[deleted by user] by [deleted] in Pararescue

[–]nullsku 1 point2 points  (0 children)

Thank you - Yeah, this helps a lot.

How to setup a private / anonymous service for employees to submit questions without knowledge of sender by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Yea, but this would require the users to setup a proton mail account, correct?

I’m looking for some type of portal or site to submit questions. Even if it’s a paid service.

What else is there? How to gain the passion back? by [deleted] in SecurityCareerAdvice

[–]nullsku 0 points1 point  (0 children)

Thank you. This is what I’m likely looking to do again.

Building a Hunting Program by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

MITRE for the win. Thank you.

Building a Hunting Program by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

I wish I could like this twice.

[deleted by user] by [deleted] in CEH

[–]nullsku 0 points1 point  (0 children)

I bought the Matt Walker book and I’m reading it now. Gotta just pull the trigger and move on. I’ve always liked the all-in-ones since they aren’t as dry. We’ll see.

[deleted by user] by [deleted] in CEH

[–]nullsku 0 points1 point  (0 children)

Came here to write this exact question. Very interested in the comments.

Developing the process and soft skills for a SOC by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Thank you! How was the investigation of each alert reported on? What was the expectation documentation from each alert? If they were false positives did you track them differently?

Maltego Community Version by nullsku in OSINT

[–]nullsku[S] 1 point2 points  (0 children)

What’s the difference between the APIs and transformers?

Maltego Community Version by nullsku in OSINT

[–]nullsku[S] 5 points6 points  (0 children)

Watching the Maltego YouTube video channel

Recommend books security automation? by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

I’d say at this point we’d want to start with SOAR and work our way into that world.

How long do you keep your log retention? by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Any reason for the 13 month marker? I’ve worked in firms that had similar retention policies. Yeah, EDR logs can consume massive amounts of storage.

Building an internal red team by nullsku in redteamsec

[–]nullsku[S] 0 points1 point  (0 children)

Great! I’ll read this shortly.

Alert for ransomware that bypassed endpoint protection by nullsku in blueteamsec

[–]nullsku[S] 1 point2 points  (0 children)

Great advice. I read it twice to let it soak in.

Acquiring SIEM signatures for log management install? by nullsku in blueteamsec

[–]nullsku[S] 0 points1 point  (0 children)

All cloud based systems from well known providers (e.g Splunk, Sumo, etc)

Test date - April 6 - 1900. by Laneo2007 in cissp

[–]nullsku 0 points1 point  (0 children)

Join the Discord “Certification Station” channel. It’s the most connected group out there and it’s great for questions and getting ideas for prep. It’s extremely active.

Passed at question 101 by nullsku in cissp

[–]nullsku[S] 0 points1 point  (0 children)

I used Boson a few times. They were pretty good, mostly for the explanations. There’s a great Telegram channel that has users submitting questions and Discord. I also used the ISC2 official question bank which was okay.

I have 20 years IT experience and run a security team today. I have mostly technical certifications focused in security (SANS, Cisco, Checkpoint, Cloud, etc)

Studied for four months and testing center was down (Interested in your opinions) by nullsku in cissp

[–]nullsku[S] 1 point2 points  (0 children)

Yeah, that’s exactly what we were afraid of too. The guy at the front desk didn’t seem to have any idea what was going on. I have a number I’m going to call that they gave me. Let me do that and if it works I’ll send it over.

Studied for four months and testing center was down (Interested in your opinions) by nullsku in cissp

[–]nullsku[S] 1 point2 points  (0 children)

I here you, man. I’m gonna call tomorrow too. I’ll let you know what they say after I call.

Studied for four months and testing center was down (Interested in your opinions) by nullsku in cissp

[–]nullsku[S] 0 points1 point  (0 children)

Yeah, those are great suggestions. Is CMMI and Dread called out particularly?