=== Trivy / scanner de imágenes en cluster ===

=== Wazuh DB de firmas (líneas detalle) ===
-rw------- 1 wazuh wazuh  28411 May 24 06:21 cis_apache2224_rcl.txt
-rw------- 1 wazuh wazuh  12576 May 24 06:21 cis_debian_linux_rcl.txt
-rw------- 1 wazuh wazuh   7609 May 24 06:21 cis_mysql5-6_community_rcl.txt
-rw------- 1 wazuh wazuh  10297 May 24 06:21 cis_mysql5-6_enterprise_rcl.txt
-rw------- 1 wazuh wazuh  35781 May 24 06:21 cis_rhel5_linux_rcl.txt
-rw------- 1 wazuh wazuh  33870 May 24 06:21 cis_rhel6_linux_rcl.txt
-rw------- 1 wazuh wazuh  36957 May 24 06:21 cis_rhel7_linux_rcl.txt
-rw------- 1 wazuh wazuh  17658 May 24 06:21 cis_rhel_linux_rcl.txt
-rw------- 1 wazuh wazuh  34376 May 24 06:21 cis_sles11_linux_rcl.txt
-rw------- 1 wazuh wazuh  35081 May 24 06:21 cis_sles12_linux_rcl.txt
-rw------- 1 wazuh wazuh  94877 May 24 06:21 cis_win2012r2_domainL1_rcl.txt
-rw------- 1 wazuh wazuh  28006 May 24 06:21 cis_win2012r2_domainL2_rcl.txt
-rw------- 1 wazuh wazuh 100530 May 24 06:21 cis_win2012r2_memberL1_rcl.txt
-rw------- 1 wazuh wazuh 376002 May 24 06:21 cis_win2012r2_memberL2_rcl.txt
-rw------- 1 wazuh wazuh  16174 May 24 06:21 rootkit_files.txt
-rw------- 1 wazuh wazuh   5548 May 24 06:21 rootkit_trojans.txt
-rw------- 1 wazuh wazuh   7314 May 24 06:21 win_malware_rcl.txt

=== Muestra de firmas anti-rootkit Wazuh (primeras 20 líneas de rootkit_files.txt) ===
# Copyright (C) 2015, Wazuh Inc.
#
# This program is a free software; you can redistribute it
# and/or modify it under the terms of the GNU General Public
# License (version 2) as published by the FSF - Free Software
# Foundation
#
# rootkit_files.txt, (C) Daniel B. Cid
# Imported from the rootcheck project.
#
# Blank lines and lines starting with '#' are ignored.
#
# Each line must be in the following format:
# file_name ! Name ::Link to it
#
# Files that start with an '*' will be searched in the whole system.

# Bash door
tmp/mcliZokhb           ! Bash door ::/rootkits/bashdoor.php
tmp/mclzaKmfa           ! Bash door ::/rootkits/bashdoor.php

=== Muestra trojan signatures (primeras 15) ===
# Copyright (C) 2015, Wazuh Inc.
#
# This program is a free software; you can redistribute it
# and/or modify it under the terms of the GNU General Public
# License (version 2) as published by the FSF - Free Software
# Foundation
#
# rootkit_trojans.txt, (C) Daniel B. Cid
#
# Imported from the rootcheck project.
# Some entries taken from the chkrootkit project.
#
# Blank lines and lines starting with '#' are ignored.
#
# Each line must be in the following format:
=== Detalle de firmas Wazuh ===
--- rootkit_files.txt: entradas activas ---
272

--- rootkit_trojans.txt: entradas activas ---
77

--- Muestra 10 rootkit signatures ---
tmp/mcliZokhb           ! Bash door ::/rootkits/bashdoor.php
tmp/mclzaKmfa           ! Bash door ::/rootkits/bashdoor.php
dev/.shit/red.tgz       ! Adore Worm ::/rootkits/adorew.php
usr/lib/libt            ! Adore Worm ::/rootkits/adorew.php
usr/bin/adore           ! Adore Worm ::/rootkits/adorew.php
*/klogd.o               ! Adore Worm ::/rootkits/adorew.php
*/red.tar               ! Adore Worm ::/rootkits/adorew.php
usr/bin/soucemask       ! TRK rootkit ::/rootkits/trk.php
usr/bin/sourcemask      ! TRK rootkit ::/rootkits/trk.php
tmp/.../a               ! 55808.A Worm ::

--- Muestra 10 trojan signatures ---
ls          !bash|^/bin/sh|dev/[^clu]|\.tmp/lsfile|duarawkz|/prof|/security|file\.h!
env         !bash|^/bin/sh|file\.h|proc\.h|/dev/|^/bin/.*sh!
echo        !bash|^/bin/sh|file\.h|proc\.h|/dev/[^cl]|^/bin/.*sh!
chown       !bash|^/bin/sh|file\.h|proc\.h|/dev/[^cl]|^/bin/.*sh!
chmod       !bash|^/bin/sh|file\.h|proc\.h|/dev/[^cl]|^/bin/.*sh!
chgrp       !bash|^/bin/sh|file\.h|proc\.h|/dev/[^cl]|^/bin/.*sh!
cat         !bash|^/bin/sh|file\.h|proc\.h|/dev/[^cl]|^/bin/.*sh!
bash        !proc\.h|/dev/[0-9]|/dev/[hijkz]!
sh          !proc\.h|/dev/[0-9]|/dev/[hijkz]!
uname       !bash|^/bin/sh|file\.h|proc\.h|^/bin/.*sh!
