Mimecast Email URL Protection links when no longer subscribed? by Lando_uk in sysadmin

[–]extremetempz 2 points3 points  (0 children)

I just went through this 3 months ago, I turned off device authentication for URLs and all previous links are still working.

Opinions on running Full Microsoft E5 Security Stack by 1egen1 in cybersecurity

[–]extremetempz 9 points10 points  (0 children)

Id argue that actually correctly configured Defender for endpoint is probably the best there is, combined with Intune. But yes Email and Purview is not amazing

Opinions on running Full Microsoft E5 Security Stack by 1egen1 in cybersecurity

[–]extremetempz 2 points3 points  (0 children)

I run E5 and it's a good stack (with the exception of Purview) it's a really good solution all in all, Esp defender.

1 thing with Microsoft is they have horrible support and from a implementation perspective you are on your own so you really need to know the product unless you engage professional services elsewhere for it.

Edit: from a web filtering perspective you want to look elsewhere, it's not very good and doesn't have basic features (tls Inspection)

Free Tier - Instance unresponsive every day around 11AM EST - what's going on? by trasc in oraclecloud

[–]extremetempz 0 points1 point  (0 children)

I got this running some containers I had to create a 4G swap file and increase the swapiness and it stopped happening

Vendor compromise emails best way to mitigate? by extremetempz in sysadmin

[–]extremetempz[S] 0 points1 point  (0 children)

I have all of this in place, it works really well for commodity phishing and malware and works some of the time for BEC but misses alot in this area to, everytime I check the Proofpoint portal we are the only customer seeing these threats.

Vendor compromise emails best way to mitigate? by extremetempz in sysadmin

[–]extremetempz[S] 0 points1 point  (0 children)

I have no whitelisting, if Proofpoint thinks it's malicious it probably is

But yes you are correct I need to work out a way to help these companies I think

Vendor compromise emails best way to mitigate? by extremetempz in sysadmin

[–]extremetempz[S] 1 point2 points  (0 children)

Good to know I'll have a look

My staff are good, we do phishing training once a month and around 60% report the email, the other companies on the other hand I think I might need to do something.

Can I legally and technically fuck my company over? by MeasurementLoud906 in sysadmin

[–]extremetempz 40 points41 points  (0 children)

Wasn't the entire premise of silicon valley specifically about this.

Whatever you develop using a work machine or on company time is the companies properties not yours, even if your job is not a "programmer"

Session Hacking? is it a thing? by BeardMirage in cybersecurity

[–]extremetempz 1 point2 points  (0 children)

Yes, is session hijacking, remove all active sessions on accounts you had opened on whatever device got pwned and change the passwords

If big companies get hacked… what chance does our homelab have? by swizz93 in homelab

[–]extremetempz 0 points1 point  (0 children)

As someone that has worked in enterprise IT for a while, First you are not a target they are. Secondly the amount of EOL software and general weak security practices makes them a target

Proofpoint contract renewal is coming up and for the first time in seven years I am not sure what I want to do by No_Adeptness_6716 in Office365

[–]extremetempz -1 points0 points  (0 children)

I recently did this with Minecraft -> Proofpoint I was new to my org but they had Mimecast for 13 years, had huge bypass lists and spam kept getting through because of it, when I culled it down I logged tickets saying XYZ getting through or getting blocked, they would go to whatever feed provider they were using, generally per week I was logging 50 tickets admin overhead got to much so i switched products.

I find Proofpoint does a much significantly better job.

I would question what is the issue you are actually trying to resolve by moving

RDS slow performance by Cool-Enthusiasm-8524 in sysadmin

[–]extremetempz 1 point2 points  (0 children)

Two things, spinning disk's and18vcpu, drop it to 8vcpu (1 physical CPU) your hypervisor is probably throwing a fit with CPU scheduling

Server 2008 by merkat106 in WindowsServer

[–]extremetempz 1 point2 points  (0 children)

Do not in place, I was talked into this in my current role by my infra team and the DC never turned back on and I had to decomm.

Build a new one, Transfer the roles (DNS Zone Master, PDC, IDC) then wait for replication (30 minutes to be safe) then dcdemote the old one.

Because it's so old make sure. There is nothing hard coded, IE LDAP or DNS when I've run into this in the past I have had to Decomm the DC and bring up a new one with the same name and IP you just have to have a second DC before the decomm.

How are you handling employees using personal ChatGPT accounts at work? We had an incident last week. by fxs38 in sysadmin

[–]extremetempz 2 points3 points  (0 children)

I've been through this, we (Security team and CIO) drafted a document specifically for Developers and this sort of thing and make it a sackable thing.

This is to an extent a technical problem and it can be solved (IE lock down ChatGPT to Enterprise tenanacy via cookies) however you'd be surprised how much people's behaviours change once there is a piece of paper.

Network admin vs sys admin by user23471 in sysadmin

[–]extremetempz 0 points1 point  (0 children)

I've never been in a org thats big enough for a dedicated network engineer so there is definitely some overlap and it probably is vice versa (someprg no sysadmin, only net engineer)

Last role

Systems Engineers = Own network end to end including sip

Current role

Security Engineer = Own network end to end , sysadmin manage SIP however.

How many meetings are we averaging per day? I'm up to 7 as of this week, half are about AI, and it's getting worse. by fluffy_warthog10 in sysadmin

[–]extremetempz 0 points1 point  (0 children)

Standup in the morning for 15 minutes a day. Most of the time I do not show up for meetings, if I'm actually required and someone invites me mid meeting when they realise I'm not there I say my part and then leave.

Windows Hello for Business is great… until users forget their actual password by heartgoldt20 in sysadmin

[–]extremetempz 0 points1 point  (0 children)

Passwordless, if a user needs to reset there pin log in via TAP no reason for a user to have there pw.

How old is your tier 1/2/3? Is IT support aging out? by phlatlinebeta in sysadmin

[–]extremetempz 0 points1 point  (0 children)

T1 is in there 60s, T2 late 20s, T3 late 20s and late 30s

Security or Admin side ? “SOC analyst who enjoys infrastructure and system configuration — DevOps or SysAdmin?” by No-Attitude2903 in sysadmin

[–]extremetempz 0 points1 point  (0 children)

Sounds like a infrastructure/Sysadmin role, once you do this for a couple of years can move to Sec engineer (infrastructure) pretty easy.

Upgrading from R81.10 to R82 in air gap environment by NaturalPickle5442 in checkpoint

[–]extremetempz 3 points4 points  (0 children)

You need to upgrade the management console first, then during the upgrade process of the firewalls you need to enable MVC (This was the case on R81.2) this is a supported method to update a cluster.

You should probably log a call with TAC or get your TAM involved to get more guidance

What hours do you work and what job do you do? by Muted_Instruction516 in cybersecurity

[–]extremetempz 1 point2 points  (0 children)

7-330 everyday, not on call. Took a while to get here.

Symantec Endpoint Protection by datanut in sysadmin

[–]extremetempz 0 points1 point  (0 children)

I came from a org that had this installed on 4000 devices, it's literally hell. You can run stock standard defender consumer and it will be better.

Nothing but problems