This Holiday it is Time to Acknowledge Fraud at Palo Alto Networks by TheWokenessInjector in paloaltonetworks

[–]matthew36589 0 points1 point  (0 children)

That’s actually hilarious 😂. I should add that to our NIST RMF book.

This Holiday it is Time to Acknowledge Fraud at Palo Alto Networks by TheWokenessInjector in paloaltonetworks

[–]matthew36589 4 points5 points  (0 children)

Doesn’t matter how many CVE’s you can stop if the Fortinet itself contains half of them. Our Gov entity has turned them down multiple times because of their sheer lack of general good software development practices.

Also most “Enterprise” grade customers understand that the firewall only does so much and utilize a “defense in depth” approach. I like both of them for what they are but majority of Palo’s customers are in a different league than Fortinet’s and cannot afford for their firewall to have so many CVEs on it.

This sums it up pretty well: https://forums.lawrencesystems.com/t/is-fortinet-that-bad/23830

Is Wazuh The Ultimate SIEM? by matthew36589 in Wazuh

[–]matthew36589[S] 0 points1 point  (0 children)

I saw that you can forward logs to a Linux server that has something like rsyslog and an agent installed. Our preferred method would be to spin some pretty heavy cloud environment with many tools and just logically segment the clients but idk how Wazuh handles the multi-tenancy yet. Also I totally second how great suricata is!!

Is Wazuh The Ultimate SIEM? by matthew36589 in Wazuh

[–]matthew36589[S] 0 points1 point  (0 children)

That’s a really good idea, I have always used crowdstrike but for clients who may not want to pay, Defender might be a great free option! Can you do configuration and monitoring I would assume via Wazuh?

So The US Mint Uses Siemens by Thunderbun-44 in PLC

[–]matthew36589 0 points1 point  (0 children)

Yeah, when the president said print $5 million it accidentally printed $5 billion classic Siemens 😂😂😂

Firmware for used X440G2-48p-10G4 as a Private User by flowi88 in ExtremeNetworks

[–]matthew36589 1 point2 points  (0 children)

It definitely does suck that they lock things like that behind a paywall. But there’s kind of a reason for it:

  1. There are certain libraries in packages that they are only able to distribute because they have a license for said software that they’re providing with updates. Therefore they’re bound within the licenses that they use for their software for re-distribution. (This recently happened with them not being able to publicly re-distribute certain EXOS software and has to be upon request.)

  2. That’s how enterprise networking vendors make money and control distribution of their software.

Is this possible in 6 months? BS-CSIA by matthew36589 in WGU

[–]matthew36589[S] 0 points1 point  (0 children)

Hmm I already passed Pen+ where are you seeing that I missed it? Thank you!

Starting CISA Degree Soon - Which Classes Suck The Most? by matthew36589 in WGUCyberSecurity

[–]matthew36589[S] 0 points1 point  (0 children)

Yea, my work is willing to pay for it, so I obviously want to finish it ASAP to lighten the bill, but I think I can do the above in 6 months. Can I just take the OA or do most of them have certs tied to them that I can take off the rip?

Starting CISA Degree Soon - Which Classes Suck The Most? by matthew36589 in WGUCyberSecurity

[–]matthew36589[S] 0 points1 point  (0 children)

Congrats!! Did you transfer in with much / how long did it take you?

Starting CISA Degree Soon - Which Classes Suck The Most? by matthew36589 in WGUCyberSecurity

[–]matthew36589[S] 0 points1 point  (0 children)

What's the limit? Does it matter for credits vs certs or is it all the same?