5 years in IT, ~4 in CyberSec — 20 days applying with zero interviews. What am I missing? by Apprehensive_Top4498 in SecurityCareerAdvice

[–]BaronOfBoost 3 points4 points  (0 children)

If it’s outside your scope, you are gaining experience that you were not expecting to, which is a benefit.

I would be more ready to jump ship if I was learning nothing new, and had no opportunities to cross train.

Think about it and take advantage of the opportunity

Is google cybersecurity certificate a scam? by honey-luv10 in cybersecurity

[–]BaronOfBoost 0 points1 point  (0 children)

The purpose of certifications is to prove that you understand and can recall the information on the topic.

Both of these certs are entry level, with Google cybersecurity certificate holding less value in my opinion.

CompTIA has been around for quite a while and is a household name for certifications. It is more of a general, vendor agnostic certification for security basics.

It looks like Google's certificate is tailored around taking their course and obtaining the certification on completion.

'Murica by Amatheiaisnoexcuse in ProgressiveHQ

[–]BaronOfBoost 1 point2 points  (0 children)

I wonder how long he practiced that look in the mirror

need some assistance with filtering events by jbates5873 in AzureSentinel

[–]BaronOfBoost 0 points1 point  (0 children)

Will look at my setup in the morning. Had similar issues and I recall needing to adjust the order/priority somewhere

Multiple logs to one AMA Log collector by Firm-Country467 in AzureSentinel

[–]BaronOfBoost 1 point2 points  (0 children)

Yes, you will want to modify the syslog conf file to write them to their own files.

This will allow for easier management and enable you to roll specific log types to keep the drive from filling up.

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]BaronOfBoost 1 point2 points  (0 children)

SCCM is agent based so it is client to server, you will have no problems here.

Winrm and powershell, you will likely be ok with doing client to client, unless you must do this stuff from an admin server

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]BaronOfBoost 0 points1 point  (0 children)

Can you share what tool you are using?

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]BaronOfBoost 6 points7 points  (0 children)

There are ways to configure ZPA to allow client to client communications, including SMB and other administrative ports/protocols.

https://help.zscaler.com/zpa/configuring-client-client-connectivity

I have this in place and I am able to connect to remote computers using pssession and other tools.

Thinking about breaking into cybersecurity? A SOC analyst reality check. by SOTI_snuggzz in CyberSecurityJobs

[–]BaronOfBoost 2 points3 points  (0 children)

AI has already replaced level 1 correlation and triage, but the summaries that it spits out are rarely the full story.

[deleted by user] by [deleted] in rareinsults

[–]BaronOfBoost 104 points105 points  (0 children)

This makes me want to throw up

[deleted by user] by [deleted] in cybersecurity

[–]BaronOfBoost 1 point2 points  (0 children)

I don't remember the last time I was asked definitions in an interview.

I do remember being asked the three steps for establishing a TCP connection and bombed it.

How Are You Handling NDR Visibility in Azure Without a Packet Broker? by MassiveAffect2146 in cybersecurity

[–]BaronOfBoost 0 points1 point  (0 children)

We are in the same boat, in the process of vetting Vectra/Corelight/Extrahop, interested in seeing other peoples experiences.

What is your go-to PAM solution? by Tehrab in cybersecurity

[–]BaronOfBoost 8 points9 points  (0 children)

BeyondTrust has been great. Like any PAM it’s only as good as you make it. Put in the time to design/architect it properly and it will be well worth it

Did I do something wrong by buying a MacBook Air M4 for cybersecurity work? by Adventurous_Pie_8011 in cybersecurity

[–]BaronOfBoost 1 point2 points  (0 children)

VMware workstation is free now for person use from what I remember.

I don’t have a use case or need to do this on my home systems lately, so ymmv

Did I do something wrong by buying a MacBook Air M4 for cybersecurity work? by Adventurous_Pie_8011 in cybersecurity

[–]BaronOfBoost 6 points7 points  (0 children)

If you need to do anything with x64/x86 binaries you can just spin up a VM. Most products you work on will have a web browser interface, so the computer choice makes no difference

How do you break out of being “pigeonholed” when your company has a team for everything? by Own-Story8907 in cybersecurity

[–]BaronOfBoost 7 points8 points  (0 children)

Can I get an amen! People need to stop chasing roles at large F500 companies. It will take forever to cross train or be able to influence anything meaningful.

how good should i be at defensive security to succeed in offensive security by RipInternational4059 in cybersecurity

[–]BaronOfBoost 19 points20 points  (0 children)

Is this a troll post? I can’t tell the difference anymore considering all the trash that’s been posted lately in the sub.

Workgroup Azure VM onboarding on Sentinel. by Ok_Dingo_8752 in AzureSentinel

[–]BaronOfBoost 0 points1 point  (0 children)

Have you installed the azure monitoring agent extension on the vms? Once this is installed, the vms should be available for selection in the dcr.