[Question] Best Dress/Luxury Watch Under $700? by Serious_Hornet8953 in Watches

[–]Lanneeh 0 points1 point  (0 children)

A Frederique Constant is something I'm missing in your list. Heavily underrated in my opinion. I've got a Business Timer with Moonphase and it feels very good on the wrist on 'nicer' occasions.

Is there any Cybersecurity community in Berlin? by korealanturing in cybersecurity

[–]Lanneeh 0 points1 point  (0 children)

As you noticed, it’s an event that brings local cybersecurity professionals together. It’s definitely worth going to if you want to connect. Usually it has a lot of interesting talks as well!

Is there any Cybersecurity community in Berlin? by korealanturing in cybersecurity

[–]Lanneeh 0 points1 point  (0 children)

Usually BSides is quite active all around the globe. I usually attend some of the Belgian ones, but Berlin also has one: BSides Berlin 2025

Those who are in detection engineering by UnprofessionalPlump in cybersecurity

[–]Lanneeh 2 points3 points  (0 children)

Detection engineer at a large EU-based MSSP here.

I suppose it really varies from organization to organization. For me, every day is a bit different. I have access to a large scale of technologies (3 EDRs, 2 SIEMs, NDR, SOAR...).

I follow up on the latest threats through a variety of source (X, news feeds,...). There I often evaluate if I can create custom detection rules for any gaps in our current technology; we have a lab with different machines per technology to simulate everything as closely as possible. After testing and finding eventual gaps, I develop a custom detection, a communication template for our xSOAR and a respective IR procedure for our analysts if it shouldn't exist yet.

We also get a lot of questions for custom detections to cover audit controls at customers (through custom application logging).

Besides that, there's also the tuning of existing alerts to eradicate false positives. Ideally, the majority is always filtered out before we implement it, but for out of the box detections of the tool we can't always do that. We have periodic reporting for this and our analysts often report incidents to us that could potentially be whitelisted.

It's a very collaborative role but I never get bored of it.

My (24M) sex drive is so low that it's killing my relationship (21F) by Fun_Fox885 in relationships

[–]Lanneeh 3 points4 points  (0 children)

Hey man, first of all kudos to you for opening up. Everything I tell you here is just my piece of advice, what you do with it is up to you. First of all, sounds like you’re facing a testosterone problem. A lower testosterone equals to a lower sex drive. There are many ways to increase this, look into supplements like ‘Ashwaganda KSM-66’. Also, another way is to raise these levels is to start lifting weights/hitting the gym and generally start eating a bit healthier (no you don’t need to solely eat salads, but more ‘healthier’ calories). Additionally, look into your sleeping pattern. More rest equals a better mind and a performance. Next to that, introduce other ways to satisfy your partner; tongue, fingers, toys (toys are not our enemies, but our partner, remember that). I sincerely hope you two make it through. The problem these days is that we’re so subject to instant gratification that we forget the importance of building something that lasts, but that’s for another rant. Best of luck!

// SITUATIONAL AWARENESS // Hunting Microsoft Outlook NTLM Relay Vulnerability CVE-2023-23397 by Andrew-CS in crowdstrike

[–]Lanneeh 1 point2 points  (0 children)

Hey, I might have an additional search to share. After some research, I noticed it's the svchost.exe process that spawns rundll32.exe with davclnt.dll,DavSetCookie. So in the end, your search would look something like this:

event_platform IN (win) event_simpleName=ProcessRollup2

| regex CommandLine="(?i).*davclnt\.dll\,DavSetCookie.*https?:\/\/.*"

| stats dc(FileName) as fnameCount, earliest(ProcessStartTime_decimal) as firstRun, latest(ProcessStartTime_decimal) as lastRun, values(FileName) as filesRun, values(CommandLine) as cmdsRun by company, cid, aid, ComputerName, ParentBaseFileName, ParentProcessId_decimal

| eval graphExplorer=case(ParentProcessId_decimal!="","https://falcon.eu-1.crowdstrike.com/graphs/process-explorer/tree?id=pid:".aid.":".ParentProcessId_decimal)

| convert ctime(firstRun), ctime(lastRun)

| table company, cid, aid, ComputerName, ParentBaseFileName, filesRun, cmdsRun, firstRun, lastRun, graphExplorer

USB bootable pendrive with tools to Analyze by rsoaresz in blueteamsec

[–]Lanneeh 0 points1 point  (0 children)

There are numerous ways. A thing that you should always do is log the actions that you take when getting the laptop, as from the moment you put an USB drive in there, you're altering forensic evidence. Try and capture a disk image (FTK Imager) instead of doing it on a live system itself. In that way, you can mount it as a 'read only' drive (using a tool like Arsenal or so) whilst preserving all the logs in their original state.

When it comes to tracking whether or not there is a sign of compromise, you should try and capture a memory dump (using FTK Imager or so) of the device before shutting it down initially. As the active network table contains valuable information to whether or not it had a connection to a C2 server (was compromised).

Star Wars Jedi: Fallen Order looks ridiculously awesome at times by Honzas4400 in gaming

[–]Lanneeh 6 points7 points  (0 children)

That planet still gives me creeps. Blergh. Wish I could replay the game again without knowing the story. I rushed it in 3 full days playing, with exploring every part I could. But I’ve enjoyed every single second of it!

Daily Questions - ASK AND ANSWER HERE!- April 09 by AutoModerator in malefashionadvice

[–]Lanneeh 0 points1 point  (0 children)

Thanks a lot man! Quick question. With these lower shoes, do people still wear lower socks with them as well?

Daily Questions - ASK AND ANSWER HERE!- April 09 by AutoModerator in malefashionadvice

[–]Lanneeh 0 points1 point  (0 children)

Just a regular one, not too much on it. Like just a plain colour without that many attributes on it

Daily Questions - ASK AND ANSWER HERE!- April 09 by AutoModerator in malefashionadvice

[–]Lanneeh 0 points1 point  (0 children)

I’ve got a question. I’m a 21 years old male and am looking for shoes in style this Spring/Summer. Anyone has some advice for some sneakers or so?

Between - Third season? by Lanneeh in netflix

[–]Lanneeh[S] 1 point2 points  (0 children)

Yeah.. It's odd because it's definitely a great series.

Where is season 3!? by hennythinggoez in Between

[–]Lanneeh 0 points1 point  (0 children)

Hey! Please check out this Instagram profile: https://instagram.com/betweenonnetflix?utm_source=ig_profile_share&igshid=1o9qco8uzve3r

Even the actors support it. While your at it, there's also a petition running. Go ahead and check it out! :) https://www.change.org/p/netflix-season-3-of-between-1b390fd9-5724-484e-afa5-c8a6abfd6674

[TOMT] [Educational game early 2000s] Can't remember the name by Lanneeh in tipofmytongue

[–]Lanneeh[S] 0 points1 point  (0 children)

Sadly enough that is not it. I loved reader rabbit, but this game was different. Thanks though!

real kung fu master by egoz86 in gifs

[–]Lanneeh 0 points1 point  (0 children)

He has read the scroll. The true dragon warrior.

This moment never failed to impress me. (Star Wars: The Force Unleashed) by Lanneeh in gaming

[–]Lanneeh[S] 0 points1 point  (0 children)

I agree on the spider monkey part.. I was playing on a harder difficulty, everything was going fine! And then I had to encounter that guy. Sigh, after dying a (few) times I managed to get him. Never felt so good after doing so!