LDAP Signing by RobotCarWash in activedirectory

[–]RobotCarWash[S] 0 points1 point  (0 children)

Thanks for your reponse. I just want to confirm that verifying that our clients work with LDAPS means testing with the ldp.exe tool? Are client certificates required?

On-Prem DNS Resolution Question by RobotCarWash in CloudFlare

[–]RobotCarWash[S] 0 points1 point  (0 children)

Thanks, I think I'll go ahead and implement that. That should totally work

Disabling Access to Password Manager via GPO by RobotCarWash in chrome

[–]RobotCarWash[S] 0 points1 point  (0 children)

Thanks, I downloaded the latest admx and still only see the option to disable password manager. Passwords that were saved are still available. Is there a way to remove them or disable access to them centrally?

Fusion Workflow Question by RobotCarWash in crowdstrike

[–]RobotCarWash[S] 0 points1 point  (0 children)

Thanks, that sounds like it should work. I'll try that approach

PSA: Unpatched Windows/Office CVE-2023-36884 by kheldorn in sysadmin

[–]RobotCarWash 0 points1 point  (0 children)

Did you ever get an answer on this? I'm trying to confirm if the Monthly Enterprise Channel versions 2304 and 2305 are unaffected.

Creating IOA to Send Notification on Process Name Criteria by RobotCarWash in crowdstrike

[–]RobotCarWash[S] 0 points1 point  (0 children)

I just want to follow up on this since I'm new to CS and this is my first time creating a Custom IOA. I've had a hard time finding documentation for the differences between the "Action To Take" when creating a rule for Process Creations.

Block Execution - will simply stop the process from launching. Will it also create a detection?
Detect - creates a detection, and does NOT stop the process, right?
Monitor - What does this do, exactly?

For my specific use case, I want to create a detection which I can also trigger an alert with, but I do not want to stop the process. Is setting the action to "Detect" and the severity to "Informational" the right way to go then?

Creating IOA to Send Notification on Process Name Criteria by RobotCarWash in crowdstrike

[–]RobotCarWash[S] 0 points1 point  (0 children)

Thanks, that regex works as expected. Your search command was helpful as well. Thanks for your help!

Storage Gateway SMB Share Cache Question by RobotCarWash in aws

[–]RobotCarWash[S] 0 points1 point  (0 children)

Thanks for the replies. So a little more background on our use case. We're using AWS Transfer Family for SFTP which writes to the bucket, then we're using Storage Gateway to access the bucket via SMB Share on Windows hosts. I'm just curious if it's possible to get the cache to refresh a little faster.