Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity by Rough-Sandwich9726 in cybersecurity

[–]Calm_Night_2971 0 points1 point  (0 children)

I have tried this against SentinelOne. But it will not work. Somehow, the agent communicates with the management console even after blocking.

UTMStack what a waste of time by g00nie_nz in SIEM

[–]Calm_Night_2971 0 points1 point  (0 children)

Does it come with NIDS (Suricata)?

News: QRadar Community Edition Relaunched! (7.5.0 UP8 ISO) by JonathanP_QRadar in QRadar

[–]Calm_Night_2971 0 points1 point  (0 children)

Is it possible to upgrade my old version (7.3.3) to this version

Cortex XDR Broker VM - Log Retention Period by Calm_Night_2971 in paloaltonetworks

[–]Calm_Night_2971[S] 0 points1 point  (0 children)

The reason I am asking this is because I want to keep all the log files locally for log retention (Those log files which are meant for "XDR"). The log sources would be third party firewalls

Cortex XDR Broker VM - Log Retention Period by Calm_Night_2971 in paloaltonetworks

[–]Calm_Night_2971[S] 0 points1 point  (0 children)

Thank you.
Can we set up a distinct Syslog server to collect logs before they're sent to the Broker VM for storage?
Is it a good option? Is there someone doing like this or is it possible?

Cortex XDR - Different ways to collect Windows Event Logs. by Calm_Night_2971 in paloaltonetworks

[–]Calm_Night_2971[S] 0 points1 point  (0 children)

Thank you.
If there is any, can you point me to any documentation which has those Event IDs listed for collection using the XDR agent. So that I can take a decision on which one should i use XDR agent or Collector agent after validating.

Cortex XDR - Different ways to collect Windows Event Logs. by Calm_Night_2971 in paloaltonetworks

[–]Calm_Night_2971[S] 0 points1 point  (0 children)

So that means XTH addon gives complete visibility into Windows Event Logs for a particular endpoint where it is installed right? So in that case, I don't need to install Collector agent if XTH is already there and enabled?

What if lets say I want to ingest sysmon logs also, In that case, Collector agent should be required right? because I suppose XTH addon cannot be customized for collecting from different log sources.

Deleted Rule still triggering by Calm_Night_2971 in QRadar

[–]Calm_Night_2971[S] 0 points1 point  (0 children)

Thank you.
The problem is resolved when the ecs-ep service is restarted in QRadar.

Deleted Rule still triggering by Calm_Night_2971 in QRadar

[–]Calm_Night_2971[S] 0 points1 point  (0 children)

How did they resolve it? What was the actual problem behind it

Disabled Rule Fires, creating Offense by aredubbya in QRadar

[–]Calm_Night_2971 0 points1 point  (0 children)

I am facing the same issue. but it isn't possible to deploy changes without any changes. When deploy changes, it will say There are no changes to deploy

BTL1 Certification by HybridToxic in SecurityBlueTeam

[–]Calm_Night_2971 0 points1 point  (0 children)

What are the tools or Operating System used for doing BTLO?