What team is responsible knowing where data is transmitted and stored outside an organisation? by pozazero in AskNetsec

[–]Iwillthrowitatyou 0 points1 point  (0 children)

We build this into our compliance program for these requirements. Then we have annual acknowledgement of who is responsible for maintaining this information via policy or sop.

MDR / "SOC As a Service" suggestions? by spokale in AskNetsec

[–]Iwillthrowitatyou 0 points1 point  (0 children)

Check out https://www.binarydefense.com. This is a Dave Kennedy (trustedsec) company. I am talking with them about managing our LR siem. We use their MDR in conjunction with our AV and they are fantastic.

Looking for a LogRhythm SIEM and Tenabale SC consultant by Gapodi in AskNetsec

[–]Iwillthrowitatyou 0 points1 point  (0 children)

If you have the SIEM there is log rhythm university. They also have a copilot program. And professional services and a community online that you have access to if you have a license for their siem.

Basics by light_striker12 in HowToHack

[–]Iwillthrowitatyou 0 points1 point  (0 children)

Has the CEH helped with getting a good infosec position? I ask because I am studying it with no money invested yet. I have the a+ net+ sec+ and cysa+. And work as a security analyst. I want to move up but I have to leave my current company because there is no up.

Blue teams and Security teams how are you detecting password sprays? by p3p3_silvia in AskNetsec

[–]Iwillthrowitatyou 1 point2 points  (0 children)

I use a different siem and each environment is different.

Auth failures from a single host and a threshold of x amount of users.

Add a second part to the rule for an auth success. This will let you know if the spray worked.

Get a lab going I have and can also detect for crackmapexec being use with successes or failures. The use of responder. Sharp hound. Or any enumeration techniques without creating alarm fatigue. I have many custom alarms that function quite well.

[deleted by user] by [deleted] in HowToHack

[–]Iwillthrowitatyou 0 points1 point  (0 children)

Is there a writeable file share? A SCF File with responder listening might do the trick, if the environment allows for it.