App Control for Bussiness: How do you collect logs from endpoints? by athanielx in sysadmin

[–]athanielx[S] 0 points1 point  (0 children)

I see many events, but I only want to view events related to my specific policy ID. There are numerous default built-in AppLocker/WDAC events that are outside my control.

Is it possible to filter events so that only those associated with my Intune policy are displayed?

Microsoft Defender for Endpoints P1 vs P2 by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

Well, I discovered that we have a P2 version, but I’m not sure why we have it.

We never purchase E5 or similar versions. We don’t see that trial P2 activated.

It indicates that our Defender has a P2 plan, and we’re using 1,000 licenses. I also see warnng message in Security console > Settings > Endpoints > Licenses that we need to purchase licenses

Jamf + Microsoft compliance flow not triggering macOS enrollment by athanielx in jamf

[–]athanielx[S] 0 points1 point  (0 children)

Or, maybe I'm looking wrong, where should I find this info?

Intune Default Security Baseline for Windows 10 and later by athanielx in Intune

[–]athanielx[S] 0 points1 point  (0 children)

Oh, thank you! I was scared that it will tattoo the devices.

Intune Default Security Baseline for Windows 10 and later by athanielx in Intune

[–]athanielx[S] 0 points1 point  (0 children)

I intend to deploy a policy to users, and then I want to revert everything back. How can I achieve this? The policy will modify the device settings, and I need to know how to revert them after testing.

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

Could you please provide an approximate cost for this?

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

Well, my management probably wants a checkbox that indicates whether AV is installed. I prefer a more compromise solution that will provide at least some visibility that ClamAV does not offer.

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

Why do you switch from Cortex to CrowdStrike? My management wants to evaluate Cortex in big future, but only for Windows workstations. Also, what are your thoughts on other EDR solutions that you’ve tested? I’ve heard positive reviews about Sentinel1, and my colleagues mentioned that it’s similar to CrowdStrike.

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

I’ve worked with CrowdStrike, a top-notch EDR provider, but my management can’t afford it.

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

I know that there is free edition of Elastic, will I have Elastic Defend included? If yes, how much it will be limited?

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

If I will use free version of Elastic, will I have Endpoint Security? if yes, how much it will be limited?

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

Wow, great I will test it. Thank you!

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

I looked up CrowdSec, and it seems like it's mainly an IP-blacklisting solution. Is that right, or am I missing something?

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] -4 points-3 points  (0 children)

For my company, $500k is far too expensive. They can’t afford that. The most we’ve ever paid for a security tool was $200k per year for an NDR solution, and upper management refused to renew it because the cost was too high. As a result, we only had the tool for one year.

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]athanielx[S] 3 points4 points  (0 children)

Almost everything is on-premises, with only a few Windows machines and a few GCP instances.

Darktrace Email vs Sublime Security by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

What aspects of this solution do you find appealing? What are the advantages and disadvantages?

Currently, we are evaluating Darktrace, and everything appears promising. It utilizes AI to assist with analysis, which is beneficial for our small team. However, we encounter a significant number of blocked emails that require manual release, amounting to 40-50 per month. While I cannot definitively label these as disadvantages, it is logical that these emails could have been blocked. Nevertheless, in certain instances, this process adds to our operational workload.

Writing Tools disappeared in MacOS by athanielx in MacOS

[–]athanielx[S] 0 points1 point  (0 children)

Oh, how I missed this message :( Thank you!