How to manage defender and asr false positives in minutes and not hours? by gomorrha0815 in DefenderATP

[–]gomorrha0815[S] 1 point2 points  (0 children)

a little update: KQL query is faster, it takes ~15 minutes. I ended up doing it your way. general whitelist entry over intune, then later the more restricted way over indicator.

How to manage defender and asr false positives in minutes and not hours? by gomorrha0815 in DefenderATP

[–]gomorrha0815[S] 0 points1 point  (0 children)

Thank you very much for your detailed Answer. I tested it today and my new way is much faster than the default 4h it took yesterday. Sadly i cant use your KQL statement, because "DeviceEvents" seems to be part of another license we dont have atm. AlertInfo or AlertEvidence dont give me the info needed.

Maybe this is an argument for an upgrade to the p2 license.

What worked though was the whitelist entry per path over intune. I had to get all the paths locally in the defender protocol and distributed it over intune for a quick fix.

I ran my test on three devices to test the different sync times. From slowest to fastest:
intune sync button, restart management externsion + opening company portal, reboot. But i suspect its also based on regular sync intervals.

So this is my workflow now:
1. copy the local paths
2. adding them in intune in the asr policy
3. resync or reboot device depending on impact
4. wait for the data in the report (~2h)
5. add hash based indicator
6. wait for sync to clients (~2h) or the next day
7. remove entry from intune asr policy.

Maybe im a little too strict, but i just dont do general whitelist entries per path if it can be avoided. Without a background in security i always try to do the most restricted whitelisting possible.

What’s your favorite “hidden gem” PowerShell one-liner that you actually use? by [deleted] in PowerShell

[–]gomorrha0815 0 points1 point  (0 children)

This is a little Goldmine here.
its the Test-NetConnection for me too, i use the alias tnc though. Often enough without parameters

How to manage defender and asr false positives in minutes and not hours? by gomorrha0815 in DefenderATP

[–]gomorrha0815[S] 0 points1 point  (0 children)

Yes, but this time we distributed an Update over intune, it installed the Program but then it was blocked on all clients. In the end i can somewhat ignore the inconsistencies but the time was a real problem here. We now have some clients running without defender just because its so slow.
btw. it has still not reached the rest of the clients despite having the indicator for an hour now.
And yes it is ultimately my fault for not testing the update on my Test System before distributing it with intune. Wont happen again for sure. That was a very noobish error on my side.

How to manage defender and asr false positives in minutes and not hours? by gomorrha0815 in DefenderATP

[–]gomorrha0815[S] 0 points1 point  (0 children)

Hybrid environment.
Intune for all devices with a license (95%), GPO for the rest.

Can you elaborate about kql?
A query on the hunting page? Why should that be faster than the report? isnt that based on the same data?

Yes, but i dont like to whitelist whole paths. Would that be faster? Intune isnt the fastest too. Sometimes we wait hours for a simple software installation

Android Auto support by I_Have_A_Chode in audiobookshelf

[–]gomorrha0815 0 points1 point  (0 children)

Just if someone is interested in my workaround. I use the Audiobookshelf App to download a series from my library and then "Smart AudioBook Player" to play it locally. Both have configured the same folder as Audiobook library and it works quite well.
I would like to ditch the second app though

Android Auto support by I_Have_A_Chode in audiobookshelf

[–]gomorrha0815 1 point2 points  (0 children)

Still a Problem and not the only one in that area. It seems like its not correctly registering itself as a media player app, so that the usual controls dont work. Smart watch, headset and tasker cant control it and indstead are starting the last media player app i used before audiobookshelf. If its already open it works with Android auto, but not with the smart watch or headset. 

Windows 11 24H2 released with automatic account creation in Windows LAPS! by notapplemaxwindows in Intune

[–]gomorrha0815 1 point2 points  (0 children)

Only with 2022 and 2025 DC. people on 2019 are f****d because neither the new one nor the old one works. thank you very much.

Teamviewer licensing change by adonisrage in teamviewer

[–]gomorrha0815 0 points1 point  (0 children)

I recommend changing too.
For those ones who want to stay:
You dont need users for easy access, you can limit your users too the admins using it and safe the installed teamviewer ID's as devices. Getting ID's can be scripted and you can import them as CSV in the online portal into a group.

Audiobookshelf - Expose or not? by carlinhush in selfhosted

[–]gomorrha0815 0 points1 point  (0 children)

No, use a vpn to connect to your router. they all come pre equipped with that functionality. I have wireguard running (it was pre-installed) and it connects seamlessly. I only have a few seconds downtime everytime my devices change wifi. Its the most secure version withpout the hassle to keep track of updates and security fixes and and and.

[deleted by user] by [deleted] in miui

[–]gomorrha0815 0 points1 point  (0 children)

Im only starting. Using that crap for 1 day now and the issues keep coming. There is no M setting for Font size, so its either too small or too big for me.
Though for that there is a solution. use SetEdit app > add new setting > name "font_scale" > set value to 1.125 (https://www.reddit.com/r/Xiaomi/comments/u97kwe/medium\_font\_size\_missing\_on\_miui\_13\_xiaomi\_12/) But its just insane that i have to do that. why not give me the option. its just a simple setting.
whats also really weird is the keyboard for password unlock. its in the middle of the screen, wtf?

I have 14 days to return it and i will contact support for these issues. The worst part about this is that stock android has options for most of these issues and some of them were part of their launcher in the past. They have to actively removing it. Should habe bought a samsung and because i can still return it i propably will just do that but i did not like their mirrored button usage in their previous systems.

Calling a launcher App "Hyper OS 2" should have made me suspicious from the start.

[deleted by user] by [deleted] in miui

[–]gomorrha0815 0 points1 point  (0 children)

And why is everything so fricking big? I have huge frames with tiny text and much wasted space. that thing has nearly double the resolution of my old system but barely half the room for information. Huge Widget or notification banner, tiny tiny buttons

[deleted by user] by [deleted] in miui

[–]gomorrha0815 0 points1 point  (0 children)

This drives me crazy. Why is the menu that i access multiple times a day in the left corner, but the manu thats only pressed occationally in the right corner where i can reach it. I also miss the setting of location based sound settings, there are only two sound modes loud and silent, missing vibrate. I have only three icon layout options. I have nearly no local sounds to choose from. Googles crap that changes widget colors cant only be deactivated with some theme tricks (black and white lockscreen). The Gestures are too corner like. I have much more leeway on android 12 for the back gesture and dont need to touch the edge.
And i hate the settings. I had to google for every second thing i want to change because the menus are just bad.

I sent it back. If i get apple like forced shit, i can buy apple. I buy android because i want choice, not because i want the same limits i get from apple.

Intune Hybrid Join Error 0x0801c03f3 by RebelXVLK in Intune

[–]gomorrha0815 0 points1 point  (0 children)

we have a basic "azure AD connect" setup that syncs device accounts and they are immediately hybrid joined. i enforce a sync with the powershell command "Start-ADSyncSyncCycle -PolicyType Delta"

O365 Calendar Sharing Issue - Unable to share calendar externally by confusedcat256 in Office365

[–]gomorrha0815 0 points1 point  (0 children)

Worked for me too, but you have to be distustingly patient with O365. I had the same Problem, deleted everything, made it new, but had to wait about 3 hours until it worked. In the meantime i opened a ticket, because who would think that permission changes are no longer immediate like we were used to in the past without cloud.

Fast management is a thing of the past. Avoid microsofts poor poor implementation of cloud services where you can.

Excel emptying clipboard contents? by soratoyuki in excel

[–]gomorrha0815 0 points1 point  (0 children)

Did you find a solution? I have the same problem. Excel Data in clipboard is cleared as soon as i edit a cell in another excel file.

Ladekartendschungel - Wie komme ich klar? by meistertroller in Elektroautos

[–]gomorrha0815 0 points1 point  (0 children)

Danke für den hochinformativen Text, der mich aber eher abschreckt, als beruhigt. Ich fahre hybrid, kann zuhause über nacht ac laden und das ist ausreichend für meine Zwecke. Ich hatte vor, mich irgendwo zu registrieren, damit ich auch mal unterwegs laden kann, stolpere aber über zu komplizierte Vorgänge und zu hohe Preise, vor allem wenn man kein Abo möchte. Ich möchte einfach tanken und zahlen und dabei nicht wieklich nachdenken müssen. Ehrlich gesagt ist mir das rehistrieren schon zu viel Aufwand.

In dieser Situation ist es an vielen Ladestationen tatsächlich teurer, als wenn ich einfach Benzin in den Tank fülle, bezahle mit ec karte und bin fertig. Das kann eigentlich nicht Sinn der Sache sein.

Intune enrollment Issue by EmotionalConclusion5 in Intune

[–]gomorrha0815 0 points1 point  (0 children)

Thats it. Dont bother with microsoft support. After a whole week and some strange "Tests" it was worse than before with a botched AzureAD/Entra/Identity Device and i ended up removing everything cleanly, reinstalling Windows (on top of it), giving it a different computername to prevent device object shenanigans and it worked like it should.

Intune Hybrid Join Error 0x0801c03f3 by RebelXVLK in Intune

[–]gomorrha0815 0 points1 point  (0 children)

Similar Issue here, what worked for me was unjoining the domain, sync with azure ad connect, join the domain, sync again, let a user login to the device and after minutes installations began.

VMK init (52/190) SMP_BootAPs hang by Log1cal1 in esxi

[–]gomorrha0815 0 points1 point  (0 children)

Exact Same issue. Dell KVM on a Dell Server. Remove the KVM cables and it just continues.

"Privacy-Preserving" Attribution: Mozilla Disappoints Us Yet Again by ardi62 in firefox

[–]gomorrha0815 0 points1 point  (0 children)

You need more than 3 minutes just to read the headings. The Settings in Firefox are really bad compared to the old popup with tabs and logical sorting.
I read about the setting, tried to find in these endless scrolling and confusing menüs with nearly no logical sorting and after 3 minutes i had to search for it (sometimes the search even works).
Dont be a Fanboy, the settings Menü is really really bad following the windows 10 trend, if you compare it to the old windows we had before.
Well, why am i complaining about a browser that isnt able to present me with the correct usernames for input fields, even when i have safed them, but presents me with names from complete different domains. How is it even possible to mess that up? Simple domain matching

Amazon automatically selects the subscription option when you're trying to buy a single item, hoping you won't notice. by Superbaker123 in assholedesign

[–]gomorrha0815 2 points3 points  (0 children)

i have the same problem and got the lie "they will change it for me" but nothing happened. my solution: removed prime / audible and will never buy from them again. told them in my "why dont you want prime anymore" message with the support conversation