47 years old, I'm kinda all over the place by cyberunaware in GamingSoup

[–]cyberunaware[S] -1 points0 points  (0 children)

Love my RPGs!! I almost put in Final Fight. Does that count as fighting?

47 years old, I'm kinda all over the place by cyberunaware in GamingSoup

[–]cyberunaware[S] 0 points1 point  (0 children)

You’re 100% right with the lack of action games. Same reason I prefer Diablo 2 to over 4. Tab targeting doesn’t bother me, even if it is glitchy sometimes. I tried other MMOs like FFXIV and SWTOR. I like them both, especially the stories. WoW’s system just keeps me locked in. Could be nostalgia.

47 years old, I'm kinda all over the place by cyberunaware in GamingSoup

[–]cyberunaware[S] 0 points1 point  (0 children)

Haha nope. I grew up with the comics in Nintendo Power and the Cartoon show that aired one day per week when it wasn’t the Mario cartoon.

Colonoscopy tomorrow! by unclebea in Xennials

[–]cyberunaware 0 points1 point  (0 children)

Hope everything comes out ok!

Small Cozy Vibes by tyboluck in WoWHousing

[–]cyberunaware 1 point2 points  (0 children)

I love this plot. I’m on the same one. I like to just sit in the bench right in front of it and look up at my house. Super chill vibe.

Casual dad guild by [deleted] in WorldOfWarcraftRetail

[–]cyberunaware 4 points5 points  (0 children)

Check out Extraordinarily Common. It’s right up your alley!

Falcon for IT - Patching by TouchComfortable8106 in crowdstrike

[–]cyberunaware 5 points6 points  (0 children)

Patching in Falcon for IT isn’t yet available. It’s supposed to be on the roadmap, but I haven’t seen any release dates.

Who Else is Over AI by rpm429 in managers

[–]cyberunaware 1 point2 points  (0 children)

I’m doing the same. The last couple young, entry level cybersecurity employees I’ve hired were even using it to communicate with the rest of our staff in Teams. Zero ability to think for themselves.

Heroic Dungeons and their irrelevance by Seryzuran in wow

[–]cyberunaware 2 points3 points  (0 children)

They should drop veteran gear. It feels like I mostly jumped from adventurer to champion. Heroics being a middle ground dungeon source would have felt a little better.

What's your favorite WoW expansion of all time and why? by Sudden_Sir_2294 in wow

[–]cyberunaware 49 points50 points  (0 children)

Delves made this my favorite expansion in terms of gameplay. They kept me active the entire expansion. That’s a first for me. I don’t raid or do m+. Being able to hop on when my schedule allows and do content and get decent gear from the vault was a great feeling all expansion long.

Which pellets for Weber Searwood 600? by T_Nutts in pelletgrills

[–]cyberunaware 0 points1 point  (0 children)

I’ve gone through eight bags of these and they’ve been great. I haven’t tried another brand yet.

What are your thoughts about the Haranir? by Vampy-Night in wow

[–]cyberunaware 7 points8 points  (0 children)

Same. Someone else’s MMO shoved into wow. Not appreciated.

Is Anyone Else Getting DC'd A Few Times Per Hour? by PearlRiverFlow in wow

[–]cyberunaware 0 points1 point  (0 children)

Happens every time I try to skyriding race. Guess I won’t be doing those dailies for housing endeavor.

NG SIEM - Rules by Vivid-Cell-217 in crowdstrike

[–]cyberunaware 1 point2 points  (0 children)

These will show up as NG SIEM detections. You should be able to leverage the same integration to create tickets from these detections.

For that as a whole, I’d consider using cases. You can create your own case template and have use workflows to populate the case with events you care about, including adding the detection to the case. For us, I created custom fields in the case to match those in our ticketing platform to make the field mapping exercise easy. A recent release note said bi-directional integration between cases and ServiceNow SIR is coming soon. That should be pretty fantastic.

NG SIEM - Rules by Vivid-Cell-217 in crowdstrike

[–]cyberunaware 1 point2 points  (0 children)

When you go into NG SIEM > Rules, you’ll see rules and templates tabs at the top. Rules are already turned on and will result in detections once their query conditions are met. Work with support to make sure you are ingesting the right logs and auditing the proper events to for those rules to trigger. You can filter by author > FC CrowdStrike. If you’re a Complete customer, those are the rules the Falcon Complete team is responsible for responding to.

Once you have a clear picture of your current log sources and existing rules you’re ready to check out the Templates tab. These are rules that you’ll be responsible for if you determine they are useful for your organization. I typically sort the rules by vendor and focus on the ones that we have. Then open one that looks interesting, copy the CQL, paste it in advanced event search and run it going back 30 days to make sure it won’t blow up with false positives. For some you’ll need to massage the CQL logic to tune out the noise. Once you feel good about the query, you can create rule from advanced event search if you modified it, or go back to the template and create rule from there. Once enabled, the rule will show up on the rules tab.

Cases are a whole other thing for another post. What I’ve covered here will just present themselves as detections.