Wazuh agents include the appropriate policies for their particular operating system during installation. For the full list of officially supported policy files, see the table Available SCA policies. These policies are included with the Wazuh server installation so that they can be easily enabled.
For a detailed description of the various configuration parameters of SCA, please check the SCA reference.
Enabling and disabling policies
By default, the Wazuh agent scans every policy (.yaml or .yml file) in its ruleset folder:
Linux and Unix-based agents: /var/ossec/ruleset/sca.
Windows agents: C:\ProgramFiles(x86)\ossec-agent\ruleset\sca.
macOS agents: /Library/Ossec/ruleset/sca.
Note
Installations and updates don't preserve the contents of these default ruleset folders. Place your policies under an alternative folder if you want to modify or add new ones.
There are two ways to disable policies on the Wazuh agent. The simplest method is to rename the policy file with an extension other than .yaml or .yml.
Alternatively, disable a policy in the Wazuh agent ossec.conf file by setting the enabled attribute to no.
To disable a policy included with the Wazuh agent, specify its path relative to the Wazuh installation directory:
You can also specify an absolute path to the policy file.
How to share policy files and configuration with the Wazuh agents
As described in the centralized configuration section, the Wazuh server can push files and configurations to connected Wazuh agents.
You can enable this feature to push policy files to the Wazuh agents in defined groups. By default, every Wazuh agent belongs to the default group, which is used here as an example:
Edit the Wazuh agent local_internal_options.conf file to allow the execution of commands in SCA policies sent from the Wazuh server:
By enabling remote command execution, the Wazuh server can execute commands on the monitored endpoint. Remote commands are disabled by default as a security measure, helping reduce the attack surface if the Wazuh server is compromised.
You do not need to enable remote commands if you add the policy files to each agent without using Wazuh to push them. For example, you can manually create the policy file directly on the monitored endpoint, or use scp to copy the policy file to the monitored endpoint.
On the Wazuh server, place a new policy file in the /var/ossec/etc/shared/default folder and change its ownership. Replace <NEW_POLICY_FILE> with your policy name.
Add the following configuration block to the Wazuh server /var/ossec/etc/shared/default/agent.conf file to configure the new policy file in the Wazuh agent:
<agent_config><!-- Shared agent configuration here --><sca><policies><policy>etc/shared/<NEW_POLICY_FILE></policy></policies></sca></agent_config>
All files remotely pushed from the Wazuh server are saved in the /<WAZUH_HOME_DIRECTORY>/etc/shared/ directory on the agent endpoints regardless of the group they belong to. We specify the relative file path of the policy in the configuration because the full file path could differ depending on the operating system of the monitored endpoint.
The new <sca> block in the Wazuh server /var/ossec/etc/shared/default/agent.conf file is merged with the <sca> block on the Wazuh agent side, and the new configuration is added.