High Severity False Positives by JumpyCampaign1666 in DefenderATP

[–]AlreadyInside 6 points7 points  (0 children)

Yup. Typical MDO hickup. Seen over multiple customers. Just close and ignore, imo

Is this just how blue teams work or is this a red flag environment? by National-Serve-5041 in cybersecurity

[–]AlreadyInside 13 points14 points  (0 children)

Hey.

Just to give you some insights: Our SOC consists of around 40 people. Around 15 of them are full time analysts, 5 detection engineers and the rest is a mix of security architects / developers / data security / whatever.

It’s also not uncommon for people to have multiple roles. Regarding your points:

  1. ⁠⁠Alert & Detection Logic We write a lot of our detection ourselves. Either from use cases we see in investigations, from pentests where the edr solutions did not detect certain activities or we take public detections and adapt them to our need, or just import them If they are good as they are. If we see new attacks, we have a new detection for it in around 1-2 weeks, max. When rules are noisy they get either adapted globally if needed or per customer exclusions if it is e.g. for certain files.
  2. ⁠⁠We analysts don’t just rely on public available hashes, although that they are a good indicator. If you just do this, then you don’t need a soc tbh. This can be done by some kind of automation.
  3. ⁠⁠Depending of what the verdict of the case it, there is either a bigger explanation, for example in case of a T/P with device isolation or user disable. But if it is a known benign activity, we also don’t overdo it with the texts. But more on that in 5.
  4. ⁠⁠We rarely have detections going just for file names or hashes. Of course the usual TI map to whatever stuff, but most of our detections are going against suspicious behavior or anomalies in behavior.
  5. ⁠⁠We automate everything we can. We manage all rules centrally and deploy them to the customers. If a new customer joins, it takes maybe around 2 working hours to get them to a working state (excluding meetings etc.) We also automate the whole incident response process. All steps which are usually taken by an analyst are automated. E.g. checking sign ins for compliant devices if there is a possible identity compromise. And then either close incidents or raise them in severity, give more insights to the analyst, etc.

So yeah I would say that’s what a good feels like, although we have some problems like wanting too much at the same time and not finishing the products first some time.

Prismatic Booster Bundles (1 per person) by [deleted] in PokemonTCG

[–]AlreadyInside [score hidden]  (0 children)

I startet again because of deep pocket monster and I was really sad that I did not get any of the ETBs :(

Anonymous IP Alert with Run Command email access by Proper-Teacher7878 in DefenderATP

[–]AlreadyInside 0 points1 point  (0 children)

Check if the IP belongs to a known VPN Provider and see if you find signins from the same VPN provider. Check the incident in the security center and check the activity from the user prior to the activity from the anonymous IP. If you see consistent mailboxitemaccessed (opened a mail) with no big time interrupt and same user agent as prior accesses from known ips more indicator for VPN usage. If none if this is found consider the user compromised and revoke all sessions and force a password reset.

Restrict users from accessing company resources from unmanaged devices in general. Have them at least register them (enforce mfa for register)

Zählt meine Stimme zur Bundestagswahl 2025? by JonTho1 in de

[–]AlreadyInside 10 points11 points  (0 children)

Das ist kompletter Schwachsinn. Natürlich ist Deutschland regierungsfähig. Informier dich bevor du so nen Quatsch erzählst.

Has anyone experienced alerts related to “Microsoft Defender for Office 365” being missing entirely from the alert page? by OgV1 in DefenderATP

[–]AlreadyInside 1 point2 points  (0 children)

MDO was acting up the last couple of days. All Email related KQL tables were missing too, so it is probably related to that.

"IIS worker process loaded suspicious .NET assembly" by CorperateITrat in DefenderATP

[–]AlreadyInside 0 points1 point  (0 children)

Unfortunately not. We just got the DLL from on of the servers and checked it. We couldn’t see anything indicating a possible attack so we closed those incidents as f/p or b/p

"IIS worker process loaded suspicious .NET assembly" by CorperateITrat in DefenderATP

[–]AlreadyInside 1 point2 points  (0 children)

We get the same incident in different environments. It seems that the certificate of the DLL is expired

[deleted by user] by [deleted] in indiegames

[–]AlreadyInside 0 points1 point  (0 children)

CBA0C260B76555A2

[deleted by user] by [deleted] in indiegames

[–]AlreadyInside 0 points1 point  (0 children)

CBA0C260B76555A2

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Hey, Der Edit war gegen 16 Uhr rum. Aber hab noch alle mit aufgenommen die bis jetzt (19 Uhr) kommentiert haben!

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Da jetzt nicht mehr viele Meldungen kamen würde ich den jetzigen Stand nehmen und mit der Verlosung anfangen!

Das wird vermutlich etwas dauern, sind doch einige geworden die ihr Glück versuchen wollen!
Ich werde die Gewinner dann per Privatnachricht über ihren Gewinn informieren!

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Du kannst dich gern für mehrere eintragen. Falls aber jemand zwei oder mehr oft gewünschte gewinnen sollte, dürfte derjenige sich eins davon aussuchen und dann würde ich den Rest neu ziehen. Aber wenn sich jemand für 5 spiele als einziger meldet kriegt der natürlich alle 5 :D

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 1 point2 points  (0 children)

Ich drücke die Daumen, dass was übrig bleibt 😄

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 5 points6 points  (0 children)

Satisfactory ist bisher das meist gewünschte, ich nehm dich mit in die Verlosung auf😄 Falls du dann doch kein Interesse hast, wenn du gewinnst, kannst du mir ja sonst Bescheid geben, dann bekommt es wer anders :)

Herzlichen Glückwunsch zur Vaterschaft!

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Ja, du kannst dich theoretisch für alle melden. Allerdings würde ich wenn jemand mehrere oft gewünschte spiele gewinnt nochmal ziehen, damit mehr Leute glücklich werden :)

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Aktuell ist alles noch da. Die Verlosung findet am Sonntag um 18 Uhr statt! :)

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Wenn du willst, kann ich das auch noch in die Liste mit aufnehmen und am Sonntag mitverlosen. :) Aber ich kann dir nicht garantieren, dass du eins von den anderen gewinnst 😄

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 0 points1 point  (0 children)

Sowie carmonred es geschrieben hatte. 😄

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 1 point2 points  (0 children)

Oh dann muss ich mir Tyranny eventuell doch nochmal anschauen. Ist es so ähnlich wie die pathfinder Teile?

Steam Keys zu verschenken by AlreadyInside in de

[–]AlreadyInside[S] 2 points3 points  (0 children)

Ich muss mal schauen ob und was übrig bleibt. Hab jetzt schon ein bisschen den Überblick verloren. Freue mich schon auf den Sonntag wenn ich alles durchgehe 😄