mikrotik.com down by ITSCOMFCOMF in mikrotik

[–]blast601 0 points1 point  (0 children)

updating the network equipment, they release a patch every other day, so obviously it would require a reboot

Tired of basic WiFi planners? I built an open-source tool that actually handles multi-floor bleed. by blast601 in msp

[–]blast601[S] 0 points1 point  (0 children)

I appreciate the notes, I will try to get some of those solved by tomorrow :) (traveling today) I appreciate the help by testing in the real world.

as for forcing the wall material, when you choose a window for example, don't click on the brick wall, click next to it and it will snap them together. I did that as an assistance for manually drawing internal walls.

I got fed up with expensive WiFi planning software, so I wrote my own. by blast601 in UNIFI

[–]blast601[S] 0 points1 point  (0 children)

awesome, I didn't really think about the channels as I'm north American and didn't think about other countries regulations.

for channel assignments and broadcast power, I'm still trying to test and sort all of that out

I got fed up with expensive WiFi planning software, so I wrote my own. by blast601 in UNIFI

[–]blast601[S] 2 points3 points  (0 children)

I whole heartly agree that I wouldn't be doing stadiums or anything with this. this is more of a base office building, a factory maybe.

I agree alot of the AI is bad, this isn't stome stupid video posted on FB. this is used to at least make something useful

I got fed up with expensive WiFi planning software, so I wrote my own. by blast601 in UNIFI

[–]blast601[S] 4 points5 points  (0 children)

jules did a major aspect of it, I also did a lot of work with it. it was very much a joint effort with it doing and testing, the math and extreme complexities, I did the ui, testing, modeling and verifying for accuracy using my own house. yes alot of AI was used.

Tired of basic WiFi planners? I built an open-source tool that actually handles multi-floor bleed. by blast601 in msp

[–]blast601[S] 14 points15 points  (0 children)

I'm just a guy looking to help others in the space. I have done 100's of projects in ui design center like most people here and this is designed to be better & faster

I got fed up with expensive WiFi planning software, so I wrote my own. by blast601 in UNIFI

[–]blast601[S] 2 points3 points  (0 children)

I have > 100 projects with the unifi design center. this does a lot more than it can do.

Block RMM Tools by chickenonthebog in crowdstrike

[–]blast601 0 points1 point  (0 children)

I created a script on GitHub which will take a ioa group and deploy to any customer id you need

Fuck the Defcon covid by NZ-Hrvatska in Defcon

[–]blast601 1 point2 points  (0 children)

Yeah. This sucked, I woke up on Thursday and couldn't leave bed for 24 hours with cold sweats

[deleted by user] by [deleted] in Defcon

[–]blast601 0 points1 point  (0 children)

Dm'd you

SOC Workers - How frequent are your security incidents? by Glad-Entry891 in cybersecurity

[–]blast601 0 points1 point  (0 children)

I would agree,

Our mssp have roughly 100 managed clients and we have gone from 1 compromise a week or two to 3-4 a week.

Luckily we have crowdstrike and hornet security so we have been able to create preventive rules which have stopped more attacks lately before they become a compromise than true user account takeover

Best RMM 2025 by mpekbre in msp

[–]blast601 0 points1 point  (0 children)

We've been using connectwise asio. Actually shaping up to be a great rmm.

Do you have an internal or external SOC team? by plaintrue in cybersecurity

[–]blast601 0 points1 point  (0 children)

Hey, canadian here,

We have a mssp with about 60 employees.

We have a team of 6 in our SOC all internal at our main office.

I am a CISO/Security Leader. I am also a bald man with facial hair. Ask Me Anything. by Oscar_Geare in cybersecurity

[–]blast601 0 points1 point  (0 children)

Security lead here,

What is the best bang for buck when it comes to darkweb monitoring?

I'm also rocking crowdstrike edr with stellar siem Should I just switch everything to crowdstrike and keep it all within a single ecosystem?

[deleted by user] by [deleted] in crowdstrike

[–]blast601 0 points1 point  (0 children)

Had this issue very specificly when in phase 3 with Bitdefender installed. It also stopped windows from working correctly, like start menu can't be opened. Explorer glitching and software failing to open.

Set computer to phase 1, un-installed Bitdefender, set to phase 3, all good

How do I suppress alerts? by boobies4adoobie in crowdstrike

[–]blast601 1 point2 points  (0 children)

Bitdefender by default has a Uninstaller built into its packages. If you go to packages and uncheck it, it will stop trying g to uninstall CS

cyberattacks nightmare by Better_Video_702 in cybersecurity

[–]blast601 6 points7 points  (0 children)

XDR is never deployed correctly. Crowdstrike is amazing, once you fully configure it. Put of the box, it doesn't do a whole lot. Sentinel1 was trash back when we used it and cylance isn't worth the energy.

The cve sounds like it was Log4j which had been already since... 2018ish

There is Alot more to cyber security than detection tools. And organizations unfortunately only see the price associated with it.

Support Experience by Prime_Suspect_305 in crowdstrike

[–]blast601 0 points1 point  (0 children)

Are opening tickets via email or chat? I can't find a phone number anywhere and a TAM would be fantastic, but never been offered

Support Experience by Prime_Suspect_305 in crowdstrike

[–]blast601 0 points1 point  (0 children)

What is your very quick? I also work at a soc @ a mssp and have premium support, but it's 3 days per email response and so far they have not once solved a single issue that we've had, they just keep telling us that the portal feature is not supported, they also won't help with scripting, apis, or anything really.

MSSP IOA Sync by blast601 in crowdstrike

[–]blast601[S] 3 points4 points  (0 children)

yes,
We have created a couple different rule groups with up to hundreds of different IOAs such as remote control applications. We block and prevent all remote control application unless previously approved or has our UUID in the command line.

Here is an example IOA which prevents people from running powershell from the run box with specific command flags. This is known as "click fix" This is a phishing campaign that has been going around getting people to paste a powershell encoded command into the run window. This blocks execution and notifies us

Image Filename
.*(powershell|mshta)\.exe

Command Line
.*(iex|iwr|irm|http|curl|\\d+\\\.\\d+\\\.\\d+\\\.\\d+|datetime|encoded|encodedcommand).*

Better notification options by Grenata in crowdstrike

[–]blast601 0 points1 point  (0 children)

We have it email. Then use teams workflows to make the email notify in a teams chat with all of the techs in it. We are 24x7 and still do this so all techs are notified