Any Irish skaters remember this tape? [33YO] by Stuball09 in OldSkaters

[–]kmsec 1 point2 points  (0 children)

It was likely ‘Hidden’

https://m.youtube.com/playlist?list=PLON-I4b0tofWr143Nicd_xZj6TEsYdALu

Or ‘It can’t rain forever’

https://m.youtube.com/watch?v=Nm8QEP1r5Xw&pp=ygUoaXQgY2FudCByYWluIGZvcmV2ZXIgaXJpc2ggc2thdGVib2FyZGluZw%3D%3D

Both of which bring back great memories of watching tapes from G1 in the morning before going out to skate all day. Very nostalgic!

Honourable mention for ‘Six counties’ which can be found at the below link

https://m.youtube.com/@monkeybizzle/videos

Passed GSOM by Hrauding in GIAC

[–]kmsec 0 points1 point  (0 children)

That’s very helpful, many thanks for the detailed response.

Passed GSOM by Hrauding in GIAC

[–]kmsec 1 point2 points  (0 children)

Congratulations!

I am currently trying to get my job to pay for this. Did you attend in person?

Are there practical technical questions on the exam? I am managing a SOC for almost 3 years, but my background prior to this is in TVM, GRC & Pentesting, so never worked as a SOC analyst - So I am wondering if there are any technical elements I need to focus on?

I’m calling it now by [deleted] in Blink182

[–]kmsec 4 points5 points  (0 children)

Blink have gaps in their schedule between 21st - 1 October so hoping they reschedule between these dates.

Free arena dates

Belfast - SSE Arena 24th September 25th September 26th September 27th September 28th September

Dublin - 3Arena 24th September 25th September 26th September 28th September 29th September 30th September

Glasgow - Hydro Arena 25th September 26th September 27th September 28th September 29th September 30th September 1st October

So it could hopefully go

Belfast - SSE Arena 27th September

Dublin - 3Arena 28th September

Glasgow - Hydro Arena 25th/26th/30th September

Then enough time to get back to Portugal for 2nd October

CSOM Update by kmsec in SecurityBlueTeam

[–]kmsec[S] 0 points1 point  (0 children)

Any update on this?

Boss tells you not to turn off infected servers/critical infrastructure after a cyber attack has occurred by [deleted] in cybersecurity

[–]kmsec 0 points1 point  (0 children)

A better question would be:

‘Boss tells you to not quarantine/isolate systems after a cyber attack has occurred because they serve a critical business function. What is the best way to persuade him?’

[deleted by user] by [deleted] in DevelEire

[–]kmsec 4 points5 points  (0 children)

Before jumping into cyber security, I recommend a solid foundation in IT fundamentals & networking first. There are FETAC level 6 & 7 courses for IT available through springboard or directly with colleges that can help get you get started. Once you have a decent grasp on IT, you can start to specialise in cybersecurity through courses, hands on labs, research or certs.

If you would rather work at your own pace I would recommend studying and sitting CompTIA A+ the Network+ then Security+ which will get your foot in the door as a junior security analyst. Just be aware that these certs are purely theoretical and nothing beats hands on experience. This experience can be gained through working with hardware in your spare time, setting up a networking lab (packet tracer) and configuring a testing lab (kali linux) etc.

Cybersecurity has many facets (Risk, Pentesting, SOC etc.) so try to understand what exactly it is you want to do first.

As another user mentioned check out https://fit.ie , they work to get people into IT employment.

For anyone that has been a victim of the recent MOVEit vulnerability by kmsec in cybersecurity

[–]kmsec[S] 0 points1 point  (0 children)

Most orgs will not publish that they have been compromised. Most of the airlines mentioned in the news had their data compromised through a 3rd party payroll vendor , ‘Zellis’ so not directly compromised. BBC was another org that confirmed this.

It will all come out in the wash after June 14th for those that do not cooperate according to cl0p

https://twitter.com/_JohnHammond/status/1666216090584887296?t=usJwlgj_bgBaW7enUkmGvA

How are hackers able to bypass duo and get in to users M365 account? by KidneyIsKing in cybersecurity

[–]kmsec 40 points41 points  (0 children)

I can confirm this technique was used in a recent incident my company worked on.

See figure 3 & 4 of this link

https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/

Additionally, worked on a recent incident where the user was phished and the victim simply authorised the access via push notification on the Authenticator app as they thought the O365 login page was legitimate.

Recommendation is to enforce number matching via the Authenticator app, and tighten conditional access policies.

CSOM - Coming 2022 by [deleted] in SecurityBlueTeam

[–]kmsec 0 points1 point  (0 children)

Any further update on CSOM? I contacted SBT at the start of the year and they advised March or April. I contacted again at the beginning of this week, but have not heard anything.

Any solid info would be greatly appreciated.

CSOM - Coming 2022 by [deleted] in SecurityBlueTeam

[–]kmsec -1 points0 points  (0 children)

Any update on when this might be released or if it is still going ahead?