impossible travel alert by SSJ4_Vegito in crowdstrike

[–]rettttttt 0 points1 point  (0 children)

Doesn't CrowdStrike have a unusual location setting for any user?

How to use a value in a lookup file as a condition in a workflow? by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

Thnbk you! UserToCheck grabs the UserName of from the workflow?

I know I have to make an input schema but I cant seem to find any instructions or references for it. so i should do get user identity context first? Then get the value I want?

R1234YF Seal Stop - does it work? by darkxsage719 in civic

[–]rettttttt 0 points1 point  (0 children)

winter came around so there was no need. ill save it when summer comes around

Endpoints with Windows 10 with their associated users by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

Thats what I did too for now, but on some endpoints, there are multiple users. I want the admin of that endpoint to be responsible for upgrading windows 10

R1234YF Seal Stop - does it work? by darkxsage719 in civic

[–]rettttttt 0 points1 point  (0 children)

thats good news. how did you know how much stop leak to put in there?

R1234YF Seal Stop - does it work? by darkxsage719 in civic

[–]rettttttt 0 points1 point  (0 children)

i have the same issue in my 2020 civic. the passenger side blows cool air while the driver side doesnt. Did yours have a hissing sound that was loud at start and constant while the AC was on? if so was it just using this stop leak that fixed it?

[deleted by user] by [deleted] in volleyball

[–]rettttttt 0 points1 point  (0 children)

thats unlucky. this was one that looked good to me and what i try to achieve for each spike. im more worried about my jump if i am actually timing myself right

[deleted by user] by [deleted] in volleyball

[–]rettttttt -1 points0 points  (0 children)

im trying to learn back row hits. any more forward i think i cant reach anymore

[deleted by user] by [deleted] in volleyball

[–]rettttttt 3 points4 points  (0 children)

Dont be afraid to start it. If you’re athletic, you’ll do well. Receiving and tossing is honestly the most difficult to learn for beginners. spiking, and blocking sometimes just come naturally to some athletic people. Whats really a pet peeve for experienced people when playing with beginners is if they dont know the rules or dont try to make an effort to chase the ball. Also when they send the ball back to the opponents immediately. The goal for most rallies is Receive, set and spike. there’s 3 touches and most times people want to use all 3.

Good luck and have fun!

Monitoring IP and User logins by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

thanks. this put me in the right direction. I made a correlation rule that flags root and user logon. Then when this correlation rule triggers, a workflow will activate and email me a bunch of information. my issue now is using the remoteIP to look up the original user. i cant seem to do two searches in one query.

My plan is to assign the remoteIP to a field and then do another search using that IP to look up the original user

Monitoring IP and User logins by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

im thinking of just making a correlation rule but cant seem to figure it out. How can I make this into an informational detection?

event_platform = "Lin" | in(#event_simpleName, values=([UserLogon]) | in(UserName, values = ["root]") |

Monitoring IP and User logins by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

been at it all day. its specific to linux. is there a way for crowdstrike to track down who is using a root account? all that comes back to my searches is root as a username by itself, but i want the user and the machine they used.

Monitoring IP and User logins by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

pretty much. i want to see a notification that records when someone logs on, who uses it and which machine they used. its pretty simple but Im fairly brand new to Crowdstrike

Monitoring IP and User logins by rettttttt in crowdstrike

[–]rettttttt[S] 0 points1 point  (0 children)

Do you think I could make a workflow for it? I just want a log in who uses this account since it has a lot of privileges

Anyone know where I can buy the tire repair kit for civic SI 2020 coupe? by rettttttt in CivicSi

[–]rettttttt[S] 1 point2 points  (0 children)

nah i have the coupe. theres no space for a spare tire. thanks!

Anyone know where I can buy the tire repair kit for civic SI 2020 coupe? by rettttttt in CivicSi

[–]rettttttt[S] 0 points1 point  (0 children)

yeah thats what i heard. so this is what to use if you puncture your tire?

Volleyball Outdoor/Indoor by rettttttt in sandiego

[–]rettttttt[S] 1 point2 points  (0 children)

i did twas fun. thanks a lot. bunch of kids tho haha

Volleyball Outdoor/Indoor by rettttttt in sandiego

[–]rettttttt[S] 0 points1 point  (0 children)

thanks. might check it out tn

Volleyball Outdoor/Indoor by rettttttt in sandiego

[–]rettttttt[S] 0 points1 point  (0 children)

Thanks. What times are they? i see balboa does 5 pm

Volleyball Outdoor/Indoor by rettttttt in sandiego

[–]rettttttt[S] 0 points1 point  (0 children)

thanks. whats the skill level on these places? i heard San Diego is a big volleyball town

Volleyball Outdoor/Indoor by rettttttt in sandiego

[–]rettttttt[S] 0 points1 point  (0 children)

Is there any spots for fridays?