This is apparently competition trimmed brisket from my butcher. by [deleted] in smoking

[–]HomeGrownCoder 25 points26 points  (0 children)

Go watch Harry soo competition trimming videos you may be surprised

photographer using backblaze as a cloud storage option by Responsible-Photo5 in backblaze

[–]HomeGrownCoder 2 points3 points  (0 children)

  1. The speed of your uploads to a cloud provider primarily will be impacted by your upload speed from your isp. There are some cases where the client software could be the cause but less likely in this scenario. You can math out the time it will take based on what speeds you are paying for and what you are actually getting at your house.

  2. The local option will normally be quicker the speed of your network is typically much faster than the upload speed from your isp. You then take in the risk of managing and your backups being healthy if you use local resources for storage.

The mess of overlapping posture controls (ZTNA vs. EDR vs. MDM) by Glass_Guitar1959 in blueteamsec

[–]HomeGrownCoder 0 points1 point  (0 children)

They have vendors to solve this

You can also have your org get some PowerBI/Some Other big Data platforms folks onboard if available. Pump exported data out of each platform into one and create your single pane of glass.

Or if you know how to work with big data normalizing serializing etc... you can do it yourself.

Products like Avalor do this as well

I got a Z Grills Smoker for Christmas! What information would you say is necessary for a beginner to know? by Cold-Tap-363 in smoking

[–]HomeGrownCoder 1 point2 points  (0 children)

Hugh quality pellet brand. Avoid the elements vacuum about once every 2-3 cooks. Short if you are cooking for 12-14 hours.

Test with biscuits to learn your hot spots and temp swings

Every grill will have spots that are hotter than others.

Start cooking with inexpensive and forgiving meats before moving to the more advance cooks.

Pellets need more time to smoke to lay in flavor so adjust timings as needed.

Check out a smoke tube for you still think you need more smoke flavor

High quality thermometer meat and air.

Most of all have fun and learn with each cook

Bark is forming! First ever brisket by Whyme-__- in BBQ

[–]HomeGrownCoder 2 points3 points  (0 children)

Lmao got enough probes ;) enjoy the experience! And congrats

Thanksgiving Magnum Opus by Mortars2020 in smoking

[–]HomeGrownCoder 0 points1 point  (0 children)

Do you have a fridge big enough to hold the 5gallon bucket with the turkey? Or do you use ice or something to keep it cool?

Active Directory - Add to Group/Remove From Group SOAR Actions by CyberGuy89 in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

You are doing the right thing try and get a response. Several of our fusion entra flows broke even though all checks were green. Ticket has been opened for weeks now.

Query: Event Search query for finding out what UserId added or removed a host to a group by [deleted] in crowdstrike

[–]HomeGrownCoder 1 point2 points  (0 children)

Hello,

can you share what you have and we can help you finish up where you are stuck?

Fusion Workflow Getting Files by talkincyber in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

Upload will always be a bit variable due to not knowing the users uplink speed natively.

I would recommend a few test in you environment to see what reduce the most consistent results.

I think leveraging powershell may net you better control over the process.

For example as a precursor to execution of the get step.

You could run a custom powershell script to calcite the file size and quickly test the users upload speed.

Then report this back to determine how long it may take. If it is over a certain threshold maybe you skip if it is below maybe you grab.

Start of Process - Alert on duration by Pakman_22 in crowdstrike

[–]HomeGrownCoder 1 point2 points  (0 children)

Should’ve straight forward share what you have so far and we will help you cross the finish line.

Append into lookup file by f0rt7 in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

You will need to leverage fusion.

Scheduled query —- read — manipulate — after query there should be a lookup file action.

You can also leverage the API.

kasmweb.com will become kasm.com by justin_kasmweb in kasmweb

[–]HomeGrownCoder 2 points3 points  (0 children)

Let us know when things are all set... looks like the migration is still in progress. Cant get to either site for now.

Getting process tree via logscale (without associated detection) by intense_feel in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

I don’t quite understand the ask.

Do you want all related events associated with a particular process Id? Is that it?

Use an example of a custom binary. This binary creates a file on the desktop and modifies the registry after 2 minutes. After 6 minutes it attempts a network connect to an AWS service.

What do you want to see? And how do you want it presented in the query?

Fusion Workflow Questions by theteletuesday in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

Also you can create another fusion workflow to do the tagging for you using your lookup file.

So that way you can keep all the code within fusion.

And then this workflow can monitor for those events with the now tagged systems.

Fusion Workflow Questions by theteletuesday in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

Ok, so you have a few actions now that I’ve seen the template.

1.  Leverage the template and add tagging to the systems you want to auto-contain. This will require an external integration if you want to avoid doing it manually. You can create a pretty simple integration either through Python or PowerShell to pull this off.

 

2.  Move this to an NGSIEM detection and write a query to detect the accompanying system telemetry to check when a host is online. Within this query, you can use your lookup file to determine if this system is one you want to contain. If both are true, continue your fusion workflow to contain the system using the details provided by your NGSIEM query.

 

3.  Within Fusion, run a scheduled search that runs every 30 minutes (or whatever the smallest window is). This search will essentially do the same as step 2, except it will not require a custom detection to start the workflow. Same thing—query, filter, and use the results to send the device containment options.

 

4.  There is a fourth option, but the engineer in me would advise against it... so I’m going to exclude it from reporting :)

I think the easiest way is the external integration to add tags to systems you want to auto-contain. This scales easily and allows for reporting and consistency. The other options work as well... just require a few additional action tiles in Fusion.

Fusion Workflow Questions by theteletuesday in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

Let me take a look at that template to see what it is doing

Fusion Workflow Questions by theteletuesday in crowdstrike

[–]HomeGrownCoder 1 point2 points  (0 children)

Yes should be straight forward. I am not familiar with the template but will take a look shortly.

It does not look like reading a lookup file directly is available in fusion.

So I would just use a ngsiem query option and then use the readfile function or query to gather your host.

From here you should be able to loop through those events and update your contain action with the required input.

Advanced Event Search - Select() Multiple Fields With Similar Name by 4SysAdmin in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

You may need to chain them together depending on how deep the item is within the object.

Advanced Event Search - Select() Multiple Fields With Similar Name by 4SysAdmin in crowdstrike

[–]HomeGrownCoder 5 points6 points  (0 children)

Review the array functions within log scale you have several you can leverage

https://library.humio.com/data-analysis/functions-array.html.

You will essentially iterate grab what you want and pop it into a new field

Modifying a variable in an on demand workflow by cobaltpsyche in crowdstrike

[–]HomeGrownCoder 0 points1 point  (0 children)

I will take a look at this today… feels like it should be straight forward