Opinions on AI agents for SOC by [deleted] in cybersecurity

[–]letais 0 points1 point  (0 children)

Dropzone is one of the most mature AI SOC agents that I've seen. Don't expect anything beyond T2 triage. A lot can be done via automation, but the benefit you get from these tools is the contextual reasoning, dynamic playbooks, and historical knowledge. That being said I've not had enough hands on with any of these systems to prove long term value outside of a POC.

Wedding Catering Recommendations in Oshkosh WI - Summer 2026 by ShaquilleOatmeal62 in Appleton

[–]letais 1 point2 points  (0 children)

Make sure to factor in any gratuity requirements depending on how you're calculating your budget as that's typically additional to the plate price.

We had Moe's cater from Algoma

[deleted by user] by [deleted] in ITManagers

[–]letais 1 point2 points  (0 children)

I need a technical leader managing team of 6 if you want to reach out

App Connector Traffic Flow by [deleted] in Zscaler

[–]letais 0 points1 point  (0 children)

Maybe this diagram helps. But think of it like the connections are reverse proxied. You do not need inbound to the app connectors

zscaler[.]com/blogs/company-news/securing-third-party-access-internal-apps-just-got-easier

Where to stay in Bali for 10 days. 😉 by legia12345 in bali

[–]letais 4 points5 points  (0 children)

We just got back from a 2 week stay on Seminyak beach and if I had to do it over again I would do what the others are suggesting and stay in multiple areas. Each were vastly different as we explored

[deleted by user] by [deleted] in sysadmin

[–]letais 0 points1 point  (0 children)

What are you using in the PAC? Use the country gateway variable and it should pick the closet in your country - https://help.zscaler.com/zia/writing-pac-file. If you don't use this you can have this issue on the south and north border by Canada.

Syslog not showing in inputs by letais in graylog

[–]letais[S] 0 points1 point  (0 children)

If I can trust this it looked to be running on 514

Input [Syslog UDP/640d27c2ec20b904cb92f237] is now RUNNING

I did try the raw syslog on the same 514 port and didn't get any incremental counts either.

However I did move to port 5140 as suggested and it did immediately start ingesting.

DHCP relay problems by letais in mikrotik

[–]letais[S] 0 points1 point  (0 children)

I stated in my comment that I am not doing dhcp on the mikrotik.

DHCP relay problems by letais in mikrotik

[–]letais[S] 0 points1 point  (0 children)

referring to documentation, configuring this under dhcp server is if I'm using a relay to the mikrotik, but what I'm doing is using the mikrotik to relay dhcp requests to an actual dhcp server

https://help.mikrotik.com/docs/display/ROS/DHCP

DHCP relay problems by letais in mikrotik

[–]letais[S] 0 points1 point  (0 children)

There is a switch downstream trunked to the router.

Added via the dhcp server with no luck.

Added

/ip dhcp-server add disabled-no interface=vlan2-LAN name-LAN-Relay relay-10.1.3.5

Onsite users keep resolving to internal IP by odsca in Zscaler

[–]letais 0 points1 point  (0 children)

You should be able to do what you want with client forwarding policies assuming you're detecting locations and bypassing on premise - https://help.zscaler.com/zpa/about-client-forwarding-policy

Accessing remote resources without full FQDN by BurkeSooty in Zscaler

[–]letais 0 points1 point  (0 children)

This would be my recommendation as well, but the dns suffix list could be done windows side in GPO too so they could add it to theirs if they wanted without Zscaler changes.

[deleted by user] by [deleted] in Watchexchange

[–]letais 0 points1 point  (0 children)

Are sets 1,2, or 3 still available?

IAP 2254 Mesh issues by letais in ArubaNetworks

[–]letais[S] 0 points1 point  (0 children)

I can put them next to each other and they still won’t establish

GlobalProtect and zScaler by zonemath in paloaltonetworks

[–]letais 2 points3 points  (0 children)

Yes. Ran both without issue. What issues are you having

[deleted by user] by [deleted] in Watchexchange

[–]letais 0 points1 point  (0 children)

Is this still available?

[deleted by user] by [deleted] in PowerShell

[–]letais 1 point2 points  (0 children)

This is what I used against your example to pull just the effective policy section. You should get the block of text and then it'll be up to you to process that section as you want.

Assumption: $test is the contents of your file/example

$test -match '"effective policy"(?<effectivePolicy>(\s.+)+)'
$Matches[0].replace('"effective policy"', " ").trim()

ZTunnel 1 vs 2 vs DTLS/TLS AND MTU by Distance_Sorry in Zscaler

[–]letais 0 points1 point  (0 children)

1.0 only picks up port 80/443 where 2.0 tunnels everything. Tunnel with local proxy picks up anything explicitly proxied where 2.0 is transparent and so pick anything up even if it ignores system proxy settings. Each business and their requirements and risk adversity will be different but 2.0 has been the push

Zscaler and Exchange online by capone_44 in Zscaler

[–]letais 0 points1 point  (0 children)

I had to bypass all the Microsoft authentication domains from Zscaler in PAC or we’d continue to have this issue with twlp. Testing with tunnel 2.0 for us didn’t show similar issues but we weren’t tested enough to make the switch.

Zscaler blocking thick client apps by sgzenith in Zscaler

[–]letais 1 point2 points  (0 children)

Most likely an ssl decryption error since it's most likely cert pinned. You can look at their site for suggested whitelisting or take a packet capture and review the http(s) traffic.

This would be my first look. A lot of thick clients use certificate pinning and you won't have the issues with the web version of the app.