MalwareBytes Endpoint Protection
Copy link

MalwareBytes is software installed on your assets that detects malware and viruses. You can connect MalwareBytes to send its data to SIEM (InsightIDR) in order to more quickly detect suspicious files on your Windows assets.

To do so:

Configure MalwareBytes Logging
Copy link

You must be an Administrator to configure syslog logging for this application.

You can configure MalwareBytes to send its log to syslog following the instructions on page 33 of this guide: https://de.malwarebytes.com/pdf/guides/MBQSG.pdf

To configure syslog logging as an admin:

  1. Log in to the MalwareBytes interface.
  2. On the left menu, select the Settings page.
  3. Select the Syslog Logging page.
  4. Select which Windows Endpoint should send its log to a syslog server.
  5. Provide information for the IP address/host, port, protocol, message severity, and communication interval (where the default is five minutes).
  6. Click the Save button.
syslog.png

Configure SIEM (InsightIDR) to collect data from the event source
Copy link

After you complete the prerequisite steps and configure the event source to send data, you must add the event source in SIEM (InsightIDR).

To configure the new event source in SIEM (InsightIDR):

  1. From the left menu, go to Data Collection and click Setup Event Source > Add Event Source.
  2. Do one of the following:
    • Search for Malwarebytes Endpoint Security in the event sources search bar.
    • In the Product Type filter, select Virus Scan.
  3. Select the Malwarebytes Endpoint Security event source tile.
  4. Choose your collector and event source. If you want, you can also name your event source.
  5. Choose the timezone that matches the location of your event source logs.
  6. Optionally choose to send unparsed logs.
  7. Configure your default domain or add a new domain.
  8. Select syslog and specify a port and a protocol.
    • Optionally choose to Encrypt the event source if choosing TCP by downloading the Rapid7 Certificate.
  9. Click the Save button.