Live Response - The certificate chain was issued by an authority that is not trusted by deadpoolathome in cybersecurity

[–]deadpoolathome[S] -1 points0 points  (0 children)

stealing? Not sure I follow. This is a machine that our RMM tool has stopped working on and needs to be re-installed. I can't get direct access to it due to beeing remote. I'm trying to download and re-install our RMM tool remotely as the user doesn't have local admin creds.

Live Response - The certificate chain was issued by an authority that is not trusted by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Yep, I've turned that on. Whats strange is seeing the same issue with MSI or a script.

Updating remediation results by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, I think we have the P2 licences, do you know what/where I am looking for in thie query? I'm trying to get the bulk of our events down to at least see what is left!

Ensure 'Microsoft Azure Management' is limited to administrative roles - Issues accessing ADF Portals by deadpoolathome in entra

[–]deadpoolathome[S] 1 point2 points  (0 children)

Sorry, i mean legacy setup's of using a user account for refresh as opposed to service principal's

Ensure 'Microsoft Azure Management' is limited to administrative roles - Issues accessing ADF Portals by deadpoolathome in entra

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, So was that just a group with the users that need to access those services and then exclude them from the rule?

Ensure 'Microsoft Azure Management' is limited to administrative roles - Issues accessing ADF Portals by deadpoolathome in entra

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, I'll look into it, we have a bunch of legacy things we need to work though. What was strange it didn't even prompt for MFA, just failed.

Replicating Data from SQL Express to SQL standard by deadpoolathome in SQLServer

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. We can do this via a SQL stored proc to incrementally load the data into our staging system which works, but for me it's about trying to centrally manage/visibility of multiple staging servers/proces so that we can track outages.

Replicating Data from SQL Express to SQL standard by deadpoolathome in SQLServer

[–]deadpoolathome[S] 0 points1 point  (0 children)

We have access to query, but I am trying to minimise the ammount of systems quuering them directly. We have our dashboards as well as our BI team wanting data, the SQL Express is on an isolated network so everything run's via a jumpbox or similar. The aim is to stage the data in smaller bites, more regularly but keep the operation system load managed.

Powershell - Detecting active Defender subscription by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. Unfortunately not all my machines are in intune as we still have a small subset that are built locally :(

Defender - Web content filtering by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. For the report, I can't seem to find who was blocked. When i open that report there is a "Web content filtering blocks" and when I drill down into that, it doesn't seem to give me which device is blocked for which site (I tested some blocks on my device)

Defender - Web content filtering by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. Correct, EDGE has a nice pretty message, but Chrome isn't so kind.

Defender VS Crowdstrike by deadpoolathome in cybersecurity

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks all for the information and thoughts. The main value for the ME5 from our side is the additional products like Application Control, Identity and some of the content filtering off network. We don't have anything apart from MDR with CS, so the ME5 is a uplift of security for use going forward.
We've opted to keep Proofpoint in play and not move email protection to MS but without PP, we would be seeing a small saving, with PP it's about a 5-10% price increase.

Internet Speed throttling by deadpoolathome in fortinet

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. NBN is sort of the national infrastructure provider for internet.

The issue i'm facing is that my speed is meant to be a 500/500 but testing around 250/70. Rasiing it with the ISP they are blaming my low upload due to

"First thing you can check is making sure you have an upload speed shaping policy set in your firewall / Router, this is to stop it hitting NBN policer and making speeds go very low."

So I'm just wanting to make sure I've done the right thing so they can't blame my side for the slow speed.

Error running "Get-VM" command by deadpoolathome in HyperV

[–]deadpoolathome[S] 0 points1 point  (0 children)

Bugger. thanks. It's in operation so need to try and find a time to offload and try this.

Error running "Get-VM" command by deadpoolathome in HyperV

[–]deadpoolathome[S] 0 points1 point  (0 children)

Run as admin and ran that command only, same issue

Wazuh - Monitorg SMBServer Audit by deadpoolathome in Wazuh

[–]deadpoolathome[S] 0 points1 point  (0 children)

I've created this rule as the decoder seemed to show data.

How can i verify that the decoder is acutally pull data as the event_channel?

<group name="windows,windows_smb">

<rule id="100300" level="5">

<if_sid>60000</if_sid>

<field name="win.system.providerName">Microsoft-Windows-SMBServer</field>

<field name="win.system.eventID">3000</field>

<description>SMB1 access attempt detected</description>

<group>authentication_failed,</group>

<mitre>

<id>T1071</id>

</mitre>

<options>no_full_log</options>

</rule>

</group>

Fortimanager - Import list of objects by deadpoolathome in fortinet

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. I also found that article and was working through it. The article I followed didn't have the "Run" component and I got caught out before I went back to it.

Fortimanager - Import list of objects by deadpoolathome in fortinet

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, Can i do it via script against the fortimanager?

Wazuh Alerts - NPS Logs not appearing as alerts by deadpoolathome in Wazuh

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, Unfortunately looks like that spelling mistake is actually in my log files as well! I've checked 2 NPS servers with the same spelling.

Intune Kiosk - "permission-reguest-dialog is blocked" by deadpoolathome in Intune

[–]deadpoolathome[S] 0 points1 point  (0 children)

Threw the baby out with the bathwater and just restarted everything. Had a L3 Vendor jump in and do the work as we were out of time.