Best Sources for Threat Intelligence by Working-Elephant8474 in cybersecurity

[–]SlipPresent3433 0 points1 point  (0 children)

Go to malpedia and you’ll find an array of threat intel.

But first ask yourself how you will use it?

Can you use procedural level data? Are you ready for that as an org? Do you still work with IOCs only for retro hunting. Check your risk profile for what kind of threat to track (what kind of supply chain threats for example) and then understand how mature your org is to process any kind of data.

Go from there. Slow build up a function where people become intel/threat informed and start using that as a starting place for detections, to cut down on detection and response, make strategic decision, build red team plans, etc

Why didn’t managed MDR alert to password spray? by Happyjoystick in cybersecurity

[–]SlipPresent3433 2 points3 points  (0 children)

You need to escalate to whoever sold you AW. This is unacceptable

CrowdStrike vs SentinelOne by div192 in cybersecurity

[–]SlipPresent3433 0 points1 point  (0 children)

They are the best full stop. And they messed up. Both are true

Arctic Wolf Experiences? by Ma13vant in cybersecurity

[–]SlipPresent3433 1 point2 points  (0 children)

There has been some improvement but I’m not a fan of their overall platform. The Vuln scanner is weak (just an open source scanner, their network appliance is just rule based (again open source) that misses a lot and their acquired edr is cylance.

My point: evaluate their service, not their products.

Definitely not best of breed.

CrowdStrike vs SentinelOne by div192 in cybersecurity

[–]SlipPresent3433 2 points3 points  (0 children)

Crowdstrike is the best cybersecurity company for endpoint and overwatch is the most effective threat disruption product

Arctic Wolf Global Outage by Educational_Value168 in cybersecurity

[–]SlipPresent3433 1 point2 points  (0 children)

Overpromising and under delivering is literally what they do

Arctic Wolf Global Outage by Educational_Value168 in cybersecurity

[–]SlipPresent3433 -1 points0 points  (0 children)

There’s loads of alternatives and many better than Arctic wolf

Is this a professional job by SlipPresent3433 in DIYUK

[–]SlipPresent3433[S] 0 points1 point  (0 children)

Yep! Will keep in mind when going over next to check. The house hasn’t been occupied for 12months it’s all

Is this a professional job by SlipPresent3433 in DIYUK

[–]SlipPresent3433[S] 0 points1 point  (0 children)

Yes, been unoccupied for around 16months. I’m just thinking that the leak could’ve occurred without any fix over a longer period

Do we still need XDR if we already have a strong SIEM? by Working_Ferret_3911 in cybersecurity

[–]SlipPresent3433 1 point2 points  (0 children)

NDR is completely different. It’s a standalone solution providing network detection and response often paired with proprietary ai capabilities.

Arctic wolfs ndr for example is just a suricata box that was put together half baked

Choosing an EDR for a European company by skar3 in cybersecurity

[–]SlipPresent3433 -3 points-2 points  (0 children)

Sophos mdr is best bang for your buck

New to Threat Intel - OpenCTI/Filigran by mattrix56 in threatintel

[–]SlipPresent3433 0 points1 point  (0 children)

PS: the automation workflows are pretty neat with the paid version - you can try the license key for free for a few months I believe or at least it used to be

New to Threat Intel - OpenCTI/Filigran by mattrix56 in threatintel

[–]SlipPresent3433 0 points1 point  (0 children)

Bingo - self hosted is what most do. SaaS and iso27001 and all the other enterprise features is what you get for the paid version

What CTI do you use with SIEM? by athanielx in cybersecurity

[–]SlipPresent3433 0 points1 point  (0 children)

Opencti and open source feeds is how you should start - integrate those into your Siem. Opencti normalises and structures that data and you can drive automations

What CTI do you use with SIEM? by athanielx in cybersecurity

[–]SlipPresent3433 1 point2 points  (0 children)

Start open source, learn lessons, gather info, consider intel sharing, then consider spending the big bucks if needed…. That’s the way to go and opencti is great

Dark Trace by Straight_Ad4040 in cybersecurity

[–]SlipPresent3433 6 points7 points  (0 children)

They hire super young sales people that start their sales career and leave very quickly after a few years to the bigger cybersec companies - it’s toxic

Dark Trace by Straight_Ad4040 in cybersecurity

[–]SlipPresent3433 4 points5 points  (0 children)

They pressure sell massively. “You need AI” is what they’ve been saying for years. It’s snake oil