I am new to OSSEC and Cyber Security in general and would like to understand it a bit better. OSSEC provides so called "Rules Groups" alerts get assigned to and I would like to understand those groups a bit better.
https://www.ossec.net/docs/docs/manual/rules-decoders/rule-levels.html#rules-group
Some of the 12 groups are pretty straight forward and do not need any explanation what kind of alert gets assigned to the group. However, I do not know what the following groups mean:
attacks
adduser
sshd
ids
firewall
squid
apache
syslog
Maybe someone of you knows that and could help me out or give me something to read! I tried to google but didnt find anything helpful.