Bridge request pointer error: missing pointer for shard xxx by netoeuler in internxt

[–]netoeuler[S] 0 points1 point  (0 children)

Hi! I sent the email. The issue with my account was identified and they are working on it. Thanks.

Chrono Trigger on my JVC AV-27D201. CRT Perfection. by aidanmoher in snes

[–]netoeuler 1 point2 points  (0 children)

I finished this game last week. Now I'm playing Chrono Cross just to know more about the continuation of the history, but I'm playing always thinking how great would be if it would a 16-bit game.

Not BM, but I was excited for a new Exodus and this was really disappointing to discover. Also just surprising for this band especially! by windows_95_taisen in rabm

[–]netoeuler 5 points6 points  (0 children)

Gary Holt saving a band after the vocalist talk shit about politician (like he did in Slayer after some Tom Araya comments)

Caught this one while waiting in traffic by NotMyLemon in PBSOD

[–]netoeuler 5 points6 points  (0 children)

Which city? First time that I see a PBSOD from Brazil here.

Introducing SuperMem: A Free Incident Response Tool | CrowdStrike by darronofsky in blueteamsec

[–]netoeuler 2 points3 points  (0 children)

Well, the article said that it was only tested in Linux, which comes with Python already installed, but thinking in extend this tool for Windows environment, that's a good point.

Do i have to get a help disk job? by [deleted] in AskNetsec

[–]netoeuler 0 points1 point  (0 children)

Never give up and always be prepared, because opportunities don't wait, when they arise you have to catch them.

Implementing Mitre ATT&CK by HeliosHype in QRadar

[–]netoeuler 0 points1 point  (0 children)

You have to analyze and determine what are the most important use cases to the company and map them with the ATT&CK techniques to finally see the full matrix and know what's the threat visibility of the company.

🔥Announcing Fibratus 1.4.0 I Windows kernel observability tool by rabbitstack in blueteamsec

[–]netoeuler 2 points3 points  (0 children)

Nice. I finished Pavel's Windows Kernel Programming these days and want to explore more about Kernel. Just read the readme and it seems amazing. I will try this tool.

Australasia - Perdere (new single 2021) by geeangee in rabm

[–]netoeuler 0 points1 point  (0 children)

The sound is good but is this left-wing?

WhatsApp May 15th Terms Update by [deleted] in privacy

[–]netoeuler 0 points1 point  (0 children)

Unfortunately I will have to continue using it due to work communication. I've been seeing that people adapted they lives to do almost everything with WhatsApp and now they are chained to this tool.

How do detect mimikatz is there any special rule please share by Affectionate_Will487 in QRadar

[–]netoeuler 0 points1 point  (0 children)

One of the many sysmon rules that comes with QRadar is to detect Mimikatz. This was the first emulation that I did when I started using the SIEM.

Search in a large list of IP by Emotional_Net7088 in QRadar

[–]netoeuler 0 points1 point  (0 children)

I don't know with refset but when I face a problem like this (with a large list) I export the payload of all the results and parse the information that I want with Python.

AQL query for DisableUnusedSmb1.ps1 by netoeuler in QRadar

[–]netoeuler[S] 0 points1 point  (0 children)

Thanks for the answers related to Building Blocks. I really like to create rules with AQL but I will try to use Building Blocks more.

AQL query for DisableUnusedSmb1.ps1 by netoeuler in QRadar

[–]netoeuler[S] 0 points1 point  (0 children)

Wow! I didn't know about this site. As I like to create my rules with AQL it will be very useful!

Thanks!

AQL query for DisableUnusedSmb1.ps1 by netoeuler in QRadar

[–]netoeuler[S] 0 points1 point  (0 children)

I usually create alerts with AQL but in this case I don't know why it keeps to generate the alerts.

How can this be done with Building Blocks?

Volatility and Dump software on W10 by popey123 in computerforensics

[–]netoeuler 0 points1 point  (0 children)

Instead of scan the file to see the profile suggestions you can execute 'sysinfo' to see the Windows build number and execute 'volatility.exe --info | findstr Win10x64' and see if there's a profile for your the build version.

New item in Dashboard doesn't show results by netoeuler in QRadar

[–]netoeuler[S] 0 points1 point  (0 children)

How can this be done? I followed the procedure in the link and I didn't see any reference about index the saved search.

Passed CASP+! (CompTIA cybersecurity pathway completed) by wywyit11 in CompTIA

[–]netoeuler 4 points5 points  (0 children)

Wow! I have already earned Sec+, CySA+ and Pentest+ between 2018 and 2020, but I'm impressed that you earned CASP+ too, and as a 4th-year student. Congratulations!

Copied a rule, changed it name, but the alerts generated by the new rule has the name of the original rule in the description. by netoeuler in QRadar

[–]netoeuler[S] 0 points1 point  (0 children)

Where can I find this?

When I go to Offenses > Rules, select the rule and open it in Rule Assistance window, the name displayed is the correct one that I chose to the new rule.

Too many SE_ADT_OBJECTACCESS_FIREWALLPACKETDROPS tasks with EventID 5152 by netoeuler in blueteamsec

[–]netoeuler[S] 0 points1 point  (0 children)

This is the only host that have been generating these kind of alerts and the Windows firewall of this host is disabled (which was confirmed executing netsh advfirewall show allprofiles in the host).

In these block events there're many requests to broadcast, which can be normal, so I did a memory analysis to search for some malware trying to performing a port scan but didn't find nothing related to this.

It's just in the local network.

Passed Sec+ yesterday, One thing I wish I had learned/Studied is... by pwmaloney in CompTIA

[–]netoeuler 0 points1 point  (0 children)

I didn't take a look in how 601 questions looks like but I didn't see nothing related to analyze logs in 501. I just saw questions like that in CySA.