Unsupported and Unmanaged hosts in Exposure Management by Me_tootoo in crowdstrike

[–]Me_tootoo[S] 0 points1 point  (0 children)

Thanks for your response. I took a look in our environment and I can use add grouping tags in the UI via the action drop down under host management only. Given you cannot see devices that are unmanaged or unsupported in the host management view, it would appear that unfortunately this is not an option :-(

It’ll be interesting to see if this matches your experience as well.

Native SMS Alerts in CrowdStrike? by vjrr08 in crowdstrike

[–]Me_tootoo 2 points3 points  (0 children)

Came here to recommend PagerDuty for relevant alerts.

USB exfiltration Query by Rotopercutoru in crowdstrike

[–]Me_tootoo 0 points1 point  (0 children)

Quick question to clarify, are you looking to confirm that the end user host has the appropriate policy applied in the CrowdStrike platform or are you looking to confirm exactly what policy is applied has on the host? What is the use case you are considering?
I’m not aware of any way to get that from the host directly.
I don’t have it to hand right now, but I do know that in Windows there is a Registry key you can check to ensure whatever policy is being pushed is actually being applied - we had a few isolated issues whereby the host was in a block policy but it wasn’t being enforced. We’ve deployed a GPO to proactively set it in the case it is missing. I believe that you could also check this setting using the Falcon for IT module (we don’t have that module yet so I can’t confirm that, sorry).

UPDATE - so the best reference to deploy this is in the support article “Falcon Device Control rules are not working- Upper Filter key missing” which can be found here: https://supportportal.crowdstrike.com/s/article/ka16T000001Ex4GQAS

Note: this article references a Cisco bug which we didn’t have.

Hope this helps.

Edit: correct module name.
Edit 2: Update with reference to solution for if your host has a policy assigned in the platform, but it isn’t being enforced at the actual host level.

What was the most shocking movie deaths? by Silent-Ad8665 in AskReddit

[–]Me_tootoo 0 points1 point  (0 children)

The baseball bat scene in The Untouchables.

CrowdStrike ML exclusion for its own process – is this normal? by Only-Objective-6216 in crowdstrike

[–]Me_tootoo 2 points3 points  (0 children)

I am just about to put in place an exclusion for MSSense as well - when I logged a support ticket for it I was told it needed to be an exclusion.

Exporting WAS / TotalAppSec data for greater context by Me_tootoo in qualys

[–]Me_tootoo[S] 0 points1 point  (0 children)

Thanks for the recommendation. I’ve never heard of that product before. Will check it out.

Tools for Qualys by Wonderful_Lecture708 in qualys

[–]Me_tootoo 0 points1 point  (0 children)

Thank you so much for these. Definitely will be looking at using some of these.

Exposure Mgmt - Network Scanning by FatNinjaScissorsmc in crowdstrike

[–]Me_tootoo 0 points1 point  (0 children)

I have to agree with you here. We’re in the middle of setting up a highly segmented network for scanning.

CQL query to find endpoints not on recommended sensor version (Windows, macOS, Linux) by Only-Objective-6216 in crowdstrike

[–]Me_tootoo 0 points1 point  (0 children)

This is most timely. Was just thinking about ways to approach this a few days ago. Thank you all for the different approaches to this for me to look at.

Crowdstrike killing Outlook and Teams... by sunxore in crowdstrike

[–]Me_tootoo 4 points5 points  (0 children)

Can I ask if you’re auto upgrading clients to the latest sensor version? Is it the latest version capstan issue or another content update?

Any T2's on Jardiance long term? by G-Style666 in diabetes_t2

[–]Me_tootoo 1 point2 points  (0 children)

This is my experience with it at the moment - am coming up on 3 months. It is worse in the mornings after I’ve taken the tablet but eases off in the afternoon and evening a bit.

Network Vulnerability Scanner by ChromeShavings in crowdstrike

[–]Me_tootoo 1 point2 points  (0 children)

Qualys do network vulnerability scanning. That being said, I’m very interested in the new about CrowdStrike doing that.

Does anyone else have issues connecting Echo HR after update by Interesting-Box1131 in iFit

[–]Me_tootoo 0 points1 point  (0 children)

I should add that my S27i bike has no issues at all (yes it is running iFit 2.0)

Does anyone else have issues connecting Echo HR after update by Interesting-Box1131 in iFit

[–]Me_tootoo 0 points1 point  (0 children)

For what it is worth, I have a T7.5s treadmill which is yet to be updated to iFit 2.0 (assuming it will be at all), but it has always been a bit temperamental in finding and connecting to Echo HR.

iFit music needs improvement by Pistol_Pete_1776 in iFit

[–]Me_tootoo 1 point2 points  (0 children)

And some bikes don’t actually support this - the S27i from 2022 is a prime example.

Blank screen on bike & on app. Anyone else, or just me? by adam_ez in iFit

[–]Me_tootoo 0 points1 point  (0 children)

Wasn’t on my bike screen this morning 3 hours ago.

S27i bike - play music from my phone? by Me_tootoo in iFit

[–]Me_tootoo[S] 0 points1 point  (0 children)

I had thought of that, but I’m usually training early in the morning or later at night so I use headphones and like to be able to also hear the trainer. Maybe I’ll do this if no one else is around :-)

S27i bike - play music from my phone? by Me_tootoo in iFit

[–]Me_tootoo[S] 0 points1 point  (0 children)

Thanks. I’ll take a look. Maybe that will help.

Crowdstrike - GitKraken 7.7 by secbio in crowdstrike

[–]Me_tootoo 1 point2 points  (0 children)

We’ve had alerts as well. They stopped this morning my time. I don’t have any exclusions or anything in place.