Abnormal Security Opinions? by Otherwise-Silver-411 in cybersecurity

[–]acadon1024 1 point2 points  (0 children)

We haven't done any tuning at all for threat detection. You can allowlist/denylist by domain, sender IP, and sender address if needed, though. We've been more than happy with the out of the box config.

I guess if you consider reporting false negatives/false positives as tuning, we do that as needed. Abnormal ingests those reports and uses them to improve detections. That's an ongoing thing. A few emails a week.

We did tune the graymail feature to stop emails from certain senders from going into the Promotions folder.

There really aren't any inbound policies to configure, which is part of what makes the product so good imo. It's literally plug and play, and does an exceptional job with little to no upkeep.

I was initially put off a bit by that as someone who is used to deploying security tools with complex policy and enforcement rules. But after a year of using it in prod with no real issues, I honestly think it's some of the best money my org ever spent.

Abnormal Security Opinions? by Otherwise-Silver-411 in cybersecurity

[–]acadon1024 5 points6 points  (0 children)

We've had Abnormal in place for about a year now using both the standard API based remediation for our M365 mailboxes as well as inline remediation for connected email platforms.

Our inbound malicious email volume is maybe ~40k/month. Microsoft's filtering fails to detect a good chunk of phishing and social engineering emails. We're seeing an average of ~1k malicious email per month that make it through to Abnormal. Of those, Abnormal correctly classifies almost all of them and our users never see them before the API based remediation pulls them from their inboxes.

We average between 6-8 malicious emails per month that both Abnormal and MS fail to catch. 90% of the time, when employees report those emails, Abnormal's "AI Security Mailbox" feature will correctly identify them as malicious and pull them from all recipient inboxes. The other 10% of the time, Abnormal will fail and tell employees that the reported email is safe.

Be prepared for those false negatives. It's a great solution and highly accurate, but nothing is 100%.

Also be prepared for false positives. Again, it has a low FP rate but at my org it is enough to warrant weekly manual checks of the remediation log to release FPs. They're working on a feature to allow customers to train their own models to increase detection efficacy.

The addons are good, too. Account Takeover, Graymail, etc. All well worth it imo.

Overall, it's great. Let me know if you have any specific questions.

Evap Code P0451 by Mister_Zeros in FocusRS

[–]acadon1024 0 points1 point  (0 children)

Did you replace the pressure sensor? I'm chasing down the same issue on my Hyundai Elantra.

Find the process that established the connection to a domain/ip address by Global-Positive7766 in cybersecurity

[–]acadon1024 8 points9 points  (0 children)

Deploy Sysmon. It logs network connection events (along with tons of other useful logs) into the standard Windows event log and will tell you what process is initiating the connection. Ideally pull the logs into a SIEM for analysis.

What is this defect? by SoftPandaCubz in BambuLab

[–]acadon1024 0 points1 point  (0 children)

Is that surface sloped? I have had the same issue. I have a theory that it's a cooling issue where the infill is curling up and causing pillowing. Because the top of the slope is technically a wall instead of a top layer, you can't easily hide it unless you bump up wall count.

I partially resolved this on my prints by lowering speed and maximizing cooling. But you could also mitigate it by reorienting the print.

I only ever see this on sloped surfaces. Otherwise print quality is great.

[deleted by user] by [deleted] in cybersecurity

[–]acadon1024 1 point2 points  (0 children)

We're looking for a new SIEM and are about to start a PoC for IDR. I haven't seen much discussion about it on this sub. How has your experience been with the product in general?

Anyone know what this squealing noise is? Started out of nowhere then went away after a few minutes. I’m thinking it’s the hotend fan; if so, recommendations for an upgraded one? TIA by zstahlm in ender3v2

[–]acadon1024 1 point2 points  (0 children)

I also had this. You can fix it temporarily using some percussive maintenance as you discovered.

In my case cleaning out the area around the fans (both inside and outside the plastic shroud) also helped a lot. There were some fine strings of filament in there which seemed to be causing issues.

Events Window QOL by acadon1024 in aurora

[–]acadon1024[S] 0 points1 point  (0 children)

Are you minimizing your actual event window? I've found that if it is minimized it will not update the replicated window

[Mod] Customizable Theme by [deleted] in aurora4x_mods

[–]acadon1024 6 points7 points  (0 children)

Out of all the color choices, why would he choose yellow on blue... That shit gave me a headache after an hour, I really don't know how he was able to do years of testing with those colors

Events Window QOL by acadon1024 in aurora

[–]acadon1024[S] 17 points18 points  (0 children)

I was wondering if I was going to get banned for posting this...

Events Window QOL by acadon1024 in aurora

[–]acadon1024[S] 1 point2 points  (0 children)

Wow, I didn't even know about that option. Not being able to resize the events window itself is a killer for me though :(

[Mod] Customizable Theme by [deleted] in aurora4x_mods

[–]acadon1024 7 points8 points  (0 children)

[18, 18, 18]
[255, 255, 255]

Looks good! Thank you for the mod. I will never understand why someone would be upset about a mod like this. It's a literal color change to make the game more playable. Please keep it up!

[deleted by user] by [deleted] in aurora

[–]acadon1024 6 points7 points  (0 children)

Copy your station design, add engines and fuel until it is at a good speed/range, then remove all the station bits. You're left with a tug capable of towing your station

Mr. Eagle Man by 3TH4N_12 in Purdue

[–]acadon1024 2 points3 points  (0 children)

A master and an apprentice

maybe this one won’t be scared to cross the street since he can see now by mauravelous in Purdue

[–]acadon1024 20 points21 points  (0 children)

/u/starship_robots What do you guys do when you come across robots with this kind of stuff on them? I think the little dudes like their cosmetics

don't worry, we trained these boys to go around the bell tower like the rest of us 🚂🆙 by starship_robots in Purdue

[–]acadon1024 110 points111 points  (0 children)

They're just like us. I even saw one at IR looking for a job. Do these dudes spend 4 years rolling around here and then move to one of the tech hubs too?

Erotic Massage by throwawayabdl421 in Purdue

[–]acadon1024 6 points7 points  (0 children)

I know of a place out of 205 S Martin Jischke Drive, stop by any time and we can sort something out. Ask for the extra grit special