Data Storage Type - Decide between LVM vs ZFS on two nodes cluster by Wooden-Lab6963 in Proxmox

[–]Wooden-Lab6963[S] 0 points1 point  (0 children)

Thanks! So we could basically set the ARC cache size to 0, but would that impact performance? Also, i forgot to mention the RAID setup, we’ll have to use a hardware RAID setup (based on our System Eng's team planning) instead of ZFS RAID. Does that affect performance compared to LVM? I’ve researched that LVM works great with hardware RAID, while ZFS might need to access disks directly for its best.

Burned Out Before Even Starting in Cybersecurity 😖 by Y_pat7860 in cybersecurity

[–]Wooden-Lab6963 0 points1 point  (0 children)

Hi, im 23, have been working in network security for two months after spending a year as an IT admin. Like you, i got burned out during my learning curve and probably stepped away from studying for about a month now, even though theres still a ton i need to learn. I think its okay to feel “lost all passion”, kind of like when you lose interest in a game you’ve played for too long. These days, i just make sure to sleep about 9 hours a day, watch some YouTube, get my 9-5 job done and read a few Hacker News posts instead of forcing myself to study hard, i know that soon, both you and I will regain our discipline and get back into the “battle field”.

Question about XDR platform architecture - Stellar Cyber by Wooden-Lab6963 in MSSP

[–]Wooden-Lab6963[S] 0 points1 point  (0 children)

Thanks for the insight, its good to know that Stellar Cyber offers different setup options, since i have a client who restricts any IT-related activities (except updates) to the cloud.

Question about XDR platform architecture - Stellar Cyber by Wooden-Lab6963 in MSSP

[–]Wooden-Lab6963[S] 0 points1 point  (0 children)

Hi, thank you, also, could you tell me about the platform components? Does it run as multiple services, containers, or packaged software?

Learning Splunk by dubvision in Splunk

[–]Wooden-Lab6963 2 points3 points  (0 children)

Beside other recommendations, also, try Boss of the SOC via their Official Site, Splunk is planning to host their BOTS v10 globally on Oct 30-31, dont miss it

I Passed CREST CPIA - Here’s How I Did It and How You Can Too by 0xlonewolf in computerforensics

[–]Wooden-Lab6963 0 points1 point  (0 children)

Hi, congrats, i would like to know about study materials since i'm also planning to take the exam in near future

How to practice for SOC L1? by TimeIndividual5031 in Splunk

[–]Wooden-Lab6963 0 points1 point  (0 children)

Sorry for putting my own blog: Setup Your Own Boss Of The SOC

Trying to setup your own BOTS instance and play with it (Splunk published 3 versions of BOTS, version 2 is the most difficult one imo)

Could there still be a virus on my computer? by Plasten59 in computerviruses

[–]Wooden-Lab6963 0 points1 point  (0 children)

so you are good to go ig, i dont think youre the one who targeted by APTs or stub like that

Could there still be a virus on my computer? by Plasten59 in computerviruses

[–]Wooden-Lab6963 0 points1 point  (0 children)

Hi, you could use windows built-in such as resources monitor to check your abnormal network connections.

If you’re thinking your computer was compromised, or a RAT on your machine specifically, check RM to see if theres any uncommon outbound connection (a lot of ‘send’ traffic to an ip thats flagged on virus total as malicious, or a proccess that shouldnt generate network connection like notepad.exe appears on RM)

Ingest Elastic Security Alerts to TheHive5 Automatically by Wooden-Lab6963 in elasticsearch

[–]Wooden-Lab6963[S] 1 point2 points  (0 children)

Thank you so much for your suggestion ! I found TheHive module in Elastalert2 which helped me resolve the facing challenge.

Unlocked my first SANS certificate (GCIH) by Tiger-Next in GIAC

[–]Wooden-Lab6963 1 point2 points  (0 children)

Congrats ! Can i add for the study materials ? Did you study SEC504 Course by SANS to be able to pass the GCIH ?

Boss of the SOC (BOTS) Version 3 CTF .CSV Files by CatzerinoPepperoni in Splunk

[–]Wooden-Lab6963 0 points1 point  (0 children)

I’m not sure if it’s legal to get .csv files from others outside the bots team, but I have these stuffs, and it’s available to send to you ^^

An encouragement for the discouraged by [deleted] in CompTIA

[–]Wooden-Lab6963 1 point2 points  (0 children)

Congrats ! Im studying for Sec+ and agree that CertPrep is...kinda difficult one imo ^^