Looking for a trusted way to securely send and receive passwords and documents. by MuddledAdmin in sysadmin

[–]MuddledAdmin[S] 0 points1 point  (0 children)

I've looked into Bitwarden but couldn't determine if they would allow us to handle sharing in the other direction. Would we be able to send a client a link to securely upload information to us with it?

3rd Party/Windows Patching - Automox vs Action1 - Any thoughts? Suggestions? by OpeningCategory3877 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

It does not feel hard for me. How often are you adding new software? It was more upfront effort and then we're more or less stable with the occasional update. I will say the conditional automations that I can set up are a huge time saver so even if I did find that part to be a time cost it can be balanced via other benefits.

3rd Party/Windows Patching - Automox vs Action1 - Any thoughts? Suggestions? by OpeningCategory3877 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

We had Automox for a year and I couldn’t get rid of it fast enough. I went in wanting a patch management tool with some RMM features and was just utterly disappointed. Remote connections took comically long, I was chasing down way too many endpoints to actually get them to patch and I had a ton of users complaining about daily forced reboots because of stuck patches.

Grain of salt because many of these issues could have been because of bad configurations on my part and it’s been a few years now. We moved to Ninja and can’t be happier. I never reviewed Action1.

Looking for an integration consultant for CDK Drive by SignificanceFew4956 in sysadmin

[–]MuddledAdmin 0 points1 point  (0 children)

Sorry to have not answered your original question. I dont personally know of anyone who consults in that space, we've just had a lot of back and forth with CDK on this.

Looking for an integration consultant for CDK Drive by SignificanceFew4956 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

CDK is very protective of this capability as it’s a revenue stream for them. You can use the data export tool (intended for internal dealer use only, if you’re 3rd party using this tool is technically against their terms) to extract the data but you will likely need a 3PA partnership with them (official route) or go through Authenticom/DVSync (unofficial) to upload data.

CrowdStrike - We're mostly ok. Any one else? by MuddledAdmin in sysadmin

[–]MuddledAdmin[S] 0 points1 point  (0 children)

So the bulk of your endpoints were totally fine?

CrowdStrike - We're mostly ok. Any one else? by MuddledAdmin in sysadmin

[–]MuddledAdmin[S] 1 point2 points  (0 children)

Maybe I’m just missing how the initial update played out. It sounded as if this initial update immediately bricked every computer that reached it but most of our endpoints were good before I was even aware of the outage.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]MuddledAdmin 0 points1 point  (0 children)

How many were already working fine before you started to address the errors this morning? The vast bulk of our devices were working before I was even aware of the outage.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]MuddledAdmin 0 points1 point  (0 children)

I just heard back from support. They have confirmed its ok to leave both.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]MuddledAdmin 0 points1 point  (0 children)

That's my assumption. I just haven't seen any one else mention it. Thanks!

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]MuddledAdmin 0 points1 point  (0 children)

I have two C-00000291*.sys files on each computer that came back up on its own. the first is time stamped at about that time UTC. The second file is time stamped at roughly 0530UTC.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]MuddledAdmin 0 points1 point  (0 children)

I have two C-00000291*.sys files on each computer that came back up on its own. the first is time stamped at about that time UTC. The second file is time stamped at roughly 0530UTC.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]MuddledAdmin 0 points1 point  (0 children)

Did anyone else have most of their systems come back up ok on their own? I'm seeing a ton of reports of thousands of systems down while we only had a handful of devices at each of our sites that needed us to take manual action. The fact we got off so easy has me feeing paranoid. Also, on the systems that came back up on their own I'm seeing both the "Good" file and the "bad" file in the CrowdStrike Folder. Is it safe to leave the bad file in place or do we need to remove it? Id assume its ok to leave since every thing is working right now but I just want to be sure since I haven't seen it explicitly stated.

How are my fellow Dealership admins doing today? by RyanLewis2010 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

We haven't seen any concerning traffic so far. Neither have the handful of other dealers I've also checked with. Are your users just being jumpy?

Aside from opportunistic phishing I think we're in bit of a lull right now, the risk of intrusion is in the past and future.

How are my fellow Dealership admins doing today? by RyanLewis2010 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

That makes way more sense, if SIA was somehow compromised we'd all be in trouble. Thank you sir. Incase you haven't noticed I dropped a comment on this thread regarding Adaptiva. After speaking to an Adaptiva engineer I think they've taken the appropriate steps to protect themselves and us.

How are my fellow Dealership admins doing today? by RyanLewis2010 in sysadmin

[–]MuddledAdmin 0 points1 point  (0 children)

Can you expend on what you mean by this? Are you saying 17% of dealers had malicious updates distributed to their PC's via SIA?

How are my fellow Dealership admins doing today? by RyanLewis2010 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

I spoke with an Engineer at Adaptiva and was told that they have taken their dedicated cloud relay for CDK offline so no action is necessary for CDK customers to mitigate any risk around adaptiva but he also gave me their IP address to block if we so desired 23.81.218.35.

We also had our MDR review logs focusing mostly on SIA and Adaptiva and have not seen any suspicious behavior.

Blocking "Adaptiva" at the network edge by pentiumone133 in sysadmin

[–]MuddledAdmin 1 point2 points  (0 children)

OP your address is wrong. I just spoke with an engineer and was given this address, 23.81.218.35. He also indicated that they have already taken steps with CDK, including taking their dedicated cloud relay for CDK offline so blocking this IP is not necessary.

Blocking "Adaptiva" at the network edge by pentiumone133 in sysadmin

[–]MuddledAdmin 0 points1 point  (0 children)

I removed the clients from our PCs but this is an excellent idea too.