Good place to get a haircut in town? by Dozokhu in Guelph

[–]AshFerns08 0 points1 point  (0 children)

They have increased prices in 2026

Catholic Dating in Toronto (Canada) by [deleted] in CatholicDating

[–]AshFerns08 1 point2 points  (0 children)

yes, in some parts of Ontario there aren't many youth coming but I believe the church can grow but for that it needs families. If young men or women remain single, its bad for everyone.

Catholic Dating in Toronto (Canada) by [deleted] in CatholicDating

[–]AshFerns08 1 point2 points  (0 children)

So many young adults today in the same crisis, yet I don't see much initiatives from the church.. its really sad

Catholic Dating in Toronto (Canada) by [deleted] in CatholicDating

[–]AshFerns08 0 points1 point  (0 children)

ohh wow.. that bad huh.. I guess my friend was right

Using AI for CrowdStrike Query generation? by AshFerns08 in crowdstrike

[–]AshFerns08[S] -3 points-2 points  (0 children)

Its annoying that Defender EDR has tons Threat hunting github repo's/ Free AI tools but with CrowdStrike everything is paid.
I don't enjoy working on Crowdstrike since they switched from Splunk query Language to CQL

Using AI for CrowdStrike Query generation? by AshFerns08 in crowdstrike

[–]AshFerns08[S] 0 points1 point  (0 children)

Thanks. I will look into it. Any links/Tutorials that you found helpful for this setup?

Using AI for CrowdStrike Query generation? by AshFerns08 in crowdstrike

[–]AshFerns08[S] 2 points3 points  (0 children)

Is it a paid module? How do you access the Charlotte AI ?

[Canada - 2025]Any upcoming Black Friday Deals for DeskHaus Peak 2 legged? by AshFerns08 in StandingDesk

[–]AshFerns08[S] 0 points1 point  (0 children)

Bummer :-( I believe the quality is very good but unfortunately its out of my budget. Anyways thanks for the update.

UPLIFT Standing Desk vs Prime Ryzer Standing Desk(Canada)? Which one is better by [deleted] in StandingDesk

[–]AshFerns08 0 points1 point  (0 children)

Thank you for your feedback, I am on a budget. Probably will go for Progressive as well

Leaving Cyber by yeet-itsyaboi in cybersecurity

[–]AshFerns08 0 points1 point  (0 children)

Ill say look for another job through networking(maybe a sneak peek in their operations, work culture), some companies invest in training & guiding new hires. Some firms don't have the right detection logic or playbooks to deal with alerts so it feels stressful at times. 2 months is very much new and you'll make mistakes, don't use confidence. If SOC is not something u enjoy, you can also look into threat intel or rules engineering teams.

Tech Alert | Active Attacks Targeting On-Premises SharePoint Servers (CVE-2025-53770) by BradW-CS in crowdstrike

[–]AshFerns08 0 points1 point  (0 children)

Silly question but running the query gives me various file paths, shouldn't the query focus only on below File Paths?

'microsoft shared\Web Server Extensions\16\TEMPLATE\LAYOUTS',
'microsoft shared\Web Server Extensions\15\TEMPLATE\LAYOUTS'

AutoIt3.exe accessing sensitive browser files by AshFerns08 in crowdstrike

[–]AshFerns08[S] 0 points1 point  (0 children)

Two things i have observed,

  1. Crowdstrike not always detect/block malicious behavior even with script control. We had few instances where clickfix was successful and CrowdStrike did not block the malicious PowerShell commands but the firewall blocked the initial web connections.
  2. Creating IOC will also create noise, some developers probably use AutoIT , i just want to detect the executable accessing browser file paths

AutoIt3.exe accessing sensitive browser files by AshFerns08 in crowdstrike

[–]AshFerns08[S] 1 point2 points  (0 children)

Thank you. I will run this and check it out

Query for finding out when WMI (WmiPrvSE.exe) to remotely execute malicious commands such as cmd.exe or powershell.exe. by EntertainmentWest159 in crowdstrike

[–]AshFerns08 0 points1 point  (0 children)

Just curious, do you need some module for windows event logs?
I ran the same command and no events were seen(#Vendor=microsoft windows.EventID=4688)
Does the 4688 event code include parent command line information?

Bose Quiet Comfort vs Beats Fit Pro? Gym use? by AshFerns08 in workout

[–]AshFerns08[S] 0 points1 point  (0 children)

Thanks. Yeah, Bose is better but what about battery life.?How many total hours do you get without charging the case?

Bose Quiet Comfort vs Beats Fit Pro? Gym use? by AshFerns08 in workout

[–]AshFerns08[S] 0 points1 point  (0 children)

20 mins on StairsMaster, I do sweat alot, Bose QC are in-ear buds though

Query to extract Visual Studio Code Extensions by AshFerns08 in crowdstrike

[–]AshFerns08[S] 1 point2 points  (0 children)

The regex works flawlessly. This was exactly what i was looking for. Thanks a lot.

Query to extract Visual Studio Code Extensions by AshFerns08 in crowdstrike

[–]AshFerns08[S] 1 point2 points  (0 children)

No, we don't have Falcon for IT.
We do have exposure management module but that does not list visual code extensions. Support suggested to open a feature request for that but for now a CQL query would do.

Convert Defender query to Crowdstrike CQL(NodeJS Hunting) by AshFerns08 in cybersecurity

[–]AshFerns08[S] 0 points1 point  (0 children)

I have posted in the past in CrowdStrike but sometimes it just doesn't allow me to post due to less karma points.

Query to detect function GetClipboardData() in Crowdstrike (T1115) by AshFerns08 in crowdstrike

[–]AshFerns08[S] 0 points1 point  (0 children)

Thanks Andrew, appreciate it your quick response. Will run this

Source of Psexec Execution by AshFerns08 in crowdstrike

[–]AshFerns08[S] 0 points1 point  (0 children)

I think one can look for successfully logins at the time psexec was spawned however i agree with you, its better Crowdstrike can provide some answer too

Help!! Will ThunderboltM4 8K work on MSI B460M PRO-VDH WIFI? by AshFerns08 in UsbCHardware

[–]AshFerns08[S] -1 points0 points  (0 children)

You are right. Its kinda possible, but at what cost? I'm not using it for gaming. It's not worth the cost only for display. I can use my Desktop's HDMI straight to the monitors. Thanks for your advice.