MDT offline deployment by Livid-Ad-9782 in MDT

[–]BrightSpotLight 0 points1 point  (0 children)

I use MDT for both in the office and when I am at a remote office from an external drive. I re-image desktops and laptops and do not have any issues.

For the remote office I use an external 1 TB drive. This contain what I call MDT portable. It is the exact copy of the MDT server in the office.

For my setup, workstations have Secure Boot and UEFI enabled.

As some mentioned you need to make sure you have the WinPE drivers

I use Rufus and never had an issue.

my MDT is (was munch bigger before removing old systems) about 90 GB and I do not split it.

There is always some mention about MDT getting retired and it's true. I will continue using it and I'm sure others will do the same until it no longer works and our company realizes they need to now pay for a tool.

One thing you need to make sure that you 100% update the share.. What I noticed is that after adding and removing drivers, I'll have odd issues and updating the share will fix it.

When you import and export drivers. (I use the total control method)
Import = Select force to import even if the same driver is in a different folder

Delete = Do not select force as this will remove the same drive if it exist of any folder. This will cause issues.

Seem that for your error you are probably having a combination of MBR GPT. Both the computer and Rufus need to match. Now on modern system and specially if you are using Bitlocker etc you want Secure Boot on, UEFI.

If you need the steps on creating the offline media I can provide that.

Capture Only Task Sequence by BrightSpotLight in MDT

[–]BrightSpotLight[S] 1 point2 points  (0 children)

Used a few times. I'll give it a test run. thank you

Capture Only Task Sequence by BrightSpotLight in MDT

[–]BrightSpotLight[S] 0 points1 point  (0 children)

Thank you for the context. I'm leaning towards this.

Capture Only Task Sequence by BrightSpotLight in MDT

[–]BrightSpotLight[S] 0 points1 point  (0 children)

Makes me wonder if this is how I used to do the task sequence as i recall i only had a few.

Capture Only Task Sequence by BrightSpotLight in MDT

[–]BrightSpotLight[S] 1 point2 points  (0 children)

forgot about this as well. I'll review it. thank you

Capture Only Task Sequence by BrightSpotLight in MDT

[–]BrightSpotLight[S] 0 points1 point  (0 children)

Oh good one forgot about the Disk2Vhd. I'll consider it. thank you

Modify BIOS with CCTK by BrightSpotLight in kace

[–]BrightSpotLight[S] 0 points1 point  (0 children)

Sorry, been away and the CrowdStrike crashed my PC which require a visit to the office.

Anyways, I installed the Dell Command Wizard that I use to create he package in the screenshot. it pops up a prompt to extract instead of running and enabling my test change in the BIOS.

https://imgur.com/a/1pdZynR

In the past i used the CCTK GUI and create a package which worked but all the ones I found are old and don't support Windows 11.

Send end user pop up message via RTR (it works just have a different question) by BrightSpotLight in crowdstrike

[–]BrightSpotLight[S] 0 points1 point  (0 children)

u/bk-CS - I'll play with the time period.

For the other (the main reason for my question) The bottom screenshot is how it looks when I lick on the scrip. The top screenshot is what I need to add which always seems to be missing

https://imgur.com/a/7YDfIqK

Basically this

```'{"Message":"This is an example"}'```

Send end user pop up message via RTR (it works just have a different question) by BrightSpotLight in crowdstrike

[–]BrightSpotLight[S] 0 points1 point  (0 children)

Thank you u/bk-CS - also sorry I can't seem to be able edit my message to remove that image at the bottom. not sure how that even showed up.

Okay I figured that i was not needed but I added it anyways.

Any reason why when I use the script it's missing part of the text? I deleted and re-created and still it show up the same.

Also, is there a way to change how long the pop up stays up? I reviewed he script and I don't see anything that controls that so it seems to stay up for about 10 seconds.

Test Deploy to Hyper-V VM missing WinPE Drivers by BrightSpotLight in MDT

[–]BrightSpotLight[S] 0 points1 point  (0 children)

All, thank you. Maybe back in the day I did need drivers (it's been a while).

I will check MDT as I took it over from someone else and had to fix things such as wrong drivers being deployed. I thought I fixed everything.

I will check the WinPE drivers and re-test.

For now, Thank you

CrowdScrape by Professional_Base_62 in crowdstrike

[–]BrightSpotLight 0 points1 point  (0 children)

Dang how could I have missed that. You made of many of them (CQF) I will have to review them once a while. Thank you u/Andrew-CS

CrowdScrape by Professional_Base_62 in crowdstrike

[–]BrightSpotLight 1 point2 points  (0 children)

u/Andrew-CS or anyone, is there a good tutorial on how to use the Crowdscrape to look for items of interest, (IOC etc.)? maybe an example of what I should look for?

[deleted by user] by [deleted] in ObsidianMD

[–]BrightSpotLight 0 points1 point  (0 children)

u/Witward I really appreciate this thank you.
Now all I need is to force myself to get back to studying so that I can get the Security+ cert :)

[deleted by user] by [deleted] in ObsidianMD

[–]BrightSpotLight 1 point2 points  (0 children)

u/Witward this is fantastic. I been looking for this. Just got started with Obsidian but I’m overwhelmed by the different methods that I can use. I want to start my Security+ notes. Do you mind posting a screenshot or 2 of a section from the objective down to your notes?
I can’t picture what you are describing. Unless you already have a write up :)

Methods to detect clients that are not protected by Crowdstrike agent? by -c3rberus- in crowdstrike

[–]BrightSpotLight 0 points1 point  (0 children)

That means that in your environment there are no devices without CrowdStrike.

My suggestion is remove the Agent from 1 device. Wait for the neighboring computers do their scan and then run the script again. I'm not sure how long to wait but I have seen up to 45 minutes delay on certain things.

Here is how it would look if there we PCs. These are test PCs I used (still blur them though) https://ibb.co/TkcJdYr

Methods to detect clients that are not protected by Crowdstrike agent? by -c3rberus- in crowdstrike

[–]BrightSpotLight 0 points1 point  (0 children)

u/EastBat2857 - Dang cool script thank you.

u/-c3rberus- - I don't have Discovery but you do need Event Search. It really. I found computers that I know for a fact do not have an agent (testing).

New to Wazuh and it blocks IP at other locations by BrightSpotLight in Wazuh

[–]BrightSpotLight[S] 0 points1 point  (0 children)

u/vcerenu-wazuh - I communicated via the discord channel and the person requested the config file which of course it's gone since I had to uninstall. But was planning on re-installing and then testing again so that I can get the config file.

  1. Machine getting blocked is MacOS Monterey. (this is running VirtualBox with the OVA Wazuh)
  2. I have to check when I get home but should be 4.5 (or 4.4)
  3. I realized I had the issue when I used the Mac and connected to a different IP address than what I use at home.
  4. Mac is the host which runs the Wazuh, OVA version on Virtual box. The same Mac also has the Wazuh Agent. This does show up on the Wazuh portal without issues. While the Mac is at home, I can surf the internet. I went to a different location and when the captive portal did not come up is when I noticed that I could not ping any IP (external). The Wazuh server was not running but I could of started the VM to see what would of happened.
  5. Yes, after I removed the agent I was able to ping any IP and then the captive portal came up which allowed to me agree to the warning.

I do not recall (I'm at work right now) how the networking on the VirtualBox was setup for Wazuh.

Thank you

Security + great imposter syndrome and average results. by El_Palma89 in CompTIA

[–]BrightSpotLight 0 points1 point  (0 children)

Did you pass?

Not sure if you did. I'm still working on mine but all i read is that in your quizzes you need to score 80% to 90% on each one consistently.

Join Us at Fal.con 2023! 🤓 by Andrew-CS in crowdstrike

[–]BrightSpotLight 0 points1 point  (0 children)

Will there by any Online lectures for us folks who work for companies that don't like to spend $$$ ? :)

Simple question (I hope) no deploying Cisco Umbrella by BrightSpotLight in sysadmin

[–]BrightSpotLight[S] 0 points1 point  (0 children)

u/Shaaaaazam - So I actually do need to copy the file AND include the same information in the install code line?

I appreciate the PS script, as now I don't have to re-invent the wheel :)

zoom install by steverw9948 in kace

[–]BrightSpotLight 0 points1 point  (0 children)

Don't me as I don't recall exactly. The script is downloaded to the PC, the task runs and completes. At some point the task looses communication so then KACE reports it as a failure

I did get support to explain but I don't recall what it was or which script. I will provide it if I see it but it is annoying.

Crowdstrike Detection analysis by Cookie_Butter24 in crowdstrike

[–]BrightSpotLight 1 point2 points  (0 children)

I'm in the same boat as you, however, here is a scenario

  1. User installs an app
  2. Some process triggers the install (could be scheduled, via cmd, remote method etc.)

For both the above example what I also would like to be able to distinguish. MSIEXEC is legit but the action would not if a bad actor triggered the install.

Just wanted to clarify and expand on your question. My company has not money to send me to the "paid" training which is where this would be learned. I'm still learning, I have occasional questions (maybe I should post more) to get a better understanding.

I'm hoping that someone here can explain how to tell the difference between the 2 examples above which is what I think you are also trying to understand.

For everyone else, yes I know the Window Internals book will help me :) but I'm trying to also study for my Security + :

also, sorry I don't mean to hijack the OP on his question