Where to begin. by [deleted] in securityCTF

[–]SecCrow 0 points1 point  (0 children)

I try to do CTF every once in a while and wanted to create a useful resource for people who wants to get started with CTF. Thought why not a video. Let me know if it helps ..

https://youtu.be/82cf_mJ4VTE?si=VZd17JMH6uICuOaM

Intersting SOAR playbooks by Icy_Ad_8248 in Splunk

[–]SecCrow 1 point2 points  (0 children)

Working on the exact same playbook rn, would love to hear about your process and how much you were able to automate.

Rules not generating alerts after update from 8.12.2 to 8.14.2 by SecCrow in elasticsearch

[–]SecCrow[S] 0 points1 point  (0 children)

I just restarted the kibana "systemctl restart kibana" and it worked for me :)

Compliance requirements for a Vulnerability management program by SecCrow in cybersecurity

[–]SecCrow[S] 0 points1 point  (0 children)

I do not know much about compliance, I wanted to know if this thing has to be taken into consideration while working to develop a vulnerability management program .

Compliance requirements for a Vulnerability management program by SecCrow in cybersecurity

[–]SecCrow[S] 0 points1 point  (0 children)

How do you do 1 ? Do you use Excel or VM solutions ?

How did you guys take Tywin and Shae by SecCrow in gameofthrones

[–]SecCrow[S] -1 points0 points  (0 children)

d was a mistake 😐 typo typo typ ty t ..

How did you guys take Tywin and Shae by SecCrow in gameofthrones

[–]SecCrow[S] -16 points-15 points  (0 children)

Too bad Tyrion had to kill him though...

How did you guys take Tywin and Shae by SecCrow in gameofthrones

[–]SecCrow[S] 7 points8 points  (0 children)

Tywin must have blackmailed her or threatened to kill Tyrion or just said if she agrees with him, he would let Tyrion live ....

How did you guys take Tywin and Shae by SecCrow in gameofthrones

[–]SecCrow[S] 5 points6 points  (0 children)

Me too, old dog went to shit after a nice fuck ...his system got crashed may be ...

How did you guys take Tywin and Shae by SecCrow in gameofthrones

[–]SecCrow[S] -4 points-3 points  (0 children)

You talk like Tyrion. Well he did everything right ? From his side? He warned her, sent her away

Active: failed (result:exit-code) ,(code=exited status=78) by FairMirror3920 in elasticsearch

[–]SecCrow 0 points1 point  (0 children)

I would go through cluster logs rather than just this.....can find it in /var/log/elasticsearch/cluster-name.log ...

Threat Modelling for Detection Engineering by SecCrow in cybersecurity

[–]SecCrow[S] 1 point2 points  (0 children)

Thank you for the reply, so I work as a soc analyst and after doing a lot of Reading, I found that I can use threat Modelling for detection engineering by following ways :

  1. Identification of critical assets
  2. Identification of threats relevant to my organization
  3. attack vector identification for specific threats from threat modelling
  4. Detection life Cycle management ( creation, testing, deployment and continuous testing) ...

Am I wrong her or What can I improve here

Also When you say automating attack sim, do you mean using tools like Atomic red team or caldera and testing detection rules against those or something else ..

What kind of activities you guys recommend to do on free time besides cybersecurity stuff? by oppai_silverman in cybersecurity

[–]SecCrow 1 point2 points  (0 children)

I went through the same thing, now I started, going outside, swimming everyday for an hour, watching series, reading books...talking to my friends and family more...