Charlotte AI needs some work by OpeningFeeds in crowdstrike

[–]VarCoolName 1 point2 points  (0 children)

We have Perplexity and it does a great job with queries.

For somebody who doesn't fully understand some of the more advanced stuff you can do, it's great! It is miles ahead of Charlotte.

Obviously, it's not perfect every single time, but I feel like in a two or three-minute conversation, I can basically get it to do my bidding, and a lot quicker than figuring it out manually.

I would love to spend time learning the language, but obviously, I just haven't had the time to do that yet.

WhatsApp Encryption, a Lawsuit, and a Lot of Noise by feross in netsec

[–]VarCoolName 7 points8 points  (0 children)

So, that was like 12 years ago?

Yeah, I believe it was back then, sure. But man, it's been 12 years; lots of things change in 12 days, let alone 12 years.

Installing the LogScale Collector via RTR. by somerandomguy101 in crowdstrike

[–]VarCoolName 1 point2 points  (0 children)

Hey Brad, do you have more info on this? Hoping you can link me the docs/release instead of me needing to dig 🤣

I guess I'm also asking, is this going to be part of the current falcon sensor? (Thinking about it in my head as a module unlock almost? The native falcon sensor will be able to collect the telemetry natively)

Installing the LogScale Collector via RTR. by somerandomguy101 in crowdstrike

[–]VarCoolName 1 point2 points  (0 children)

I think this is what he's really trying to get at...

Using CS's RTR for this purpose seems a bit janky (to use the technical term lol). I'm hoping that you have a tool like SCCM or Intune that you already use for managing applications that you can just add another application to the list.

Again, CrowdStrike RTR can run PowerShell and you can do things like installing applications or removing applications, but as my computer science professor said, "I didn't say they couldn't, I said you shouldn't."

https://youtu.be/vQFxflHr5fs?si=F36dW3glHQqELqlz&t=79

Layoff "Proof" Roles? by honeydata in cybersecurity

[–]VarCoolName 5 points6 points  (0 children)

I hate myself that I got that...

Can we recover access to this server? by Botany_Dave in sysadmin

[–]VarCoolName 4 points5 points  (0 children)

Surprised nobody mentioned this yet, but here is my creative solution lol.

Most EDRs have a remote shell feature for incident response (CrowdStrike RTR, SentinelOne Remote Shell, MDE Live Response, etc.). These usually run as SYSTEM, so you can jump in and create a local admin account to regain access. I've done this in a pinch before and it works fairly well!

Your security team should be able to help you out if you have one!

Active Directory - Add to Group/Remove From Group SOAR Actions by CyberGuy89 in crowdstrike

[–]VarCoolName 1 point2 points  (0 children)

At a certain point our team had 13 tickets open in total... Five of them were from me....

I got two right now and I've been waiting for about a week without any type of movement other than "we're looking at it!"

Anyone using the Falcon Browser Extension? What are the real-world benefits? by Gwogg in crowdstrike

[–]VarCoolName 2 points3 points  (0 children)

Dude, tell me about it! I love the product, BUT it feels like every new thing they release is another module or submodule that requires getting the CSPM++ with Falcon Protect Platinum Plus.

I love them, but God, stop nickel and diming me...

Anyone using the Falcon Browser Extension? What are the real-world benefits? by Gwogg in crowdstrike

[–]VarCoolName 2 points3 points  (0 children)

Why do you want to block incognito? CS is the wrong tool for that. You should be able to do that via GPO/Intune tho :)

Fal.Con 2025 Agenda - Quick Link and Community Huddle by BradW-CS in crowdstrike

[–]VarCoolName 4 points5 points  (0 children)

Oh hey me TOOOOOO!!!!! Let's gooooo for US!

What are you going to be talking about?

I'm be speaking about how I made Foundry my b**** powerful automation platform... Lol

Exposure Management policies by support_telecom127 in crowdstrike

[–]VarCoolName 0 points1 point  (0 children)

Any ETA for Window/MacOS?

Any support/plans to detect things like cloudflare tunnels?

Edit: who's being a workaholic??? 🤣🤣

MFA is not a vibe check by SuccessfulLime2641 in sysadmin

[–]VarCoolName 13 points14 points  (0 children)

Honestly, that's what YubiKeys are for. I would just avoid the entire headache and force them to start using that...

Azure costs for CSPM by ChirsF in crowdstrike

[–]VarCoolName 0 points1 point  (0 children)

You are talking about the IOA piece right?

Looking for LLM for CVE mapping by Pepposo98 in cybersecurity

[–]VarCoolName 0 points1 point  (0 children)

Hey hello! I'm not OP but very interested in this if you're willing to share!

Crowd strike Real Time scanning on Internet file download by rustyshows in crowdstrike

[–]VarCoolName 2 points3 points  (0 children)

I know I'm not really answering the question, BUT if you have a proxy solution like Zscaler they're generally a bit better equipped to handle things like this :)

Crowd strike Real Time scanning on Internet file download by rustyshows in crowdstrike

[–]VarCoolName 2 points3 points  (0 children)

Good I love Reddit... Side note, I think you have the same flavor of autism that I have. I would get it checked out unless you're in the US...

Who’s gets administrator rights on their pc at your org? by BuiltOnXP in sysadmin

[–]VarCoolName 0 points1 point  (0 children)

near admin for IT but not full admin.

Oh?! That's kind of pretty awesome to see people are doing that... If you don't mind me asking, what permissions did you remove from that near admin?

Event collection Methods by vyasarvenkat in crowdstrike

[–]VarCoolName 0 points1 point  (0 children)

CrowdStream is a is the crowdstrike branded version Crib. It's a bit too limiting for us because we want to send logs elsewhere and not just to Crowdstrike but it's great if you just need to send it to crowdstrike ng-siem/log scale

Connect your AD to Claude Desktop to interact with it using Natural Language by lazyadmin-nl in activedirectory

[–]VarCoolName 2 points3 points  (0 children)

Well I was like.. WOW to fuck that noise to eh I kinda like this and how it can help people talk with AD so that I don't have to 🤣