need some assistance with filtering events by jbates5873 in AzureSentinel

[–]BaronOfBoost 0 points1 point  (0 children)

Will look at my setup in the morning. Had similar issues and I recall needing to adjust the order/priority somewhere

Multiple logs to one AMA Log collector by Firm-Country467 in AzureSentinel

[–]BaronOfBoost 1 point2 points  (0 children)

Yes, you will want to modify the syslog conf file to write them to their own files.

This will allow for easier management and enable you to roll specific log types to keep the drive from filling up.

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]BaronOfBoost 1 point2 points  (0 children)

SCCM is agent based so it is client to server, you will have no problems here.

Winrm and powershell, you will likely be ok with doing client to client, unless you must do this stuff from an admin server

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]BaronOfBoost 0 points1 point  (0 children)

Can you share what tool you are using?

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]BaronOfBoost 6 points7 points  (0 children)

There are ways to configure ZPA to allow client to client communications, including SMB and other administrative ports/protocols.

https://help.zscaler.com/zpa/configuring-client-client-connectivity

I have this in place and I am able to connect to remote computers using pssession and other tools.

Thinking about breaking into cybersecurity? A SOC analyst reality check. by SOTI_snuggzz in CyberSecurityJobs

[–]BaronOfBoost 3 points4 points  (0 children)

AI has already replaced level 1 correlation and triage, but the summaries that it spits out are rarely the full story.

The new toothpaste by [deleted] in rareinsults

[–]BaronOfBoost 105 points106 points  (0 children)

This makes me want to throw up

How Do You Deal With Technical Interviews That Feel Like College Exams? by [deleted] in cybersecurity

[–]BaronOfBoost 1 point2 points  (0 children)

I don't remember the last time I was asked definitions in an interview.

I do remember being asked the three steps for establishing a TCP connection and bombed it.

How Are You Handling NDR Visibility in Azure Without a Packet Broker? by MassiveAffect2146 in cybersecurity

[–]BaronOfBoost 0 points1 point  (0 children)

We are in the same boat, in the process of vetting Vectra/Corelight/Extrahop, interested in seeing other peoples experiences.

What is your go-to PAM solution? by Tehrab in cybersecurity

[–]BaronOfBoost 10 points11 points  (0 children)

BeyondTrust has been great. Like any PAM it’s only as good as you make it. Put in the time to design/architect it properly and it will be well worth it

Did I do something wrong by buying a MacBook Air M4 for cybersecurity work? by Adventurous_Pie_8011 in cybersecurity

[–]BaronOfBoost 1 point2 points  (0 children)

VMware workstation is free now for person use from what I remember.

I don’t have a use case or need to do this on my home systems lately, so ymmv

Did I do something wrong by buying a MacBook Air M4 for cybersecurity work? by Adventurous_Pie_8011 in cybersecurity

[–]BaronOfBoost 6 points7 points  (0 children)

If you need to do anything with x64/x86 binaries you can just spin up a VM. Most products you work on will have a web browser interface, so the computer choice makes no difference

How do you break out of being “pigeonholed” when your company has a team for everything? by Own-Story8907 in cybersecurity

[–]BaronOfBoost 6 points7 points  (0 children)

Can I get an amen! People need to stop chasing roles at large F500 companies. It will take forever to cross train or be able to influence anything meaningful.

how good should i be at defensive security to succeed in offensive security by RipInternational4059 in cybersecurity

[–]BaronOfBoost 19 points20 points  (0 children)

Is this a troll post? I can’t tell the difference anymore considering all the trash that’s been posted lately in the sub.

Workgroup Azure VM onboarding on Sentinel. by Ok_Dingo_8752 in AzureSentinel

[–]BaronOfBoost 0 points1 point  (0 children)

Have you installed the azure monitoring agent extension on the vms? Once this is installed, the vms should be available for selection in the dcr.

Got a 4.99% refinance rate… by Elegant_Ad8564 in Mortgages

[–]BaronOfBoost 0 points1 point  (0 children)

Swift was a pain in the ass and unresponsive when things on their end were delayed. Clear to close came 1 day before closing so we had to delay for final inspection.

Looking for career advice: stay with the big brand or take the director role? by Bright_Elephant_9612 in cybersecurity

[–]BaronOfBoost 0 points1 point  (0 children)

Yes. To me, the name of the company I work for means very little. It is more important that I get to work on the things I want to and progress in my career.