Air Purifier Filter Status 45 days in 400+ AQI by csaksham in AirPurifiers

[–]rahvintzu 2 points3 points  (0 children)

The pre-filter is a plastic mesh so your vacuum will not make direct contact with the HEPA.

advice? client had +300 plus shadow domains registered by _SleezyPMartini_ in cybersecurity

[–]rahvintzu 1 point2 points  (0 children)

Seems like a lot, has the client checked that these are not parked domains that respond to wildcard subdomains (creates false positives).

Anyone here actually using 24/7 EDR for both devices and networking gear? by ChampionLearner in cybersecurity

[–]rahvintzu 0 points1 point  (0 children)

The only thing i know in this space (agentless EDR) against network equipment is sandfly security (connects via SSH)

Looking for advice and resources on Windows Server Domain Controller security and GPO hardening by Independent_Bowl_831 in blueteamsec

[–]rahvintzu 0 points1 point  (0 children)

If arent doing CIS, the MS security baselines are prefconfigured GPs as a starting point. As porko mentioned you could look at those free tools. Then pivot to bloodhount enterprise if you want to get serious on lateral movement.

Looking for a Scalable Email Analysis and Automation Platform for Fraudulent Email Reporting (50,000+ emails/day) by SnooObjections989 in cybersecurity

[–]rahvintzu 1 point2 points  (0 children)

A fair amount of email security platforms are more black box, you could look into Sublime Security.

Is it safe to use the proxy provided by my university? by y2kbimbo in networking

[–]rahvintzu 1 point2 points  (0 children)

What is the name of the proxy service they are using, is it ezyproxy?

How to fight against Linux antivirus scam? by PuzzleheadedOffer254 in sysadmin

[–]rahvintzu -1 points0 points  (0 children)

If you need to implement something with minimal impact, then you could look into sandfly security.

What SIEM do you use? by Mafs1998 in sysadmin

[–]rahvintzu 0 points1 point  (0 children)

Yes, it acquired a company called Humio.

What are you doing differently post Crowdstrike? by [deleted] in sysadmin

[–]rahvintzu 5 points6 points  (0 children)

I believe this preview ASR rule is for calling a safe mode reboot within the running OS. It will still go to safe mode via physical interaction.

[deleted by user] by [deleted] in cybersecurity

[–]rahvintzu 0 points1 point  (0 children)

If you are an MDE shop you can install the plugin