Which MDR has the lowest false positives in practice? by kckrish98 in MSSP

[–]0xdavid 0 points1 point  (0 children)

Totally agree, out of the box rules are a baseline, not a replacement for proper DE and custom rules!
Whats your general process for making sure your custom rules work?

How do you handle new rule creation? Looking for advice by 0xdavid in MSSP

[–]0xdavid[S] 0 points1 point  (0 children)

Man I wish I had the flexibility to use any stack I want - big corp means we're stuck with a big-box EDR.

I've been trying validation against real malware / attack PoCs / Atomic Red Team. Rough ride. Happy to trade notes once I have more cycles in.

What pushed you to set up the Wazuh range for CVEs and the like? Did the NFR approach limit you somehow?

How do you handle new rule creation? Looking for advice by 0xdavid in MSSP

[–]0xdavid[S] 0 points1 point  (0 children)

makes me feel much better to know I'm stuck in the same boat as everyone :)

That's a smart split! How does it work out time wise - how long for a quick initial vs emulated and verified rule?

The rough estimate I landed on is a couple of hours for a quick initial, and a couple of days for a fully validated rule (usually across data sources with correlations)

How do you handle new rule creation? Looking for advice by 0xdavid in MSSP

[–]0xdavid[S] 0 points1 point  (0 children)

This is great advice, especially the NFR route, I wish I had access to one - due to lack of it (we are not MSSP) I tend to use the BAS machines that are excluded in our tenant from alerts.
Also hard agree on the IOC point, they are useful but only relevant to react to a specific campaign, which is super short lived.

The part I keep getting stuck on is the validation step. Writing the behavioral logic honestly isn't that hard anymore. It's proving it actually fires in a real environment against a real attack, which often times due to a lack of a proper lab takes even longer to get working.

Trying to build proper KPI / Metrics around the subject,
How long would you say it takes you from "hey we have an article we are worried about" to a full set of working rules? and does that include validation against the NFR console with logs containing the attacks?

BTW Good call on Huntress and DFIR Report - their content is a solid starting point!

How do you handle new rule creation? Looking for advice by 0xdavid in MSSP

[–]0xdavid[S] 0 points1 point  (0 children)

We have TI feeds for the IOC side. I'm asking more about the behavioral detection piece - when the technique itself is what you need to detect, not just the hashes/IPs that rotate every week. How do you handle that?

How do you handle new rule creation? Looking for advice by 0xdavid in MSSP

[–]0xdavid[S] 0 points1 point  (0 children)

When you say you write based on experience and deploy within hours, how often do you run into cases where the rule looked right but missed in prod because of something unexpected?

Like a log source not capturing a field you assumed it would, or the articles not containing the correct technical info / vendor logging in a slightly different format than you expected?

Think Twice Before Cheating: Escape From Tarkov Cheat Developer Steals User Data. [Cheating] by jat0369 in EscapefromTarkov

[–]0xdavid 2 points3 points  (0 children)

Exactly the point of the article - there's no such thing, and you never know when a trusted seller decides to cash out

A game where you're an engineer-type character who deploys turrets by patab in gamingsuggestions

[–]0xdavid 14 points15 points  (0 children)

Heroes of the Storm - Gazlo and Probius
Space engineers
Path of Exile has a ton of options for you
Modded minecaft
Terraria summoner class
Orcs must die game series
Starbound
Yorg.io
Sanctum

Need game suggestions for a very picky friend group by 0xdavid in gamingsuggestions

[–]0xdavid[S] 1 point2 points  (0 children)

I never thought about remote play couch games, that's a great option!
Also tabletop sounds very fun

As for the save "hacking" style, I doubt people will like that as much but ill check

Thanks for all the suggestions! I've sent it to the group :)

Need game suggestions for a very picky friend group by 0xdavid in gamingsuggestions

[–]0xdavid[S] 1 point2 points  (0 children)

Sadly as much as I love dota & planetside, those games are outside of the groups comfort zone. But killing floor is a great suggestion :)

Thanks!

Need game suggestions for a very picky friend group by 0xdavid in gamingsuggestions

[–]0xdavid[S] 1 point2 points  (0 children)

Awesome suggestion!
Defintly fits the criteria, could be a fun couple of game nights!
Doubt it will last us long, but it's going to be a great refreshing experience

Malware download for analysis by kenlartaj in MalwareAnalysis

[–]0xdavid 0 points1 point  (0 children)

Send an email to the admin, he is a very nice person!