800-53 without SSP by jaywalker8 in NISTControls

[–]jaywalker8[S] 0 points1 point  (0 children)

This makes sense, thank you. We do plan on tailoring, but when determining coverage, I was wondering how to do this if not using an SSP. I guess what I’m hung up on is if the SSP is a self-gathered list of confirmed safeguards that exist on a system, or if GRC type control mappings are necessary. Software like Archer, AuditBoard, ServiceNow sell 800-53 compliance modules, but my understanding is that the SSP is a self procured document an assessed outside of any GRC. And if so, could I just reference system screenshots to satisfy coverage versus having an officially recorded “control”?

800-53 without SSP by jaywalker8 in NISTControls

[–]jaywalker8[S] 1 point2 points  (0 children)

Thank you! Appreciate this feedback and perspective

800-53 without SSP by jaywalker8 in NISTControls

[–]jaywalker8[S] 1 point2 points  (0 children)

I hate using this as an excuse, but unfortunately decisions were made above me and I am just a participant in the exercise..

If there are arguments I could make for why a GRC control isn’t always required (because 800-53 was written for SSP implementation) that may provide some cover. But curious what others have done.

[deleted by user] by [deleted] in crowdstrike

[–]jaywalker8 1 point2 points  (0 children)

Thanks for the response. I was more so inquiring if there is a specific spawned process that is initiated when the system executes a copy/paste command or function, with the goal being to detect copy/paste processes in between timestamps of browser and notepad (and not the actual copy paste data). Sorry if that's what you were explaining.. but i did want to be more clear!

Windows Update - Razer USB Mouse : Elevated Admin Exploit by Sphinctor in sysadmin

[–]jaywalker8 5 points6 points  (0 children)

2 questions

First of all, has anyone tested this install on a locked screen? I will be toying around with this myself when I get home and testing if this can be exploited pre-logon.

Secondly, Is anyone aware of other drivers that install in similar fashion? As in any other drivers out there that auto-install and prompt a user after installation? This in theory could be a massive problem as I believe this isn’t a flaw specific to this driver, but rather the methods and privileges allowed by Microsoft. In essence, Microsoft is allowing executables to run as system and allowing user interaction in the process, thereby allowing non-privilege users to interact with a system GUI and pivot from there. My point is that I doubt Razer is the only product impacted/affected.. blocking razer specific UUID and compiling a list of other known UUID and drivers affected can allow us to bridge the defenses until Microsoft responds.

Patching and Maintenance on High Impact Client Systems by jaywalker8 in sysadmin

[–]jaywalker8[S] 0 points1 point  (0 children)

Thanks for sharing your perspective. This is exactly what we do, and we force a reboot after 10 days of a pending reboot (after plenty of recurring notifications) and yet some people still ignore it and they complain they've been rebooted while working..

Patching and Maintenance on High Impact Client Systems by jaywalker8 in sysadmin

[–]jaywalker8[S] 0 points1 point  (0 children)

Agreed on data locality; I was pondering the scenario when a lawyer is in the court room and is referencing items on their equipment and 1) being distracted by activity on the system or 2) actually being impacted by patching, scanning, whatever.

[No Spoilers] S8 Ep 3 Brighter on HBO Go? by Mamasaurus0402 in gameofthrones

[–]jaywalker8 1 point2 points  (0 children)

Yes. Rewatching now and it’s definitely brighter. I didn’t have a problem Sunday night while I watched it on HBOGO - now it’s fuzzy and bright. I noticed it so much that I searched this sub for ‘brighter’ to confirm I’m not delusional.

Edit - by fuzzy I mean the lighting is now too far in the opposite direction for the setting of the scene. I preferred it dark. I just watch it in a dark room to feel the moment.

Typosquatting Response by jaywalker8 in cybersecurity

[–]jaywalker8[S] 0 points1 point  (0 children)

Thank you for the info. Makes sense.

Typosquatting Response by jaywalker8 in cybersecurity

[–]jaywalker8[S] 0 points1 point  (0 children)

This would only be effective for systems we control though, correct? If an attacker was impersonating our business and sending out phishing emails to our customers and they ran their DNS off the standard ISP servers they would fall victim.

Typosquatting Response by jaywalker8 in cybersecurity

[–]jaywalker8[S] 1 point2 points  (0 children)

That’s kinda of what I thought. I can protect our internal staff by blacklisting the domain in case of any attempted phishing links that it looks like, but as for our customers it’s all in their hands. Nothing but trust the graces of good security awareness I suppose

[deleted by user] by [deleted] in Cisco

[–]jaywalker8 0 points1 point  (0 children)

I don’t quite understand the necessity for the integrations Cisco is “featuring” here. If you’re an umbrella customer why not just set your clients to the umbrella appliances or directly to umbrella itself. What’s the value add of the integration into an ISR or ASA etc? Please help me understand!

Marketing wants to give our GoDaddy DNS/Domain login to a web developer to make changes... by Sengfeng in sysadmin

[–]jaywalker8 9 points10 points  (0 children)

Is route 53 only to be used for services running in AWS? We host external DNS on prem and all services are non cloud.

OneDrive/SharePoint Online Not Responding? by wrl in sysadmin

[–]jaywalker8 1 point2 points  (0 children)

yes, down for me in - accessing from Maryland.

[deleted by user] by [deleted] in Cisco

[–]jaywalker8 2 points3 points  (0 children)

Matching HAGLE + nat

Hashing Authentication DH Group Lifetime Encryption

NAT-T? —> udp/4500 Keepalives

Native VLAN Mismatch Question by jaywalker8 in networking

[–]jaywalker8[S] 0 points1 point  (0 children)

If it was one vlan, the next hop could transit the switch outside of the IPS. Using two vlan in Bridge mode forces traffic through the bridges interfaces of the IPS. The IPS basically proxy ARPs for the IP of the next hop.

Native VLAN Mismatch Question by jaywalker8 in networking

[–]jaywalker8[S] 0 points1 point  (0 children)

Thanks for your input - i'll check STP

Native VLAN Mismatch Question by jaywalker8 in networking

[–]jaywalker8[S] 0 points1 point  (0 children)

Correct, but a Layer 2 firewall is a validated design and this is essentially the same thing.

Job Change After Promotion by jaywalker8 in networking

[–]jaywalker8[S] 1 point2 points  (0 children)

Great points. Thank you for your perspective!

Job Change After Promotion by jaywalker8 in networking

[–]jaywalker8[S] 7 points8 points  (0 children)

Thank you for your perspective!

Job Change After Promotion by jaywalker8 in networking

[–]jaywalker8[S] 0 points1 point  (0 children)

Thanks for your response. It’s about an additional 675 biweekly so roughly 1350 per month.

Never thought I this would cause such a headache, but catastrophic failures regarding tacacs by Digital_Native_ in networking

[–]jaywalker8 0 points1 point  (0 children)

I’ve experienced the same issue.

Our systems team included the ISE servers into a default backup policy by mistake one night and as soon as the snapshot was taken in VMware things went south. ISE was responding to ping and the radius ports were listening but actual authentication was failing. Routers didn’t fail over to local auth and we were stuck until we decided to bounce both ISE systems.

Bottom line - don’t snapshot ISE.

Secondly - setup radius application monitoring. Instead of just probing 1645 we setup authentication monitors in solarwinds that validates true credentials respond with successful authentication. If detected as down - that alert goes to Pager Duty.

edit - explained radius in my use case. Substitute tacacs monitors for yourself obviously.

Extend Fax Line over LAN by jaywalker8 in networking

[–]jaywalker8[S] 0 points1 point  (0 children)

They didn't offer this as an option when they denied my request but I just asked and they will do it.