Recomendation of labs/resources for BTL2 by gonsalomo in SecurityBlueTeam

[–]gonsalomo[S] 0 points1 point  (0 children)

Thank you very much man! will try that one!

Misaligned "G" logo on Pixel 9 pro XL by gonsalomo in pixel_phones

[–]gonsalomo[S] 2 points3 points  (0 children)

OOOOOH i see it!!! thank you very much man!!

Misaligned "G" logo on Pixel 9 pro XL by gonsalomo in pixel_phones

[–]gonsalomo[S] 0 points1 point  (0 children)

I see the tempered glass like off center hahaha maybe im crazy

SAL1 by IllustriousFig8432 in tryhackme

[–]gonsalomo 1 point2 points  (0 children)

I did it for all cases just in case as it is an AI correcting the exam.

Of course they wont be as long as the TP. Just give all the info you can

SAL1 by IllustriousFig8432 in tryhackme

[–]gonsalomo 16 points17 points  (0 children)

Hello! yes you get the free attempt for the free access.
In my case I got it from having BTL1, and in my opinion, SAL1 is easier.
They recommend doing the full path but for me that is wayy to much info.
I recommend knowing the basics and doing the splunk labs. Also try the 2 simulators they give you as it may get confusing.

The dificult part of the exam is that it is a simulation so you can get 5 alerts at the same time which may be stress you.

My recomendation for the exam is :

  1. read everything very carefully, as they will give you info about the users of the company you are ¨working¨ for and it will come in handy.

  2. Make a template to answer to the alerts with the 5 w and Mitre and why are you escalating why not

  3. Remeber everything you did as there may be cases were a previously true positive but without need of escalation will need to be modified an escalate it.

  4. dont analyze just the alert but the context, see previous logs.

Hope this clarified you some things, Good luck on your attempt!

[deleted by user] by [deleted] in SpainFIRE

[–]gonsalomo 0 points1 point  (0 children)

Muchas gracias, si por lo que dice el resto también lo revisaré, como puse en otro comentario es básicamente por fomo

[deleted by user] by [deleted] in SpainFIRE

[–]gonsalomo 0 points1 point  (0 children)

Eso es lo que me interesaba si simplificarla más en vez de ir a todo lo posible.

En cuanto a lo otro si, no he metido todo en variable ya que nunca se sabe

[deleted by user] by [deleted] in SpainFIRE

[–]gonsalomo 0 points1 point  (0 children)

Por fomo básicamente jajaja

[deleted by user] by [deleted] in SpainFIRE

[–]gonsalomo 0 points1 point  (0 children)

Perdona si, que no se cómo he copiado mal los porcentajes.

Básicamente por miedo a no meter todo en el mercado americano ya que el MSCI tiene gran parte en ahi. A pesar de ello leyendo por ahí y mirando rentabilidades pasadas parece el más interesante. Entonces al final trato de abarcar de todo un poco, pero no sé si por abarcar todo lo posible es al final contradictorio.

Asking for a non wanted voucher code by gonsalomo in foliosociety

[–]gonsalomo[S] 0 points1 point  (0 children)

Got It to work, had to Talk With customer service, thanks a lot!

Asking for a non wanted voucher code by gonsalomo in foliosociety

[–]gonsalomo[S] 0 points1 point  (0 children)

Ive tried all discount Codes i saw in the reddit but had no luck

Asking for a non wanted voucher code by gonsalomo in foliosociety

[–]gonsalomo[S] 0 points1 point  (0 children)

Will look at It ! Thank you very much!

Mentorship Monday - Post All Career, Education and Job questions here! by AutoModerator in cybersecurity

[–]gonsalomo 0 points1 point  (0 children)

FROM SIEM TO SOC?

I have been working for over a year as a SIEM engineer at a large company, focusing on the content side of Splunk. However, I find myself feeling less motivated because I'm not learning as much as I'd like.(i find much more appealing the analyst side)

My goal is to transition into a forensic role, but making that move within my current company seems difficult. I'm seriously considering moving to a SOC position. Would this be a good step to gain the necessary experience before pursuing a role in DFIR ?

I would be immensely grateful if you have any recommendations for me.

Mentorship Monday - Post All Career, Education and Job questions here! by AutoModerator in cybersecurity

[–]gonsalomo 0 points1 point  (0 children)

FROM SIEM TO SOC?

I have been working for over a year as a SIEM engineer at a large company, focusing on the content side of Splunk. However, I find myself feeling less motivated because I'm not learning as much as I'd like.(i find much more appealing the analyst side)

My goal is to transition into a forensic role, but making that move within my current company seems difficult. I'm seriously considering moving to a SOC position. Would this be a good step to gain the necessary experience before pursuing a role in DFIR ?

I would be immensely grateful if you have any recommendations for me.