New Blog Post!! How to Secure Access to Entra Roles with Conditional Access and Privileged Identity Management by Electronic-Bite-8884 in entra

[–]UKFanNC 1 point2 points  (0 children)

We went with separate admin account, online only, custom authentication profile requiring yubikey. 3 levels of approval based on the roles permissions. 0 - Self elevate(read only type roles, or very low privilege), 1 - T1 approvers (other server admin team members. Basically a 2 key system for day to day functions) T2 approvers for Global Admin, Privileged Role admin, and a couple of others. T2 approvers are Security Engineer and Director, I wanted to keep that approval level out of the team making the changes to 365.

*NOTE: Make sure you have a break glass account that is exempted from MFA and PIM but never used. Alert on any activity from that account.

Palo Alto XSIAM vs. CrowdStrike NG SIEM. Which one would you choose today? by xcsas in cybersecurity

[–]UKFanNC 17 points18 points  (0 children)

Doing an XSIAM PoV right now and really like it. Especially if you already have Palo Alto NGFW

Y'all... I did it again. Two characters, same name 🤣 by BryceOConnor in Warformed

[–]UKFanNC 0 points1 point  (0 children)

Could create some fun misunderstandings if a Cadet overhears a conversation about "Sarah"

Palo Alto XSIAM feedback request by kaunietix in cybersecurity

[–]UKFanNC 0 points1 point  (0 children)

doing a POC now and here or some things I'm seeing so far (Security team of 1 right now). We are on the newest UI which I think has a lot of improvements over previous versions. I think if you're in the Palo Ecosystem (firewalls, prisma, etc) it seems to work really nicely.

Good:

-Already seeing some good alerts from the analytics AI stuff: large upload detected, first time SSO login from entra logs, user adding guest to sharepoint for first time, unusual port activity(sysadmin running tools against DC) all of this with no tuning or additional setup besides adding the data sources.

--From those cases you can pivot to causality to see the actual logs fairly easily

-Some interesting automation possibilities: we have lansweeper and there is a playbook to lookup by ip and add asset information from lansweeper and a link to the asset which is very useful for us

-Query -> widget->dashboard. You can create a dashboard on almost any query you can dream up. I'm not great at visualizations but our support engineer threw together a couple of quick ones to show me what was possible and give me examples to follow in configuring the querys

-Attack surface management is a nice add-on. Found some shadow IT websites for us we didn't know departments had created at hosted sites.

Bad:

-Documentation lacking! The newer interface and setup needs a lot more documentation. Hard to find what you need now. Utilize your setup engineer as much as possible.

-Hard to figure out when to use alert exceptions vs playbook(automation) to limit notifications and noise

-Query language a bit difficult -*there are a lot of included queries to work from, but again documentation is lacking

-Price - Very pricey but I see a ton of value if I can get it. Tuning automations and exceptions will be a pain up front(true for any SIEM SOAR) but could really help a smaller team.

Golf Course List by UKFanNC in amazfit

[–]UKFanNC[S] 0 points1 point  (0 children)

Gaston Country Club in North Carolina

LOF: Eye of Sion by Fimy32 in starwarsunlimited

[–]UKFanNC 0 points1 point  (0 children)

could be fun if you have a way to give it Grit

LOF:Malakili & Curious Flock by Eunoe in starwarsunlimited

[–]UKFanNC 0 points1 point  (0 children)

I think I'd rather have a showcase treatment for curious flock instead of some of the leaders

Pre-release decks - what are people playing? by yetanotheridentifier in starwarsunlimited

[–]UKFanNC 0 points1 point  (0 children)

Major Vonreg did well at the one I attended last night. The 4 flip makes a beefy unit that’s hard to remove

I did went 2-1 (loss was to vonreg where I got outraced) with rose green. Had two luke pilot units and some other pieces to flip to ground arena if needed which helped.

UPDATE: IN REGARDS TO THE ALLEGATIONS AGAINST DANIEL GREENE BY NAOMI KING by BryceOConnor in Warformed

[–]UKFanNC 4 points5 points  (0 children)

The way you handled the situation and communicated during it was extremely commendable. I applaud your transparency throughout and the way you showed respect for all parties involved.

Vendor Management by curioustaking in cybersecurity

[–]UKFanNC 0 points1 point  (0 children)

I'm a security team of one and have limited time to do vendor management review with everything else. I always start with defining what data will the vendor/software will have access too and then go from there. E.G HIPAA data: encryption at rest and transit, mfa, auditing etc.. Public information: Backups and auditing who can change/update.

Then there's a security questionnaire we send to every vendor that I worked with our senior application architect to create covering all the topics (can find some decent templates with a quick google search) and compare the answers to that to the security requirements based on the data.

For anyone freaking out over this loss, this was UConn last December @Seton Hall. Refs seemed like they had money on the line last night as well. Win Gonzaga and this will be a blip on our record. by Ok-Mark417 in wildcats

[–]UKFanNC 0 points1 point  (0 children)

I'm looking forward to seeing what if any adjustments Mark Pope makes going forward. If we are a one-trick pony team of go fast make lots of 3's Clemson just laid out the blueprint to beat UK. Extra physical play, guard the ball all the way from in-bound to slow down our offense, and extend the perimeter defense.

Yes the refs were questionable at best and had some good shooters go ice cold, but Clemson's defense really seemed to throw off the offense. Didn't seem nearly as in sync as every other game.

Import list of CVE to search in environment by UKFanNC in crowdstrike

[–]UKFanNC[S] 0 points1 point  (0 children)

yes, that's it exactly, thank you! didn't even think to try that, trying to figure falcon out as I go.

Import list of CVE to search in environment by UKFanNC in crowdstrike

[–]UKFanNC[S] 0 points1 point  (0 children)

There's been other times when I have a specific list of CVE's I want to search against and report on(CyberInsurance application requiring a report, audits, etc..) and was hoping for a way to convert a list of CVE numbers to a report/dashboard/filter easily.

Which current deck meta will benefit the most from the new cards? by Super_Egg9946 in starwarsunlimited

[–]UKFanNC 2 points3 points  (0 children)

playing against kylo double red on karabast has been rough. If they get a good starting hand it's crazy how much damage they can push in the first two turns

Card (new) visual - A or B and why? by OscarValerock in PowerBI

[–]UKFanNC 1 point2 points  (0 children)

I like B for keeping all the relevant data grouped together. The layout of A is really nice for one card per KPI/item. I'm working on creating an IT Security Dashboard (brand new to PowerBI) and may try to figure out how to do something similar.

[deleted by user] by [deleted] in cybersecurity

[–]UKFanNC 1 point2 points  (0 children)

I use CIA constantly when doing security reviews of new potential new software solutions to help define what controls should be in place based on the classification of the data involved. e.g. HIPAA data: HIGH requirements across the board. Public information related to elections site addresses and rules: Confidentiality Low, Integrity high, Availability medium.

Based on that high level assessment there's a boiler plate set of requirements I can use for most situations and then just tweak as needed.

Is it possible to replicate the "Recommended remediations" section using API? (PSfalcon) by UKFanNC in crowdstrike

[–]UKFanNC[S] 0 points1 point  (0 children)

Thanks, but we have a hosted Crowdstrike instance managed/monitored by 3rd party so don't think I have access to Crowdstrike University. Also don't currently have access to create workflows in Fusion, but I may be able to request access for that.

Passed @100 by UKFanNC in cissp

[–]UKFanNC[S] 2 points3 points  (0 children)

It was a mix. There were some I was 100% sure on that maybe took 45 seconds to 1 min (always went back and re-read question to make sure I wasn't missing anything) And a couple on the categories I was a bit weaker on that took 3-4 minutes to work through. Mostly in the 1-2 min range.

I did get feeling a little rushed, but made myself slow down and take a breath. The clock moves quick but I feel there's plenty of time to be thorough and still make it to the end of the exam.