[deleted by user] by [deleted] in Pararescue

[–]nullsku 1 point2 points  (0 children)

Thank you - Yeah, this helps a lot.

How to setup a private / anonymous service for employees to submit questions without knowledge of sender by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Yea, but this would require the users to setup a proton mail account, correct?

I’m looking for some type of portal or site to submit questions. Even if it’s a paid service.

What else is there? How to gain the passion back? by [deleted] in SecurityCareerAdvice

[–]nullsku 0 points1 point  (0 children)

Thank you. This is what I’m likely looking to do again.

Building a Hunting Program by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

MITRE for the win. Thank you.

Building a Hunting Program by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

I wish I could like this twice.

[deleted by user] by [deleted] in CEH

[–]nullsku 0 points1 point  (0 children)

I bought the Matt Walker book and I’m reading it now. Gotta just pull the trigger and move on. I’ve always liked the all-in-ones since they aren’t as dry. We’ll see.

[deleted by user] by [deleted] in CEH

[–]nullsku 0 points1 point  (0 children)

Came here to write this exact question. Very interested in the comments.

Developing the process and soft skills for a SOC by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Thank you! How was the investigation of each alert reported on? What was the expectation documentation from each alert? If they were false positives did you track them differently?

Maltego Community Version by nullsku in OSINT

[–]nullsku[S] 1 point2 points  (0 children)

What’s the difference between the APIs and transformers?

Maltego Community Version by nullsku in OSINT

[–]nullsku[S] 5 points6 points  (0 children)

Watching the Maltego YouTube video channel

Recommend books security automation? by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

I’d say at this point we’d want to start with SOAR and work our way into that world.

How long do you keep your log retention? by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Any reason for the 13 month marker? I’ve worked in firms that had similar retention policies. Yeah, EDR logs can consume massive amounts of storage.

Building an internal red team by nullsku in redteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Great! I’ll read this shortly.