goss-linux-amd64 -o /usr/local/bin/goss && chmod +rx /usr/local/bin/goss
@@ -32,6 +27,9 @@ RUN curl --fail --silent -L https://github.com/just-containers/s6-overlay/releas
tar xzf /tmp/s6-overlay-amd64.tar.gz -C /usr ./bin && \
rm /tmp/s6-overlay-amd64.tar.gz
+COPY config/etc/ /etc/
+COPY --chown=root:wazuh config/create_user.py /var/ossec/framework/scripts/create_user.py
+
COPY config/filebeat.yml /etc/filebeat/
RUN chmod go-w /etc/filebeat/filebeat.yml
@@ -39,11 +37,9 @@ RUN chmod go-w /etc/filebeat/filebeat.yml
ADD https://raw.githubusercontent.com/wazuh/wazuh/$TEMPLATE_VERSION/extensions/elasticsearch/7.x/wazuh-template.json /etc/filebeat
RUN chmod go-w /etc/filebeat/wazuh-template.json
-COPY config/etc/ /etc/
-COPY --chown=root:1000 config/create_user.py /var/ossec/framework/scripts/create_user.py
-
# Prepare permanent data
# Sync calls are due to https://github.com/docker/docker/issues/9547
+
COPY config/permanent_data.env config/permanent_data.sh /
RUN chmod 755 /permanent_data.sh && \
sync && /permanent_data.sh && \
@@ -52,4 +48,4 @@ RUN chmod 755 /permanent_data.sh && \
# Services ports
EXPOSE 55000/tcp 1514/tcp 1515/tcp 514/udp 1516/tcp
-ENTRYPOINT [ "/init" ]
+ENTRYPOINT [ "/init" ]
\ No newline at end of file
diff --git a/build-docker-images/wazuh-manager/config/wazuh.repo b/build-docker-images/wazuh-manager/config/wazuh.repo
deleted file mode 100644
index e230d6a9..00000000
--- a/build-docker-images/wazuh-manager/config/wazuh.repo
+++ /dev/null
@@ -1,7 +0,0 @@
-[wazuh_repo]
-gpgcheck=1
-gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH
-enabled=1
-name=Wazuh repository
-baseurl=https://packages.wazuh.com/4.x/yum/
-protect=1
diff --git a/multi-node/config/wazuh_cluster/wazuh_manager.conf b/multi-node/config/wazuh_cluster/wazuh_manager.conf
index fddb7fc6..70bb61fc 100644
--- a/multi-node/config/wazuh_cluster/wazuh_manager.conf
+++ b/multi-node/config/wazuh_cluster/wazuh_manager.conf
@@ -10,6 +10,8 @@
recipient@example.wazuh.com
12
alerts.log
+ 10m
+ 0
@@ -43,8 +45,8 @@
43200
- /var/ossec/etc/rootcheck/rootkit_files.txt
- /var/ossec/etc/rootcheck/rootkit_trojans.txt
+ etc/rootcheck/rootkit_files.txt
+ etc/rootcheck/rootkit_trojans.txt
yes
@@ -79,6 +81,11 @@
yes
yes
yes
+
+
+
+ 10
+
@@ -91,6 +98,7 @@
no
5m
+ 6h
yes
@@ -108,6 +116,7 @@
no
stretch
buster
+ bullseye
1h
@@ -121,6 +130,20 @@
1h
+
+
+ no
+ amazon-linux
+ amazon-linux-2
+ 1h
+
+
+
+
+ no
+ 1h
+
+
yes
@@ -199,70 +222,47 @@
127.0.0.1
^localhost.localdomain$
- 4.3.0.1
- 4.3.0.2
- 208.67.220.220
+ 127.0.0.53
disable-account
- disable-account.sh
- user
+ disable-account
yes
- restart-ossec
- restart-ossec.sh
-
+ restart-wazuh
+ restart-wazuh
firewall-drop
- firewall-drop.sh
- srcip
+ firewall-drop
yes
host-deny
- host-deny.sh
- srcip
+ host-deny
yes
route-null
- route-null.sh
- srcip
+ route-null
yes
win_route-null
- route-null.cmd
- srcip
- yes
-
-
-
- win_route-null-2012
- route-null-2012.cmd
- srcip
+ route-null.exe
yes
netsh
- netsh.cmd
- srcip
- yes
-
-
-
- netsh-win-2016
- netsh-win-2016.cmd
- srcip
+ netsh.exe
yes
@@ -306,21 +306,25 @@
etc/rules
+
+ yes
+ 1
+ 64
+ 15m
+
+
no
1515
no
- yes
- 0
yes
no
- yes
HIGH:!ADH:!EXP:!MD5:!RC4:!3DES:!CAMELLIA:@STRENGTH
no
- /var/ossec/etc/sslmanager.cert
- /var/ossec/etc/sslmanager.key
+ etc/sslmanager.cert
+ etc/sslmanager.key
no
@@ -345,4 +349,25 @@
syslog
/var/ossec/logs/active-responses.log
-
+
+
+ syslog
+ /var/log/auth.log
+
+
+
+ syslog
+ /var/log/syslog
+
+
+
+ syslog
+ /var/log/dpkg.log
+
+
+
+ syslog
+ /var/log/kern.log
+
+
+
\ No newline at end of file
diff --git a/multi-node/config/wazuh_cluster/wazuh_worker.conf b/multi-node/config/wazuh_cluster/wazuh_worker.conf
index 30670045..38d72010 100644
--- a/multi-node/config/wazuh_cluster/wazuh_worker.conf
+++ b/multi-node/config/wazuh_cluster/wazuh_worker.conf
@@ -10,6 +10,8 @@
recipient@example.wazuh.com
12
alerts.log
+ 10m
+ 0
@@ -43,8 +45,8 @@
43200
- /var/ossec/etc/rootcheck/rootkit_files.txt
- /var/ossec/etc/rootcheck/rootkit_trojans.txt
+ etc/rootcheck/rootkit_files.txt
+ etc/rootcheck/rootkit_trojans.txt
yes
@@ -79,6 +81,11 @@
yes
yes
yes
+
+
+
+ 10
+
@@ -91,6 +98,7 @@
no
5m
+ 6h
yes
@@ -108,6 +116,7 @@
no
stretch
buster
+ bullseye
1h
@@ -121,6 +130,20 @@
1h
+
+
+ no
+ amazon-linux
+ amazon-linux-2
+ 1h
+
+
+
+
+ no
+ 1h
+
+
yes
@@ -199,70 +222,47 @@
127.0.0.1
^localhost.localdomain$
- 4.3.0.1
- 4.3.0.2
- 208.67.220.220
+ 127.0.0.53
disable-account
- disable-account.sh
- user
+ disable-account
yes
- restart-ossec
- restart-ossec.sh
-
+ restart-wazuh
+ restart-wazuh
firewall-drop
- firewall-drop.sh
- srcip
+ firewall-drop
yes
host-deny
- host-deny.sh
- srcip
+ host-deny
yes
route-null
- route-null.sh
- srcip
+ route-null
yes
win_route-null
- route-null.cmd
- srcip
- yes
-
-
-
- win_route-null-2012
- route-null-2012.cmd
- srcip
+ route-null.exe
yes
netsh
- netsh.cmd
- srcip
- yes
-
-
-
- netsh-win-2016
- netsh-win-2016.cmd
- srcip
+ netsh.exe
yes
@@ -306,21 +306,25 @@
etc/rules
+
+ yes
+ 1
+ 64
+ 15m
+
+
no
1515
no
- yes
- 0
yes
no
- yes
HIGH:!ADH:!EXP:!MD5:!RC4:!3DES:!CAMELLIA:@STRENGTH
no
- /var/ossec/etc/sslmanager.cert
- /var/ossec/etc/sslmanager.key
+ etc/sslmanager.cert
+ etc/sslmanager.key
no
@@ -345,4 +349,25 @@
syslog
/var/ossec/logs/active-responses.log
-
+
+
+ syslog
+ /var/log/auth.log
+
+
+
+ syslog
+ /var/log/syslog
+
+
+
+ syslog
+ /var/log/dpkg.log
+
+
+
+ syslog
+ /var/log/kern.log
+
+
+
\ No newline at end of file
diff --git a/single-node/config/wazuh_indexer_ssl_certs/certs.yml b/single-node/config/wazuh_indexer_ssl_certs/certs.yml
old mode 100644
new mode 100755