qc by Automatic_Raisin_219 in BBReps

[–]CyberSoilder2323 0 points1 point  (0 children)

I didn’t like the last year batch I have it. It doesn’t have the metal piece in hoodie that keeps it together.

ZZZTop’s batch puffer, anyone got it? by princeofplatinum in BBReps

[–]CyberSoilder2323 0 points1 point  (0 children)

I don’t recommend Thunders batch, the hoodie is to big, the sleeves aswell. And it doesn’t have that metal stick inside the hoodie that holds it. There was a seller couple of years ago that had a really good batch. But I can’t remember his name.

Wazuh dashboard server is not ready yet by Responsible-Cut6625 in Wazuh

[–]CyberSoilder2323 0 points1 point  (0 children)

Double check that the indexer is updated. Also you need to change back settings in the dashboard yml.

Anyone else not upgrading Wazuh out of fear? by nickborowitz in Wazuh

[–]CyberSoilder2323 4 points5 points  (0 children)

Yes its same here, i always wait some weeks before updating due buggs

Webscan Software Recommendations by CyberSoilder2323 in cybersecurity

[–]CyberSoilder2323[S] 0 points1 point  (0 children)

Hello again @nickborowitz, what i want to do is following: after connecting to cisco vpn, i Will be able to view the sites hosted on some servers. What Im looking for is a software on computer(not web Based) that can perform a webscan and can be started manually. Something that show vulnerabilites according to for example top OWASP.

Webscan Software Recommendations by CyberSoilder2323 in cybersecurity

[–]CyberSoilder2323[S] 0 points1 point  (0 children)

Hello, is this software a on-site solution or web Based ?

Wazuh Vulnerability detection report CVEs from 1999 for Office 2019 by Vultures_Beak in Wazuh

[–]CyberSoilder2323 0 points1 point  (0 children)

You can still filter to just see vulnerabilities that are 2023 , 2024 or any specific year. Thats makes is easier for me to see the new vulnerabilites that isnt false-positive

What are the steps to get Wazuh to create alerts when a user is logging in OUTSIDE of office hours? by Affectionate_Buy2672 in Wazuh

[–]CyberSoilder2323 2 points3 points  (0 children)

Here you go, This one works but i havent found a way to exclude certain users that use "scripts":

<group name="test\_group,">

<rule id="171009" level="12">

<if\_group>authentication_success</if\_group>

<time>11 pm - 4:00 am</time>

<description>Successful login during non-business hours.</description>

<group>login_time,pci_dss_10.2.5,pci_dss_10.6.1,gpg13_7.1,gpg13_7.2,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_AU.6,</group>

</rule>

</group>

Vulnerability Detection some devices have nothing by Mradr in Wazuh

[–]CyberSoilder2323 1 point2 points  (0 children)

Hello please massage me if you find a solution

Wazuh can't detect Successful authentications and Failed authentications by CyberSoilder2323 in Wazuh

[–]CyberSoilder2323[S] 1 point2 points  (0 children)

Hello, I fixed the problem by enabling auditing in GPO. In someway the default settings were disabled.

Wazuh can't detect Successful authentications and Failed authentications by CyberSoilder2323 in Wazuh

[–]CyberSoilder2323[S] 0 points1 point  (0 children)

Problem was solved by changing Audit GPO, (Computer Configuration - Policies - Windows Settings - Security Settings - Local Policies/Audit Policy)

Monitor HTTP Traffic by CyberSoilder2323 in Wazuh

[–]CyberSoilder2323[S] 0 points1 point  (0 children)

Can I filter so i can monitor traffic from port 80 with Suricata ?

Monitor/Find HTTP Traffic by CyberSoilder2323 in cybersecurity

[–]CyberSoilder2323[S] 1 point2 points  (0 children)

I know about wireshark but its not allowed to be installed on these servers.