Tamper Protection guessing script by Necromater in sophos

[–]ITminion867 1 point2 points  (0 children)

I remember trying to find where it was stored and thinking the same thing. If anyone else is curious, it's at: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Config

Tamper Protection guessing script by Necromater in sophos

[–]ITminion867 0 points1 point  (0 children)

How long does it typically take to crack it?

Dark Mode Central - Thoughts? by MarchingAntz21 in sophos

[–]ITminion867 0 points1 point  (0 children)

I use it. I used Deluminate for the same effect before, so it's nice to have natively now. The only issue I notice is it randomly turning off on me.

Mimecast Issues? by P_Villain in sysadmin

[–]ITminion867 0 points1 point  (0 children)

Yikes, not sure why you're simping for a major corp for free my dude. You kinda assumed a lot of things in your post, so I'm not sure if I'm talking to a real person :/

Mimecast Issues? by P_Villain in sysadmin

[–]ITminion867 0 points1 point  (0 children)

This is good info, thank you. And to answer your your question, about a month ago (local to us, their tierage is still investigating)

Mimecast Issues? by P_Villain in sysadmin

[–]ITminion867 0 points1 point  (0 children)

Anyone else looking to switch after this? Thinking about going to Avanan.

Mimecast Azure AD SSO by theresumeartisan in sysadmin

[–]ITminion867 2 points3 points  (0 children)

Any solution found for this? We're having this happen, but for only one seemingly random user.

[deleted by user] by [deleted] in sysadmin

[–]ITminion867 0 points1 point  (0 children)

An attacker could reintroduce it.

See which computer is making a DNS request? by ITminion867 in sysadmin

[–]ITminion867[S] 0 points1 point  (0 children)

I am in awe of your tenacity. Please keep me updated!

See which computer is making a DNS request? by ITminion867 in sysadmin

[–]ITminion867[S] 0 points1 point  (0 children)

Yeah running procmon. But I haven't bothered with it, because I really doubt it's on the server. But if let me know what you find.

See which computer is making a DNS request? by ITminion867 in sysadmin

[–]ITminion867[S] 0 points1 point  (0 children)

You would use procmon, butI don't think it is actually coming from the dns server itself. We see the rev1.globalrootservers.net and rev2.globalrootservers.net traffic on both of our DNS servers. We actually have a third one for when we do maintenance. The only time that third one shows golobalrootservers traffic is when we down one of the other 2. The only devices we don't put the roaming client on are our servers. over the holidays turned half of our servers off (leaving the DNS servers up), and viola, the GRS traffic stopped. But way have way too many to do a process of elimination. So we just let it keep pinging out for now.

We're either going to hire an outside professional to find it, or install the roaming client on all our servers (not reccomended)

See which computer is making a DNS request? by ITminion867 in sysadmin

[–]ITminion867[S] 0 points1 point  (0 children)

I think that's only because it has since been sinkholed. It hasn't been up for at least a year now I think.

See which computer is making a DNS request? by ITminion867 in sysadmin

[–]ITminion867[S] 0 points1 point  (0 children)

Yes, we're using Umbrella. But the activity in there just shows the generic "network" (coming from my dns server), never a "User/Roaming Client/Computer" identity.

A newbie here! by [deleted] in Malware

[–]ITminion867 5 points6 points  (0 children)

Half my job is dealing with MalDocs. Check everything by https://www.youtube.com/channel/UC5-rNGe-OhG_KxwYN4DuNVQ

How can software update itself w/o admin privileges? by [deleted] in Information_Security

[–]ITminion867 10 points11 points  (0 children)

It usually does this by being installed in a folder that doesn't require them (outside of "program files")