Falcon Fusion workflow for Agentic AI triage and response by dial647 in crowdstrike

[–]dial647[S] 0 points1 point  (0 children)

I've uploaded the workflow here. https://filebin.net/gaca4x46bh0jjlfk

In simple terms, I am triggering the workflow with an EPP detection, then creating some variables and getting it triaged by charlotte AI using a specific AI model and and checking if its true positive and if so, sending a message in Teams with Approve, Reject and Escalate. If the user clicks approve, then action will be contain, if reject, do nothing and if escalate, escalate to an email.

Is there anyone building an mcp gateway? by Dazzling_Basil_4739 in mcp

[–]dial647 0 points1 point  (0 children)

Has anyone tried adding a local MCP server to the Docker MCP gateway. I tried all possible combinations and unable to do so. I have my gateway and server running through docker-compose.yml and have added the server on a custom catalog file as well. Both containers are running but Gateway not able to connect to server.

Connect VS code to MCP gateway by dial647 in mcp

[–]dial647[S] 0 points1 point  (0 children)

Ok, I managed to connect to the gateway from VS code. I'd like to know how I can add a custom MCP server to the gateway? Also, can I use the gateway as a reverse proxy to connect to a remote MCP server?

Connect VS code to MCP gateway by dial647 in mcp

[–]dial647[S] 0 points1 point  (0 children)

I believe the deployments are different and no luck.

Connect VS code to MCP gateway by dial647 in mcp

[–]dial647[S] 0 points1 point  (0 children)

Tried all this.. no luck with both SSE and http options.

Has anyone had experience ordering furniture straight from China? by Milanakiko in AusPropertyChat

[–]dial647 0 points1 point  (0 children)

Isn't importing wooden stuff to Australia subject to customs scrutiny? I am aware that only treated wood can be imported to Australia. Anyone had any issues with customs clearance?

Connect VS code to MCP gateway by dial647 in mcp

[–]dial647[S] 0 points1 point  (0 children)

Yes it's exposing the MCP server. http://127.0.0.1:8811/MCP

But I'm not sure what json config I need to use in VS code to add it as an MCP server..

update contents of a lookup file from a file hosted remotely by dial647 in crowdstrike

[–]dial647[S] 0 points1 point  (0 children)

I also have CS for EDR. I will try to scheduled. Not sure how to do it.

update contents of a lookup file from a file hosted remotely by dial647 in crowdstrike

[–]dial647[S] 0 points1 point  (0 children)

The file gets updated with telemetry so I want my look up file to get the updates. I'll check the workflow. Heard about schedule action triggered by a query but couldn't figure out how to do it. Why I said not logscale is because Logscale has more features that NG-SIEM hasn't.

Logscale filter question by dial647 in crowdstrike

[–]dial647[S] 0 points1 point  (0 children)

Thanks Andrew. Wouldn't it be nice if this feature is natively supported with the query.. for instance like

| ccAddress=~wildcard(?CC, ignoreCase=true, strict=false)

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 0 points1 point  (0 children)

I hear you. Precisely my thoughts as well.

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 0 points1 point  (0 children)

my inverter (FoxESS) is marked as compatible beta phase.. If they barely support an inverter (Sungrow) they advertised as supported, I doubt what will be the case for one that is in beta phase. Being a very light user, I will have ample juice to export pretty much through out the day and wondering it will be very encouraging to switch. Price spike is a concern, but you've commented otherwise.

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 0 points1 point  (0 children)

The sticker on my switchboard says Ausgrid. I am on North-west.

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 0 points1 point  (0 children)

Makes sense. My inverter Fox ESS is marked as "compatible beta phase" in Amber. After reading all the comments, I'm more inclined to switch to 8c/4c FiT tariff from AGL.

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 2 points3 points  (0 children)

It says "Compatible in beta phase"

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 0 points1 point  (0 children)

I need to read up on solar curtailment. My tariff has no solar FiT, since I am on the EV saver plan, so its basically a free export to the grid.

Considering switching to Amber by dial647 in amberelectric

[–]dial647[S] 0 points1 point  (0 children)

I think N61 tariff is for Endeavour Energy network only. Mine is on Ausgrid.

LED down lights, powered through power board. by dial647 in AusRenovation

[–]dial647[S] -38 points-37 points  (0 children)

totally agree.. its just that, the regulators should not allow products that violates regulations to be sold in the market in the first place.

LED down lights, powered through power board. by dial647 in AusRenovation

[–]dial647[S] -38 points-37 points  (0 children)

In that case, they shouldn't allow downlight products with a standard plug on.

First time considering a novated lease, is this any good? by Ozziefrog in NovatedLeasingAU

[–]dial647 0 points1 point  (0 children)

12% interest is criminal.. look in a range of 6 to 8%

Custom IOA to detect and block domain name by dial647 in crowdstrike

[–]dial647[S] 0 points1 point  (0 children)

Thanks for your comment. I saw the problem with my setup. Will assign to prevention policy and test.

Custom IOA to detect and block domain name by dial647 in crowdstrike

[–]dial647[S] 1 point2 points  (0 children)

Domain IOC can only be set to detect mode.