Duo authentication and admin activity logs flowing into a self-hosted Wazuh SIEM, ready for MFA monitoring and CMMC audit evidence.
As our business continues to grow our focus is on providing white labeled Tier 3 IT support services, RMM as a service, and co-managed IT services. This blog will be highlighting tips for using a Bash script to forward Cisco Duo MFA logs into a self-hosted Wazuh SIEM.
We recently connected Duo to the onsite Wazuh server of a client working toward CMMC Level 2. Logging every MFA event and every admin change is part of the evidence an assessor wants to see (NIST 800-171 controls 3.3.1 and 3.5.3). Duo ships an official tool for exactly this. Getting it to produce real Wazuh alerts took some work, so we turned everything we learned into one script that you can run by hand or from SuperOps RMM.
Research
Duo publishes DuoLogSync (github.com/duosecurity/duo_log_sync), a small Python service that pulls logs from the Duo Admin API and sends them as JSON over TCP. The plan was simple: run DuoLogSync on the Wazuh manager, send its output to a syslog listener that only accepts local connections, and let Wazuh’s built-in JSON decoder do the rest. No agent, no public port, no custom decoder.
In practice, five things got in the way. They aren’t obvious from the documentation:
Stock Wazuh rule 86600 (Suricata) matches any JSON event that has both “timestamp” and “event_type” fields. Duo auth logs have both, so every event was captured by a level 0 rule and silently thrown away. Our rules now hang under 86600 as child rules.
Wazuh loads every rule file, stock and custom together, in alphabetical order. Naming the file 9999_duo_rules.xml makes sure it loads after the stock rules it depends on.
“action” is a reserved Wazuh field name, so a field match on it stops the whole ruleset from loading. Use the <action> tag or a dotted field like action.name instead.
DuoLogSync 2.4 retired the “adminaction” endpoint. Admin events now come from the “activity” log, which has a completely different JSON layout.
DuoLogSync opens one TCP connection and never reconnects. Every Wazuh manager restart quietly lost the next batch of logs. The fix is a systemd unit tied to the manager with PartOf=wazuh-manager.service.
The payoff showed up right away. The 180-day history pull surfaced twelve failed Active Directory syncs, all caused by a Duo Authentication Proxy outage. If an AD sync fails, a user you just disabled in AD can still pass Duo, so that’s a finding worth knowing about.
Variables
DuoIntegrationKey = The integration key of a Duo Admin API application with only “Grant read log” permission – i.e. DIXXXXXXXXXXXXXXXXXX DuoSecretKey = The secret key for that application (mark this as a secure variable in SuperOps) DuoApiHost = The API hostname from the same application – i.e. api-xxxxxxxx.duosecurity.com DuoEndpoints = Optional. Which Duo logs to pull – default auth,telephony,activity DuoOffsetDays = Optional. How many days of history to pull on the first run, maximum 180 DuoAction = Optional. install, status, resend or uninstall
Script Snippet
The full script handles prerequisite checks, backups, validation, automatic rollback, and a final check with wazuh-logtest. These are the core pieces:
# DuoLogSync config - single quotes are required by DLS
cat > /opt/duologsync/config.yml <<EOF
version: '1.0.0'
dls_settings:
log_format: 'JSON'
api:
offset: $DLS_OFFSET_DAYS
checkpointing:
enabled: True
directory: '/opt/duologsync/checkpoints'
servers:
- id: 'wazuh'
hostname: '127.0.0.1'
port: 5140
protocol: 'TCP'
account:
ikey: '$DUO_IKEY'
skey: '$DUO_SKEY'
hostname: '$DUO_API_HOST'
endpoint_server_mappings:
- endpoints: ['auth', 'telephony', 'activity']
server: 'wazuh'
EOF
# Local-only listener added to ossec.conf
<remote>
<connection>syslog</connection>
<port>5140</port>
<protocol>tcp</protocol>
<local_ip>127.0.0.1</local_ip>
<allowed-ips>127.0.0.1</allowed-ips>
</remote>
# Duo auth events are claimed by Suricata rule 86600 - attach under it
<rule id="120000" level="0">
<if_sid>86600</if_sid>
<field name="txid">\.+</field>
<field name="factor">\.+</field>
<description>Duo: authentication event</description>
</rule>
# systemd: restart with the manager, wait for the listener first
[Unit]
After=wazuh-manager.service
PartOf=wazuh-manager.service
[Service]
ExecStartPre=/bin/bash -c 'until ss -ltn | grep -q "127.0.0.1:5140 "; do sleep 2; done'
ExecStart=/opt/duologsync/venv/bin/duologsync /opt/duologsync/config.yml
Restart=always
The complete script, the SuperOps edition, and the full ruleset (with alerts for MFA fraud reports, MFA fatigue, admin panel brute force, Duo configuration changes and AD sync failures, all tagged for NIST 800-171) are free on our GitHub: https://github.com/FarmhouseNetworking/Duo-Wazuh-LogSync
If your company is a MSP or wants to become one and automation just seems out of reach, then contact us to run your RMM for you.
A Comprehensive Cost Guide for Government Contractors
CMMC certification costs by level: Budget $75K-$150K for most small DoD contractors pursuing Level 2 compliance.
CMMC Certification is a new cybersecurity standard for the Defense Industrial Base (DIB) and defense supply chain, crucial for DoD contractors to protect sensitive information and prevent security breaches. The framework’s introduction and integration into the acquisition and contracting process underscore its importance for cybersecurity maturity assessment and the safeguarding of Controlled Unclassified Information (CUI).
Changes implemented with CMMC 2.0, including the use of Plans of Actions and Milestones (POA&Ms) and limited waivers, aim to streamline the certification process while ensuring rigorous cybersecurity standards align with NIST guidelines. These adaptations demonstrate an evolving approach towards enhancing the cybersecurity infrastructure of government contractors and maintaining public trust.
Factors Influencing CMMC Compliance Costs
Understanding the multifaceted nature of CMMC certification costs is crucial for DoD contractors aiming to achieve compliance. The cost factors are primarily influenced by:
Current Security Maturity: Organizations with a higher level of NIST 800-171 compliance face lower costs in adopting CMMC. This underscores the importance of existing cybersecurity practices within the organization.
Organization Size and Complexity: Larger organizations and those with multiple locations generally incur higher compliance and maintenance costs due to the scale of operations and the complexity of securing a wider network.
Scope and Access of Controlled Unclassified Information (CUI): The extent of CUI access significantly impacts compliance costs. Organizations with broader access to CUI are required to implement more stringent security measures, thereby increasing the cost.
Additionally, the approach to system changes plays a critical role:
Full Approach vs. Enclave Approach: Opting for a full overhaul of operations to meet CMMC standards can be more costly compared to creating a secure enclave for CUI. The choice between these approaches affects the overall cost and strategy for achieving compliance.
These factors, combined with the costs associated with audits, expert consultation, and documentation, form the backbone of the financial planning required for CMMC certification. Understanding these elements is essential for DoD contractors to navigate the path to compliance efficiently and cost-effectively.
Estimated Costs by CMMC Level
Breaking down the estimated costs by CMMC level can provide a clearer picture for DoD contractors on what financial commitments might be expected. Here’s a concise breakdown:
CMMC Level 1: Basic Cybersecurity
Small Entity: Self-assessment and affirmation cost roughly $6,000.
Larger Entity: Self-assessment and affirmation cost about $4,000.
CMMC Level 2: Intermediate Cybersecurity
Small Entity: Self-assessment and related affirmations over $37,000; Certification by C3PAO nearly $105,000 [5].
Larger Entity: Self-assessment and related affirmations nearly $49,000; Certification by C3PAO approximately $118,000.
CMMC Level 3: Good Cybersecurity Practices
Small Organization: Recurring engineering costs $490,000; Nonrecurring costs $2.7 million; Certification assessment over $10,000.
Larger Organization: Recurring engineering costs $4.1 million; Nonrecurring costs $21.1 million; Certification assessment more than $41,000.
This tiered structure illustrates the significant investment in cybersecurity infrastructure required at each level, highlighting the importance of accurate budgeting and financial planning for compliance.
Strategies for Minimizing Compliance Costs
To minimize CMMC certification costs effectively, consider the following strategies:
Streamline Your Compliance Efforts:
Leverage the streamlined requirements of CMMC 2.0, including self-assessments for certain levels, which are expected to lower assessment costs compared to CMMC 1.0.
Familiarize yourself with the revised CMMC 2.0 framework to understand how it aims to reduce costs and increase trust in the assessment ecosystem.
Conduct a comprehensive self-assessment using NIST’s guide for NIST SP 800-171, focusing on foundational security measures and managing consulting fees.
Optimize Your CMMC Project Scope:
Determine the exact scope of your CMMC project. Consider storing CUI in a separate, secure enclave and using expert consultants to save money.
If only a portion of your organization handles CUI, create a separate enclave for a simpler assessment process, thereby reducing your compliance boundary.
Choose technologies and platforms that are easy to deploy and use, which support the NIST SP 800-171 security controls, and offers a compliance documentation package.
Invest Wisely in Technology and Expertise:
Utilize automated platforms to centralize various types of GRC programs, reducing siloed tasks and leveraging technology to cut costs.
Consider outsourcing for SIEM, vulnerability scanning, and hardware/software monitoring to manage costs effectively:
Engage consultants who are familiar with your technology, helping to ensure a smooth and cost-effective compliance process.
Contact us today to explore how to best align your cybersecurity efforts with the demands of CMMC Certification, ensuring protection and compliance in an ever-evolving cybersecurity landscape.
On June 1st, the Department of Justice (DoJ) release further guidance about compliance programs which could effect the way PCI and HIPAA compliance breaches are handled in court.
They state that compliance programs aren’t merely one-and-done snapshots in time, but are instead dynamic programs that get updated regularly to fit changing circumstances.
An article about it states, “the latest guidance issued by DOJ is premised almost entirely on the adequacy of the organization’s risk assessment efforts, an approach well-known and particularly applicable to cybersecurity professionals. Prosecutors are urged to evaluate the quality and effectiveness of an organization’s risk assessment program by examining:
The risk management process, particularly the methodology used to identify, analyze and address the risks an organization faces
Risk-tailored resource allocation, namely whether the organization devotes enough resources to managing risks
Updates and revisions, specifically whether the risk assessment is subject to periodic dynamic reviews
Lessons learned, determining whether the company has a process for tracking and coordinating changes in its risk management program based on its experience
The DOJ also stressed the importance of risk-based training and communications about misconduct as essential parts of how it determines whether the organization’s compliance programs are up to snuff. Finally, the guidance highlights the importance of management support of the organization’s compliance initiatives and the value of extending compliance due diligence to third-party providers.”
If your company is unsure about their compliance program or risk assessment process, then contact us for assistance.
And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say, “They share freely and give generously to the poor. Their good deeds will be remembered forever.” For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.