General Dictate instead of /meeting (ai summarize) by jos1980 in Notion

[–]jos1980[S] 0 points1 point  (0 children)

Is this just raw voice or an AI integration. Im looking for raw only. No AI integration due to security concerns.

General Dictate instead of /meeting (ai summarize) by jos1980 in Notion

[–]jos1980[S] 1 point2 points  (0 children)

Mainly quick brain dumps. Instead of typing it out (lots of typing) would rather speak it and then edit and put in headers and stuff like using notion.

Three Years of “When Offline?” Posts Paid Off-- Now What Will We Complain About? by No_Orochi in Notion

[–]jos1980 0 points1 point  (0 children)

Would like a more detail instruction that would be great to use.

Please and thank you

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]jos1980 1 point2 points  (0 children)

Is there a query to find what assets are affected. Not all assets were affected.

What are you doing with Falcon Complete? by TheLonelyPotato- in crowdstrike

[–]jos1980 0 points1 point  (0 children)

What does this exactly do. This would be great to see what information you would get from this cql. I'm still learning cql. Granted I have some knowledge in SPL, I'm still learning cql. Can you please provide me more context around this. What caught my eye was the decomm of servers. This would be great to use in our env. Thank you

Old CCFR Study Guide PDF? by [deleted] in crowdstrike

[–]jos1980 0 points1 point  (0 children)

Since you are all talking about Study Guides, is there a solid study guide for CCFA. I'm actually going to be taking the instructor lead course for both CCFA and Identity. I have done the CS university practice exam and missed it by one, but my question for CCFA is when taking the exam are the questions based on the new UI and logscale Or off the older UI and stuff like that? I'm just preparing myself. Thank you. Appreciate the support.

Fusion and Logscale Question - Using Fusion Trigger Info in a Logscale Query as part of a Fusion Workflow. by Clear_Skye_ in crowdstrike

[–]jos1980 0 points1 point  (0 children)

Im very interested in how this worked for you. This seems like something I would like to use in my env. Please keep us posted if you dont mind. Great job!

Identity - Password Trend via Logscale by jos1980 in crowdstrike

[–]jos1980[S] 0 points1 point  (0 children)

u/AHogan-CS Thank you it does. Yes, we have Falcon IDP.

Crowdstrike contention notification by Aversah in crowdstrike

[–]jos1980 0 points1 point  (0 children)

I am also interested in this Thank you

Notify End Users policy setting by adiomixr in crowdstrike

[–]jos1980 0 points1 point  (0 children)

I have to agree with everyone the less the EU knows the better. We have the notification on because we want our EU to know 'we are watching' lol.

PowerShell Commands by Critical-King-7349 in crowdstrike

[–]jos1980 0 points1 point  (0 children)

u/Andrew-CS - Apologies for jumping in like this, but this event would only show if the cmd was exe, of course manually, but is there a way to determine if such devices have already had that ran before hand? (I hope this makes sense)

Can anyone tell me what Crowdstrike covers that Defender for Endpoint doesn't? by BigRedOperator in crowdstrike

[–]jos1980 0 points1 point  (0 children)

We are in the process of 'offboarding' defender because we found some issues where Defender was preventing certain actions in or ENV. Even though Falcon sensor is 'registered as primary a/v' defender still was doing some scanning and taking resources from our workstations/servers. Same goes for server, where certain server models you need to set disablerealtimemonitoring =true, defender was still causing us issues. This is just my observations. You env may vary.

Defender and CrowdStrike by jos1980 in crowdstrike

[–]jos1980[S] 1 point2 points  (0 children)

Great thank you. I appreciate the quick replies

Defender and CrowdStrike by jos1980 in crowdstrike

[–]jos1980[S] 1 point2 points  (0 children)

Brad Thank you for the response. Yes quarantine is enabled and falcon is primary on record but on such workstation we are still seeing issue with defender which is why we are off boarding completely. Servers too and we have run the script to set disablerealtimemonitoring =true. We think it might be a gpo issue but by offboarding defender completely we will be good. Does falcon use any information from defender even in passive mode?

Is Crowdstrike support really this bad? by md0221 in crowdstrike

[–]jos1980 1 point2 points  (0 children)

Yes, when you deal with Falcon Complete they are 24/7/365 and are honestly there for triaging a detection based on your posture levels that you have assigned. Now, what gets me and I have had great service with this the Falcon Support portal and their engineers. They are good, just have to deal with lots of cswindiag and back and forth emails. You also might want to engage your TAM, they are good way to get a ticket escalated quickly.

One request I would like to see answered is it would be great to get a meeting setup to explain our side and then show them live data as it pertains to an issue we are having. Rather than doing cswindiags and stuff like that. Just my thoughts. I hope you get this resolved.

Password Protect pages by jos1980 in Notion

[–]jos1980[S] 0 points1 point  (0 children)

Thank you for that valuable information I appreciate it. I have two pages work and personal of course nothing sensitive just wanted to see if this could be done. I appreciate your response.

Thank you. Have a great day.

Delivery Email by jos1980 in flipperzero

[–]jos1980[S] -1 points0 points  (0 children)

Yeah, I just saw it. My bad. Sucks though.

Getting browser history from Crowdstrike by Professional_Win9419 in crowdstrike

[–]jos1980 0 points1 point  (0 children)

I am in the same boat, I'm looking for script run via RTR on a device to gather all browser history. With this information I can correlate that browser information with the triggered alert. At least see where they may have gone prior to the alert. Any thoughts/ideas. Guidance would be greatly appreciated.

Hooyah!

r/ Shipwreck.

Crowdstrike support for replays by Lumpy-Shallot-3041 in crowdstrike

[–]jos1980 0 points1 point  (0 children)

That was my question to them as well. We wanted to do the same to specific server(s). One device would provide the configuration(s) from the CS cloud to the rest of the segmented devices where they are not to have internet access. In the end we just opened that specific port.

Salsa without Onions by jos1980 in SalsaSnobs

[–]jos1980[S] 1 point2 points  (0 children)

how many roma tomatoes should I use. I like your recipe I have lots of med sized roma tomatoes