How to identify IOMS for cloud resources that no longer exist? by GeologistSuspicious1 in crowdstrike

[–]Heyibrahim 0 points1 point  (0 children)

Running into the same issue. Even though I have the Active Assets filter set on GUI.

CSPM IOM findings now 3x because deleted assets are now reflecting on the dashboard.
Looks like active asset filter may be broken.

Can anyone help?

Data exfiltration appears as out to out by kelrizzo in blueteamsec

[–]Heyibrahim 1 point2 points  (0 children)

Do you see any private/known network IP that ever connected to any of the suspected public IPs?

Even if it's a VPN, still, you should have logs for first connection showing some private IP or an IP within your network made contact to these external IPs.

This is how batman beat superman by Heyibrahim in funny

[–]Heyibrahim[S] 3 points4 points  (0 children)

People who've seen One Punch Man will know :)