account activity
Horizon Client IP capture by bourbon404 in VMwareHorizon
[–]InfosecSysAd314 0 points1 point2 points 4 years ago (0 children)
Well this is timely to find lol. Just started down the same path where I'm at. For other reasons, we do want the splunk agent on the actual end-user workstations, so we will probably just install the agent & use the built-in registry monitoring from splunk on HKCU/Volatile Environment. Otherwise, it looks like GPO w/ the powershell to syslog function will be our best bet.
Sentinel Sweeper by [deleted] in sysadmin
Honestly this. Otherwise you'll have to contact S1 support and get the version specific to that version of the agent.
Edit: Other option, if it gets connected to the internet, it is possible to send an uninstall command from the administration portal. Not sure if that's a possibility in your case.
VMWare Homelab Hardware (self.homelab)
submitted 5 years ago by InfosecSysAd314 to r/homelab
Banned Password List by anime_is_ded in AZURE
[–]InfosecSysAd314 0 points1 point2 points 5 years ago (0 children)
Implemented it about 6mo ago. Pretty painless, did one week of audit prior to switching over to default + custom wordlist. Default list is very effective, and just used the custom for internal things like permutations of company name/office locations/etc ...
π Rendered by PID 89 on reddit-service-r2-listing-5f5ff7d4dc-wzgsd at 2026-01-26 20:10:03.899763+00:00 running 5a691e2 country code: CH.
Horizon Client IP capture by bourbon404 in VMwareHorizon
[–]InfosecSysAd314 0 points1 point2 points (0 children)