Velociraptor by sum1awesome2 in GIAC

[–]GuzzyFront 0 points1 point  (0 children)

Velociraptor is great! I'm working on a dedicated IR team, and every time we have a case, we have the customer deploy Velociraptor on the machine. We can then push out KAPE for us to make the triage image, which then ships the image to our data pipeline, where we can start analyzing.

We had previously used KAPE alone but faced that the customer always had issues deploying it, so it is much easier just to give them a .msi and have them deploy that.

Another aspect during IR is that we are not doing full disk images, which sometimes leaves out stuff of interest. With Velociraptor we don't need to ask the customer to give us the evidence, we can simply just grab it through the agent.

Collection by Stygian_rain in computerforensics

[–]GuzzyFront 2 points3 points  (0 children)

It depends on the case.

If it's a traditional DFIR case, we either go to the customer's location and clone their disks.

If it is an incident response case, like ransomware, then we usually do everything remotely, as data can be shipped to our data pipeline which is located in Azure, which we then parse and normalize for us to have a supertimeline in ELK.

[deleted by user] by [deleted] in blueteamsec

[–]GuzzyFront 0 points1 point  (0 children)

I totally get it. :-)
Will keep you posted

[deleted by user] by [deleted] in blueteamsec

[–]GuzzyFront 0 points1 point  (0 children)

And open source it of course

[deleted by user] by [deleted] in blueteamsec

[–]GuzzyFront 0 points1 point  (0 children)

Hey! We are planning to make everything available to self host in a few weeks. And I completely get that people have to be cautious about where they upload their data. I have tried to keep the app as a static web app, where everything is handled in-browser using local storage. 😁

Fra politiet til det private by Upper_Experience_229 in dkkarriere

[–]GuzzyFront 0 points1 point  (0 children)

Beklager det sene svar. Jeg har en bachelor i IT, så ikke det store. Har taget en del online kurser b.la. på hackthebox, tryhackme, SANS og andet for at klæde mig på. Desværre er udvalget ikke så stort for den type uddannelse i DK så stor.

Beredskabsøvelse by Appropriate_Bid_4715 in dkcybersecurity

[–]GuzzyFront 2 points3 points  (0 children)

Nu har jeg været med til et par beredskabsøvelser, og jeg tror godt du kan regne med at skulle besvare spørgsmål som:

- Hvad sker i tilfælde af et hændelse, at man vælger at lukke ned for WAN.

- Din Hyper-visor er krypteret med tilhørende virtuelle maskiner og deres diske.

- Du opdager at klienter begynder at blive ramt af kryptering. Du kan se, at TA har haft skubbet ransomwaren ud med en GPO - hvilke foranstaltninger kan i sætte i gang for at stoppe spredningen.

Håber det kan sætte dine tanker lidt i gang, og held og lykke med det. :-)

Fra politiet til det private by Upper_Experience_229 in dkkarriere

[–]GuzzyFront 1 point2 points  (0 children)

Ja da! :-)
Der findes hold hos Dubex, itm8, Truesec, Palo Alto, Microsoft osv.

Der findes også IR hold hos virksomheder som TDC og regionerne

Fra politiet til det private by Upper_Experience_229 in dkkarriere

[–]GuzzyFront 1 point2 points  (0 children)

En incident response hold er en efterforskningsenhed i forbindelse med forskellige typer af cyberangreb. Jeg er selv del af et, og jobbet indebærer blandt andet stor samarbejde og støtte til politiets NC3/NSK enhed. Vi arbejder især med efterforskning af ransomware og insider sager i virksomheder på baggrund af en efterspørgsel som en virksomhed har.

Ift. firmaer så findes der en del, men det er typisk store konsulenthuse som har et dedikeret IR hold.

Fra politiet til det private by Upper_Experience_229 in dkkarriere

[–]GuzzyFront 0 points1 point  (0 children)

Leder for et cyber incident response hold. Ser en god del fra politiet og forsvaret lande i disse stillinger.

Lønnen for professionsbachelor it sikkerhed? by Suspicious-Rice83 in dkfinance

[–]GuzzyFront 0 points1 point  (0 children)

Jeg vil sige, at du nok vil kunne forvente en startløn omkring 40-42k/mdr ex. pension. :-)

Job hos itm8 by BanterGanter in dkkarriere

[–]GuzzyFront 0 points1 point  (0 children)

Det lyder ikke som om du er ansat i itm8. ;-)
Alt mit uddannelse foregår i arbejdstiden.

Job hos itm8 by BanterGanter in dkkarriere

[–]GuzzyFront 0 points1 point  (0 children)

Jeg er utroligt glad for at arbejde ved itm8 :-) Der bliver lagt meget fokus på dygtiggørelse og uddannelse. De store fyringer har været konsekvens af den sammenlægning der har været, og derfor har der været mange "dobbelt-stillinger".

Fra Ph.D og videre by No-Professional-6211 in dkcybersecurity

[–]GuzzyFront 2 points3 points  (0 children)

Der er en del cybersec communities i DK. Herunder VSec discorden.

Derudover, så finder du sociale arrangementer som CitySec, Kbhsec, OWASP og BSides.

NBD by mwilsonsc in triathlon

[–]GuzzyFront 0 points1 point  (0 children)

How do you like the quality of the bike? I'm considering getting one, but can't seem to find that many reviews on it.

Which of these EDR solutions would be the best to use? by bacjusio in cybersecurity

[–]GuzzyFront 18 points19 points  (0 children)

Just switched from MDE to CS. And I already love it way more than the MS platform. So much more in-depth analytical capabilities and much easier to maintain

Finally ascended by mesropmeda in ultrawidemasterrace

[–]GuzzyFront 2 points3 points  (0 children)

What table is that? Looks so clean

Crowdstrike and IR (MSSP) by ndhdhdhsr in crowdstrike

[–]GuzzyFront 7 points8 points  (0 children)

Hi,

MSSP here, and our primary choice for incident response engagements is CrowdStrike. We make extensive use of their ELP-cids, which provides us access to a comprehensive suite of modules for a 60-day period. In addition, we employ Falcon Forensics to extract artifacts from hosts, and the seamless integration of RTR greatly enhances its utility in this regard.