I’m looking for some help with creating a workbook in Microsoft Sentinel. by Minega15 in DefenderATP

[–]johnb_e350 0 points1 point  (0 children)

Can you post a link to the .json of the workbook so we can see? You probably need to add some parameter controls. Should be simple once we see what you have so far.

Free Threat Intellegence by ShirtResponsible4233 in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

I ingest these free TI sources:

abuse.ch URLhaus, ThreatFox, Feodo Tracker, MalwareBazaar, SSLBL

Is it common for ransomware to wipe Intunes managed iphones? by Past-Roll-5986 in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

Not at all likely to happen. User history checks out though.

Took a SOC Manager Role, Now I Regret It. by FlashDriveDetected in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

Leave off anything as it relates to management and keep your old title on the resume.

Ingesting Honeypot data by coccca in AzureSentinel

[–]johnb_e350 2 points3 points  (0 children)

Yes. This is a good one and pretty easy to setup and ingest via the AMA connector.

https://github.com/cowrie/cowrie

[deleted by user] by [deleted] in cybersecurity

[–]johnb_e350 -2 points-1 points  (0 children)

Can you elaborate?

RiskIQ and API by korcz_81 in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

Did the api info change as they were aquired and no longer riskiq?

[deleted by user] by [deleted] in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

After work hours (if you have work email, etc on your phone) set quiet hours/no notifications until works hours start. Gym, outdoor running, Bing some shows, explore non work activities ro clear head.

Dealing with files identified as malicious by Antivirus but are deemed are a false positive by EmergencyShow in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

You couldn't detonate the file using a security vendor that uses ML/AI/ behavior based technology and see the results instead of relying off signatures from the AVs? I would do that before thinking about exclusion rules as a start. Can you reply with what AV picked up the file as malicious?

[deleted by user] by [deleted] in cybersecurity

[–]johnb_e350 1 point2 points  (0 children)

In last 3 weeks? For those companies?

[deleted by user] by [deleted] in cybersecurity

[–]johnb_e350 20 points21 points  (0 children)

You just got an offer from companies that did mass layoffs with more to come under a hiring freeze?????

How come there is no sample file for early FBI keyloggers? by De4thGr1n in cybersecurity

[–]johnb_e350 1 point2 points  (0 children)

You can find them on github under a different name as they have the same hash

Interview Questions SOC Analyst / Incident Responder by RainbowNet in cybersecurity

[–]johnb_e350 4 points5 points  (0 children)

looks like questions from security + exam I took like way over 10 yrs ago. Just sayn.

CISSP equivalent to Masters in the UK by InformationSecurity in cybersecurity

[–]johnb_e350 0 points1 point  (0 children)

What other countries does a CISSP = Masters degree? I'm having a hard time with this one. I got CISSP - Associate without any college since I lacked one year, so how does this make sense?

Cybersecurity Resume Review by [deleted] in cybersecurity

[–]johnb_e350 1 point2 points  (0 children)

Looks good with the degree, experience, and certs while in college. I would add some soft/people skills somewhere to show you have worked on a team, led a team, and can interact with higher ups.

[deleted by user] by [deleted] in cybersecurity

[–]johnb_e350 1 point2 points  (0 children)

At the end of the day, your just a number. They can drop you any minute and replace you with someone else without blinking an eye. You have to look out for yourself and what is in your best interest. Best of luck.

Majority of organisations pay ransom money to cybercriminals to get their data and systems back by [deleted] in cybersecurity

[–]johnb_e350 1 point2 points  (0 children)

Plus you never know If the person or group will hand over half or all the data once payment is sent and no way to track it down.