Real-Time Malware Blocking with ClamAV On-Access (Part 7)
How I set up ClamAV on-access scanning with clamonacc, clamd, AppArmor, and Wazuh, then narrowed the protection scope so it stays stable on real hosts.
Writing & analysis
Longer-form writing about operational trade-offs, lessons from implementation, and the decisions that make systems easier to trust.
How I set up ClamAV on-access scanning with clamonacc, clamd, AppArmor, and Wazuh, then narrowed the protection scope so it stays stable on real hosts.
How I built an internal ClamAV mirror using Nginx to serve virus definitions, cutting 7.2GB/day of redundant egress traffic.
How I wrote Wazuh suppression rules that silenced 300+ noise alerts per hour after four failed approaches.
How I managed different Wazuh agent ossec.conf profiles using inventory-owned files, host variables, and Ansible deployment roles.
How I managed Wazuh manager ossec.conf using inventory-owned files, local wrapper roles, and a controlled restart flow.
How I integrated Wazuh with Keycloak using SAML, group-based access, and Wazuh RBAC mapping.