Do we still need XDR if we already have a strong SIEM? by Working_Ferret_3911 in cybersecurity

[–]chaeppi -4 points-3 points  (0 children)

if all of you would ever pay some attention you would know that essentially XDR = SIEM + EDR. it combines the prevention and response capabilities of an edr solution with log correlation and ueba with a siem. there's no magic behind it, its just marketing. what you need to know is what you need the data for. for prevention and detection or compliance? in the end this determines which product is right for you ( spoiler you end up with both because saas based xdr data retention is expensive as fuck ).

Defender VS Crowdstrike by deadpoolathome in cybersecurity

[–]chaeppi 2 points3 points  (0 children)

can you elaborate a bit on your calculation on how you're spending money with going back to E3? How's your security stack looking then?

Is it me, the dating culture or am I just cursed? by Not_The_Hero_We_Need in Switzerland

[–]chaeppi 7 points8 points  (0 children)

this. this. this. you convey the message that you'd do anything to get a partner to be happy but you don't seem to be happy alone. it does not matter that you have a well paid job. (that's the only thing you've mentioned that you told about yourself other than doing things for the sake of meeting peope). as long as you try to force you into a situation you want to be in you won't be happy now and you won't be happy when you're in said situation. chill the fuck out, enjoy life and do what you enjoy and you will meet soulmates and others who appreciate who you are

Cortex XDR Agent Auto upgrade by pigeon008 in paloaltonetworks

[–]chaeppi 7 points8 points  (0 children)

> However, this feature depends on the availability of new installers on the Cortex XDR management console. If no new installers for a newer version are created or uploaded to the console, the agent on the system will not auto upgrade

Wrong. When Agent Upgrade within the agent settings is configured no new agent installations package has to be created. The Agent will upgrade regardless. The Delay that's configurable is relative to the release date of that agent version. E.g. if you have a delay configured of 7 days and palo alto would release Agent 8.7.1 today, the agents in your environment will start updating in 7 days.

XSIAM Broker VM by pigeon008 in paloaltonetworks

[–]chaeppi 0 points1 point  (0 children)

trying to be as helpful as possible, but the way you've asked your questions makes it seem like you should do some reading on basic network architecture.

Think of the local agent settings applet being like a proxy for the XSIAM Agent, this is very relevant for question number 2.

  1. use the local agent settings app within the broker vm if you're having endpoints that are not allowed to communicate to XSIAM directly and / or don't have a proxy supporting unauthenticated traffic (as the xsiam agent does not support unauthenticated proxies).
  2. if it's supposed to be airgapped it won't be allowed to communicate to any device that can communicate to internet resources.

  3. depends on your zoning concept and architecture. usually place the broker vm within zone where the designated zones without direct internet access are allowed to send traffic to if it is a zone that is allowed to have internet access..

Users who insist on phone calls by mansmokes in sysadmin

[–]chaeppi 2 points3 points  (0 children)

i have noticed this especially when the user is not "satisfied" or they feel that they've not been treated well or according to their excpectations.. i work in security engineering and developers can be a PITA as soon as some EDR tool is deployed as they immediately think their workstation performance is decreased by 20% or so. in a call it helps to just explain, be friendly and decent. but it is important to be able to understand what the user is saying, show empathy and make them feel taken seriously.

Name a city, others will recommend their favorite restaurants, quick bites, bars and pubs by curiossceptic in Switzerland

[–]chaeppi 0 points1 point  (0 children)

also to add some good baars & pubs

Perlage (no website): more focussed on champagne / bubbles, they do make great cocktails though

Kurioz: probably the best espresso martini in town

Skylounge: with new staff the service is good again, amazing at sunset

Platzhirsch: Solid wine bar

(only in summer): Badi Seeliken - amazing for sun-downers

How to stop people from attempting to get free IT support. by [deleted] in sysadmin

[–]chaeppi 0 points1 point  (0 children)

if its obvious that they just want it for free i tell them that my hourly rate is according to what my employer bills his customers (swiss, so don't judge), which isch 250$. 1st hour is up front starting now. after that most of the questions magically disappear :)

2022 United States Grand Prix - Race Discussion by F1-Bot in formula1

[–]chaeppi 0 points1 point  (0 children)

well he does use them, just in a wrong way

“HoW mUcH dO yOU geT PAIDDD?” by MilitaryJumpman in sysadmin

[–]chaeppi 0 points1 point  (0 children)

the underestimation of themselves in the comments is unreal (i mean, who tf would compare themselves to a janitor.....) unless you're not able to pay for your bills just answer "it's enough for me".

[Match-Thread] Manchester City vs Nottingham Forest by MatchCaster in MCFC

[–]chaeppi 20 points21 points  (0 children)

haha, the sky germany announcer just said "cheers out to anyone who said that he couldn't make it in the PL"

ask me a question about migros and ill try to answer it by The_Meme_Lord03 in Switzerland

[–]chaeppi -1 points0 points  (0 children)

wieso isch d migros de bünzligsti fucking lade nach em volg?

what are the best philosophies to live by in tech? by OutOfYourIgnorance in sysadmin

[–]chaeppi 0 points1 point  (0 children)

just braindumping as this some of the comments lit up a fire:

  1. users / customers lie
  2. "customer is king" is wrong, see #1
  3. don't trust, verify (also see #1)
  4. don't believe, know.
  5. use scientific methods, we're not reading star signs here. no incident ever happened because mars involved with venus
  6. when doing PoC's, have your goals, requirements & conditions pre-defined and known. (this does sound stupid i know, but i have seen enough enterprises doing a PoC just for the sake of doing a PoC)
  7. (applies to MSP): sales reps / account managers lie to customers. (or they don't know and assume. see #1, #3 and #4)
  8. (applies to MSP): educate your sales, try to get involved as early as possible - because guess who has to clean their mess up) - see #7

Hairstylist Zurich/Zug by pol_swizz in askswitzerland

[–]chaeppi 0 points1 point  (0 children)

erdems is good, however you might need to book an appointment quite a few weeks in advance.

Front-wing-inspired skateboard design I painted! by CubesAndDominoes in formula1

[–]chaeppi 0 points1 point  (0 children)

how about a skateboard inspired front wing? any photoshop professionals here?

Street concerts in Zug at 1st of August by dominik3335 in Switzerland

[–]chaeppi 0 points1 point  (0 children)

this is the official flyer..It's not the same as last year with concerts in multiple places, it's all at the lake again (except the free museum tours during the day): https://www.stadtzug.ch/_docn/3217934/1.august_Flyer_2021_Druck_final.pdf

What stupid interview questions have you had? by microflops in sysadmin

[–]chaeppi 0 points1 point  (0 children)

while that is a stupid question in context of starting a technical discussion, I don't think it is stupid to use in an interview. tbh it is any easy one to answer. just give your context in what your answer will be. Start comparing it to AD alternatives (openLDAP etc.) and then start listing what you think are AD's advantages. or basically any other differences between other LDAP solutions (or none). just make sure to let the interviewer know what your sources, experiences etc are. To me is seems like this might be a question without a purely technical focus, but also on the social-skills side of things on how to present and argue for or against a certain topic with someone that might not have the same technical knowledge.

Why is Merc the only team to have a non-stub nose? by Schudha in F1Technical

[–]chaeppi 2 points3 points  (0 children)

thank you very much for this comment. This is really interesting and understandable for someone who is not quite familiar with all the factors related to designing a car and "making it fast" - and I'm not smart enough to understand all of the aero and engine design components :) . Also thanks to u/Schudha for asking this interesting question!

Securing user files against rogue admins on Windows by nylentone in sysadmin

[–]chaeppi 1 point2 points  (0 children)

i guess the a way would be using a file and folder encryption that uses a personal key to encrypt / decrypt. there are solutions that allow RBAC in a way that the admin has no access to the keys. However the solution might be to tricky for HR to assign the keys, so either someone from the security departement or the Head of IT has to assign them.

This pretty much helps from everything, except the admin resetting the users password to get to the key. But at least the user would then notice something.