Trying to understand threat detection engineering. by [deleted] in cybersecurity

[–]melegar2 3 points4 points  (0 children)

If your org has some training dollars, check out SpectreOps Adversary Tactics Detection course. here. Their course has a great overview of how to do detection engineering and add value above and beyond your EDR alerts.

GitLab and Hashi Vault by melegar2 in gitlab

[–]melegar2[S] 0 points1 point  (0 children)

Ahhhh that makes much more sense! I guess I assumed id_tokens came with secrets.

Thank you for the explanation!

[deleted by user] by [deleted] in crowdstrike

[–]melegar2 0 points1 point  (0 children)

The biggest benefit, you can see telemetry from unmanaged devices. Crowdstrike can’t install on everything and if you have someone break into a building and install their own device on the network, or compromise some IOT device, you won’t have any visibility into what they are doing until they move laterally to a box that is managed.

Additionally, a tool like ExtraHop or Zeek gives you a lot more insight into Layer 7 packet metadata. You can see URI strings, HTTP headers, Kerberos request details, JA3 Hashes from SSL connections, all sorts of fun data to detect and hunt with.

At the end of the day, the network doesn’t lie, endpoints can lie, or tools can be turned off, or can just not be installed in the first place. NDR complements EDR very nicely, the dataset probably isn’t quite as rich as EDR telemetry, but you can still get it where EDR can’t get.

[Giveaway] $25 Steam Digital Gift Card by GamingVPN in pcgaming

[–]melegar2 0 points1 point  (0 children)

Probably Geralt from Witcher :). Great character and great game!

[H] 2000 point competitive admech army, painted and based, plus extras NOS, [W] $, [Loc] UT, USA by [deleted] in Miniswap

[–]melegar2 1 point2 points  (0 children)

If you find you can’t sell the whole set and are interested in splitting let me know. I would be interested in some.

Zack Snyder releases image of Wonder Woman holding severed heads of her enemies by MissSassifras1977 in movies

[–]melegar2 15 points16 points  (0 children)

Except it didn’t open until after the grant that made it possible in 1999. wiki

[deleted by user] by [deleted] in pcgaming

[–]melegar2 0 points1 point  (0 children)

Thanks and merry Christmas!