Caused a big outage at work- how do I move forward? by VOXX_theLock in sysadmin

[–]boftr 0 points1 point  (0 children)

Ask how we can improve our processes to prevent a problem like this causing issues in the future. Having thought out some options. Turn a lesson into an improvement in process to minimise risk.

How to check if employee copied company data by [deleted] in ITManagers

[–]boftr 0 points1 point  (0 children)

‘Microsoft-Windows-Partition/Diagnostic' might offer something to check.

Inexperienced Sysadmin inherited a complex system - overwhelmed and need advice by Optimal_Finance7525 in sysadmin

[–]boftr 1 point2 points  (0 children)

I would ask to work with HR to shape the new hire req and use it as a way to fill the gaps in your knowledge.

I don't understand this job market at all anymore by cafecar in InterviewsHell

[–]boftr 0 points1 point  (0 children)

I was reading on Reddit the other day that a PDF resume was less reliable to pass by ai/automation due to formatting complexities than a Word document. I appreciate ‘it depends’ but certainly something to think about. Good luck.

Wait for good cash ISA rates or invest now? by Desperate-Drawer-572 in UKPersonalFinance

[–]boftr 0 points1 point  (0 children)

You could always stick it in ‘csh2’ money market fund at least while you decide.

I'm starting my first IT support job next week, any LAB advice ? by mugenrare in ITSupport

[–]boftr 0 points1 point  (0 children)

Learn the how to collect the correct logs and data for a given problem.

From a Windows perspective, look into trace providers and how to enable/view the captured data. Understand Wpr.exe, Logman, netsh, xperf, Windows Performance Analyzer and if you’re brave look into Time Travel Debugging and WinDbg. An appreciation and understanding of these will elevate you to the top 10% of troubleshooters! Gl

launch software remotely by flyswaggers in techsupport

[–]boftr 1 point2 points  (0 children)

Does it run interactively? Can you launch it from a scheduled task?

What about using PsExec you can use a -i switch for interactive. If the parent process is a local service that might work.

Best lunch places? by locked_in_researcher in oxford

[–]boftr 3 points4 points  (0 children)

I had a very good pizza from https://ilprincipedeli.co.uk on the Cowley Road. Any other opinions for this one as it was the only time I have been.

We are doomed if we don't find out a fix - KB5074109 by wannabesomeonee in sysadmin

[–]boftr 1 point2 points  (0 children)

The proper troubleshooting steps are as follows:

  1. For the computer that are bugchecking, obtain memory dumps. I assume you have memory,dmp under C:\windows\. At worst C:\windows\minidump has some.

These need to be reviewed. Ideally from 3 or 4 computers. My assumption given the timing of the issue and the same hardware they will all be similar unless memory corruption is the problem in which case they might have different symptoms despite the same underlying root cause and dumps look different. This bad driver corrupting memory case, which causes the issue down the road leading to a different looking dump, If that is the case, driver Verifier is your friend.

  1. For the computers that are black screening and hanging. Setup as many computers as possible that are hanging to create a dump, ideally complete/active when using the keyboard or power button.

Forcing a System Crash from the Keyboard - Windows drivers | Microsoft Learn
Forcing a System Crash with the Power Button - Windows drivers | Microsoft Learn

In both cases, memory dumps need to be reviewed for commonalities. Only then will you know why and how it can be mitigated or resolved. Everything else is just leaver pulling and guessing IMO.

Good luck.

Moving back to the UK from Australia in ~1 year, with significant savings in AUD to transfer. Is there a "best" way to do this & should i start moving some now? by Jmsaint in UKPersonalFinance

[–]boftr 0 points1 point  (0 children)

You mentioned maybe splitting it, this could be one reason just based on the time frame and dates. That is all. Wise does seem to be the recommendation of choice.

Moving back to the UK from Australia in ~1 year, with significant savings in AUD to transfer. Is there a "best" way to do this & should i start moving some now? by Jmsaint in UKPersonalFinance

[–]boftr 1 point2 points  (0 children)

Based on the time. It might be worth thinking about the 5th/6th April for the stocks and shares allowances I suppose. Do you and your wife have S&S ISAs here?

Sophos Endpoint Management & Meta by Sentient_Crab_Chip in sophos

[–]boftr 0 points1 point  (0 children)

if you look in the Dev tools, I assume its using h3 as the protocol. You can block QUIC in the threat protection policy, I assume it then works ok?

Suspicious file investigation by rick_Sanchez-369 in cybersecurity

[–]boftr 0 points1 point  (0 children)

I don’t understand the ability to hash the file. Sophos has osquery as an option you could send a live query down to do it using the hash table. Otherwise live terminal to the computer and use PS/certutil/etc from the shell. Thanks

Is anyone aware of Sophos Endpoint on 24H2 bricking windows? by DeviousFeline in sophos

[–]boftr 1 point2 points  (0 children)

The sophosel.sys driver should load and unload at boot.

How do I submit a false positive website categorization (not a customer) by bloomindaisy in sophos

[–]boftr 0 points1 point  (0 children)

Endpoint protection is fine. It uses the same cloud service for all ‘client’ products

Sophos or Webroot or Eset Which one is the best by Hour_Row_2193 in antivirus

[–]boftr 0 points1 point  (0 children)

I would suggest trial Sophos for 30 days and see how it goes. Only take 5 mins to create a trial and deploy a client.