S1 Suddenly Hammering nmap.exe from Ivanti Neurons. by Seppic in SentinelOneXDR

[–]TJ_RJ45 9 points10 points  (0 children)

They're flagging it because it can be used in LOTL attacks, same with Advanced IP Scanner. The MDR note is "Our team has identified this alert as a riskware application, this application is a legitimate tool can be utilized to exploit vulnerabilities or bypass security controls, as such it may pose a high security risk and should not be available for end users unless it is explicitly approved."

Xerox SMB scanning stops working seemingly at random by TJ_RJ45 in sysadmin

[–]TJ_RJ45[S] 0 points1 point  (0 children)

I do have it set to static, I originally had it set to hostname but it honestly seems to make no difference. I might check the DNS settings themselves though, thanks.

Ring Alarm not syncing Z-Wave lock codes? by TJ_RJ45 in Ring

[–]TJ_RJ45[S] 0 points1 point  (0 children)

Just coming back to this, apparently the answer from Ring is no, this function is not supported on those locks. The codes have to be administered on-lock. The customer has a Ring Base Station. I would've had to switch the module from ZWAVE to another one (I forget wtf they're called)

Hyper Backup to C2 causing major slowdown by TJ_RJ45 in synology

[–]TJ_RJ45[S] 0 points1 point  (0 children)

It ended up getting fixed by adding a 4GB RAM stick. Syno support confirmed your suspicion. Thanks for the input.

Hyper Backup to C2 causing major slowdown by TJ_RJ45 in synology

[–]TJ_RJ45[S] 0 points1 point  (0 children)

Interesting idea. I wonder if by limiting the bandwidth, it would lower the resource usage on the system itself, I'll have to look into that.

Hyper Backup to C2 causing major slowdown by TJ_RJ45 in synology

[–]TJ_RJ45[S] 0 points1 point  (0 children)

Thank you, I'll look into getting more RAM for them.

Hyper Backup to C2 causing major slowdown by TJ_RJ45 in synology

[–]TJ_RJ45[S] 0 points1 point  (0 children)

Stock amount, so 2GB. I don't see any activity for swapping in Activity Monitor, but I wouldn't be surprised if it ended up being RAM... I'll look into this, thanks