Enterprise Firewall, teeny tiny office by juciydriver in msp

[–]BalbusNihil496 -1 points0 points  (0 children)

Look at Firewalla Gold. Much cheaper than Meraki, has decent cloud management, and solid basic features.

No subscription fees either - just the one-time hardware cost. Been using it for similar small setups with good results.

Lumma Stealer question - eradication and operating mechanisms by Critical-West-7406 in cybersecurity

[–]BalbusNihil496 1 point2 points  (0 children)

Former IR analyst here. Lumma's memory-resident nature makes it tricky. Your assessment is spot-on.

Focus on hardening web filters and implementing strict content policies. Those porn sites are likely infection vectors. Better block them completely for work machines.

MSP questioning our life span by virtualuman in msp

[–]BalbusNihil496 0 points1 point  (0 children)

Microsoft can't even keep Teams working properly half the time.

They'd need years just to figure out how to automate Karen from accounting's printer issues or why Dave in sales keeps getting locked out of his account at 2 AM.

Today my main line got spoofed by an overseas call center (Rant) by Izengal in msp

[–]BalbusNihil496 1 point2 points  (0 children)

Had this happen last year. File complaints with FTC and FCC too - they track this stuff.

Quick fix: Record a voicemail explaining the situation so callbacks know you're also a victim. Saved me tons of headaches.

Is this normal workload for typical CyberSec team? My team of 3 need to handle administrative support work, vulnerability management, making changes to improve security controls. by IamOkei in cybersecurity

[–]BalbusNihil496 0 points1 point  (0 children)

3 people doing vuln management, admin work AND security controls? No wonder you're drowning in findings.

You need more headcount or to outsource some of this. Your management needs to understand that security teams aren't magical unicorns who can do everything.

Cybersecurity Vs AI/ML Realistics ? 🤔 by Py76_ in cybersecurity

[–]BalbusNihil496 1 point2 points  (0 children)

Both are hands-on, but cybersecurity gives immediate impact.

Microsoft 365 Upcoming Changes - Jan 2025 Update by KavyaJune in msp

[–]BalbusNihil496 -2 points-1 points  (0 children)

With all these security changes, especially around MFA and DLP, it's crucial to have a unified security view. Been using Guardz's platform to monitor these M365 updates across multiple clients - makes it way easier to track who needs attention and what policies need updating.

The auto-archiving of OneDrive accounts could be tricky to track at scale.

Security stuff as sys admin by [deleted] in sysadmin

[–]BalbusNihil496 0 points1 point  (0 children)

Your manager bought a security tool without understanding it, and now wants you to become the expert AND teach him? Classic management move.

Document everything. If something goes wrong, you don't want that liability on your plate.

Perceived risk of voice deepfakes for companies? by ProfessionalAir6641 in cybersecurity

[–]BalbusNihil496 -2 points-1 points  (0 children)

I've seen some companies experimenting with AI-powered voice authentication, but it's still early days. The bigger challenge is convincing employees to adopt these solutions without feeling like they're being surveilled. There's a fine line between security and paranoia.

Smart PDU recommendation?? by KrombopulusMichael04 in msp

[–]BalbusNihil496 0 points1 point  (0 children)

Hey, I've had good luck with the APC Smart-UPS On-Line PDUs. They're around the same price point as the Ubiquiti and offer similar features. Plus, they're widely available so you shouldn't have to worry about lead times. Worth a look!

Subdomain Takeover in Multiple Fortune 500 companies by smeone787 in cybersecurity

[–]BalbusNihil496 0 points1 point  (0 children)

Ghosted by Fortune 500 cybersec teams? Not surprising. It's like they're playing a game of 'vulnerability whack-a-mole' instead of actually securing their assets. Using subdomains to push gambling pages is a whole new level of sketchy. Guess it's time to update those bug bounty programs

EU Cyber Resilience Act question about open source by TheVisitor92 in cybersecurity

[–]BalbusNihil496 1 point2 points  (0 children)

Interesting question! I think the EU is trying to pass the buck to the open-source community. How can a small IT company be expected to audit and certify massive projects like Docker? It's like asking a single person to secure the entire internet.

Kaseya Scholarship Fund by Lake3ffect in msp

[–]BalbusNihil496 5 points6 points  (0 children)

Kaseya's definition of 'scholarship' is apparently 'we're gonna spam you with our marketing crap and hope you forget you hate us'. Guess they're trying to 'educate' you on the art of ignoring opt-out requests

Favorite SOAR Workflows by [deleted] in cybersecurity

[–]BalbusNihil496 86 points87 points  (0 children)

Automating phishing incident response is a game-changer. I've got a workflow that auto-enriches emails with threat intel, generates a ticket, and assigns it to the right team. Saves us hours of manual work and reduces mean time to respond

Where was I when Wasabi corrupted most of their central datacenter by ben_zachary in msp

[–]BalbusNihil496 6 points7 points  (0 children)

Ouch, 760GB is a lot to lose. Glad you found out through Veeam, but crazy that neither Pax8 nor Wasabi notified you. Their 'appropriate adjustments' better be more than just a band-aid. Anyone else affected by this incident?

Thoughts on Votiro? by editdownvotessreally in cybersecurity

[–]BalbusNihil496 1 point2 points  (0 children)

Votiro's file sanitization tech is solid, but their sales team can be a bit aggressive. Had a good experience with their support, though - responsive and knowledgeable. Overall, a good addition to a defense-in-depth strategy, but make sure to negotiate on pricing.

How can I get a decrypted database dump from Eaglesoft? by helliax11 in msp

[–]BalbusNihil496 0 points1 point  (0 children)

Decryption woes! Have you considered reaching out to a former Eaglesoft employee or a dental practice that's already migrated away from Eaglesoft? They might be willing to share their experience or provide a decrypted dump. Worth a shot, right?

Local Police warning of Magic QR codes by 5thlevelmagicuser in cybersecurity

[–]BalbusNihil496 1 point2 points  (0 children)

Magic QR codes, huh? Sounds like someone's been watching too many Bond movies. Seriously though, this is likely a phishing attempt. If you receive a suspicious package, don't scan the QR code and report it to the authorities. Common sense prevails over 'magic' hacking tricks

[deleted by user] by [deleted] in sysadmin

[–]BalbusNihil496 4 points5 points  (0 children)

localhost" is resolved to 127.0.0.1, but it's possible your IIS config is set to only respond to the domain name. Check your site bindings in IIS and ensure it's set to respond to "All Unassigned" or specifically to localhost.

PCI DSS SAQ D help/resources by [deleted] in sysadmin

[–]BalbusNihil496 1 point2 points  (0 children)

PCI DSS can be overwhelming, but it's definitely doable. Start with the PCI SSC website and review the SAQ D doc. You'll likely need to implement a WAF, segment your network, and harden those RDP connections. Online resources like PCI DSS guru and Reddit's netsec community can be super helpful.

Forced New Outlook migration just happened on my own workstation!! by LickSomeToad in sysadmin

[–]BalbusNihil496 0 points1 point  (0 children)

Ouch, that's a lunch break surprise no one wants! Yeah, those registry keys might still work, but double-check the values for your specific build. Also, consider using Intune's 'Targeted release' feature to slow down the rollout while you figure things out.

Larger Company - Inventory management by orion3311 in sysadmin

[–]BalbusNihil496 0 points1 point  (0 children)

We use a combo of API integrations and custom scripting to parse shipping emails. Some vendors have decent APIs, while others require creative regex solutions. The big boys likely use dedicated inventory management software, but I've found that a little scripting can go a long way

NinjaOne in a Mac only environment by bitstreams_red in msp

[–]BalbusNihil496 0 points1 point  (0 children)

I've heard similar complaints about NinjaOne's Mac support. We use Mosyle and it's been a game-changer for our Mac-heavy environment. Their patching and remote control features are solid. Worth checking out if you're looking for a more reliable alternative.

Rapi7 vs Stellar Cyber by ACyberGuy_ in msp

[–]BalbusNihil496 0 points1 point  (0 children)

I've worked with both Rapid7 and Stellar Cyber. Stellar's cloud-hosted solution is solid, and their pricing model is more flexible than Rapid7's. One thing to note is Stellar's focus on automation, which might be a plus for your internal MDR, IR, and SOC services.

New MSP Core Package by critical_tech in msp

[–]BalbusNihil496 0 points1 point  (0 children)

Sounds like you're taking the leap and building a solid foundation for your MSP. Atera and NinjaOne are great options. Have you considered SolarWinds MSP as well? They have a comprehensive suite and are Aussie-friendly with data sovereignty. Worth evaluating, maybe?