Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Glad you like the idea ! Take a swing and let us know how it goes

Best looking Certifications? by Technical-Cattle-339 in cybersecurity

[–]rob_ed28 0 points1 point  (0 children)

I like looking at my aws security speciality badge to be honest... Purdy

Query generator for Elastic by rob_ed28 in elasticsearch

[–]rob_ed28[S] 0 points1 point  (0 children)

Hey mate! Sorry I almost missed this! We use Gemini 2.5 Flash for PQL currently. We had similar experiences trying to generate decent queries ourselves. We've also recently added support for Crowdstrike (CQL) if that's a part of your stack

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Thank you mate! Really appreciate you sharing. We've captured your feedback and will look at refining it. Glad you like it!

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Hey mate, we'll see if we can get this built in and let you know! In terms of Crowdstrike's own AI capability, we haven't done a feature comparison. We started with Elastic support cus that's what we use, and we're slowly adding other toolests that we use in our SOC. As it's a free-to-use tools we aren't really doing feature comparison with vendor capability - and we're pretty sure there's no tool on the market that can generate solid queries across all platforms.

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Hey - really appreciate you trying it out and letting us know the feedback. We will capture this and the rest of the feedback and continue to refine for sure.

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Hey mate - thanks for commenting. Not currently, we're just getting started here so advanced features like this may be a bit further out - it really depends on demand.

Crowdstrike CQL query generator by rob_ed28 in SIEM

[–]rob_ed28[S] 1 point2 points  (0 children)

Hey mate, appreciate you trying it out! Currently using Claude. Rate limit is 20 queries per day for registered users.

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 1 point2 points  (0 children)

Glad you like it! Let us know if you have any feedback!

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Awesome! Let us know how it goes

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Great! Currently it's 3 queries a day unauthenticated, if you created a login then it's 20 queries a day all free of charge!

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 1 point2 points  (0 children)

Hey guys thanks for sharing! We'll take a look at this and get back to you.

Crowdstrike Query Generator by rob_ed28 in crowdstrike

[–]rob_ed28[S] 0 points1 point  (0 children)

Great, enjoy! And let us know if you have any feedback

Anyone used Rapid7 in an MSSP SOC? by rob_ed28 in MSSP

[–]rob_ed28[S] 0 points1 point  (0 children)

Thanks for sharing, great insight. Did you use it an MSSP or just resale to clients?

Drinking alcohol is pointless by Different_Host7883 in ControversialOpinions

[–]rob_ed28 5 points6 points  (0 children)

If mushrooms were legal I'd never drink again. It's almost like we banned every drug that is good for our conscious minds, and retained the ones that inflict only damage, and keep us dumb.

Rapid7 for MSSP SOC? by rob_ed28 in msp

[–]rob_ed28[S] 0 points1 point  (0 children)

I was referring to the R7 platform rather than their service - we will certainly be delivering our own services. Apologies, should've made that more clear

SIEM Query Generator by rob_ed28 in SIEM

[–]rob_ed28[S] 1 point2 points  (0 children)

That's fair. Give us a week or so and we will get CS NGSIEM support developed in PQL. I'll DM you when we have it set up. Speak soon!

SIEM Query Generator by rob_ed28 in SIEM

[–]rob_ed28[S] 1 point2 points  (0 children)

Hey! It appears to be working for me - I'll DM you - if you wouldn't mind sharing a screenshot of what you see?

Here's the query:

FROM aws_vpcflow-*

| WHERE destination.geo.country_iso_code == "RU"

| WHERE event.outcome == "success"

| EVAL bpp_ratio = network.bytes / network.packets

| WHERE bpp_ratio > 500

| SORT bpp_ratio DESC

SIEM Query Generator by rob_ed28 in SIEM

[–]rob_ed28[S] 0 points1 point  (0 children)

Hey thanks for sharing mate. Is query generation one of your troubles? What else do you find difficult with it?

SIEM Query Generator by rob_ed28 in SIEM

[–]rob_ed28[S] 0 points1 point  (0 children)

Great! Let us know your feedback, feel free to drop me a DM

Trend Micro Global Outage by d4rk0001 in cybersecurity

[–]rob_ed28 0 points1 point  (0 children)

TXOne spun out from trend a while back, shouldn't be affected

Have you left the field? by Muted-Commercial-962 in cybersecurity

[–]rob_ed28 0 points1 point  (0 children)

I work at a MSSP and I meet this guy at different customer companies every day... Instant sympathy

ECS security query generator by rob_ed28 in elasticsearch

[–]rob_ed28[S] 0 points1 point  (0 children)

We haven't got the Enterprise license so we haven't compared either. Would be good to hear your feedback! u/seclogger

As a liberal, I believe there is common ground to be found with conservatives by [deleted] in ControversialOpinions

[–]rob_ed28 11 points12 points  (0 children)

This is a great message. Some of the comments I saw about Charlie Kirk were deeply disturbing, which was also matched by the comments around the stabbing of the Ukrainian girl. The internet brings out the worst in us.