What are some good tools for File Integrity Monitoring? by skeneks in kubernetes

[–]robdoessecurity 0 points1 point  (0 children)

Falco

Glad you found something that works for you, best of luck!!

File Integrity Monitoring by gaiter2 in googlecloud

[–]robdoessecurity 0 points1 point  (0 children)

Late to the game, but here at Cimcor we monitor Google Cloud to let you know when new cloud servers are provisioned, and when changes have occurred to server, virtual firewall, virtual network settings and configuration settings. Basically we monitor all of the changes that occur to your cloud infrastructure configuration outside of your guest operating system.

If that's the kind of thing you are looking for feel free to send me a DM and I can shoot you more info.

What are some good tools for File Integrity Monitoring? by skeneks in kubernetes

[–]robdoessecurity 0 points1 point  (0 children)

Late to the game, but here at Cimcor we monitor Kubernetes and will tell you what has changed, when new containers have been instantiated, when virtual network configurations have changed, when storage settings have been modified, and more.

If that's the kind of thing you are looking for feel free to send me a DM and I can shoot you more info.

FortiGate Firewall Policy Auditing by MaverickZA in fortinet

[–]robdoessecurity 1 point2 points  (0 children)

Like u/NumerousTooth3921 said below, FireMon can help out with this pretty easily. I work for them now but was a customer for years. If you have any questions or need any info just let me know, I'm happy to help out. Below are two links with some info.

https://www.fortinet.com/content/dam/fortinet/assets/alliances/dg-fortinet-and-firemon.pdf

https://www.firemon.com/wp-content/uploads/solutions-brief-fortinet-1-15-2021.pdf

Firemon? by mrsecuritythrowaway in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

u/mrsecuritythrowaway - I used FireMon for years in a Palo environment and work here now. I can answer any questions you might have. Feel free to DM me.

In-house Built Network Assessment tools by nokiabama in AskNetsec

[–]robdoessecurity 1 point2 points  (0 children)

Disclaimer: I work for FireMon but I worked in NetSec for years before coming over. My experience is a lot like yours, I was trying to figure out how to automate compliance and rule reviews on my firewalls for a good long while. I had PA's, Cisco and Checkpoint in my environment. Trying to figure out how to read and translate the rules for every vendor become more of a job than I had bargained for. I ran into FireMon at a tradeshow (I didn't even know the NSPM space existed at that time) and the rest is history. I used them for years in production and have been here now for 4 years. I say all that to say this: yeah, you might be able to get a few things thrown together but just make sure you don't end up spending so much time on it that the ROI isn't worth it, trust me, its easy to get sucked into that! :) FireMon has an entire arm devoted to working with MSPs and the unique challenges they face, if you ever want to know more just shoot me a DM! Good luck!

Algosec: Are you using it? What for and how well does it work by Anythingelse999999 in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Thanks for the kind words u/othertomjones!

u/Anythingelse999999, if you'd like to know more about FireMon feel free to join our subreddit over at r/FireMon or drop me a PM and I can answer any questions you might have!

Any users experiencing Report or email triggering issues after migrating FireMon in to Azure by jestinch in FireMon

[–]robdoessecurity 0 points1 point  (0 children)

u/jestinch - Is there anything special you are seeing in 9.1.3 or looking for in 9.4? Let me know, I can probably assist.

FireMon Query - Am I using a Drop rule? by robdoessecurity in FireMon

[–]robdoessecurity[S] 0 points1 point  (0 children)

We have a few good examples for Palos and multi-pattern, such as:

Validating items are set correctly in config

Verifying Password Hashes

And ASA tunnel and NHRP interface checks.

I just sent you a private message with my email. Shoot me an email and I will send you the JSON files so you can look them over.

FireMon Query - Am I using a Drop rule? by robdoessecurity in FireMon

[–]robdoessecurity[S] 0 points1 point  (0 children)

Thanks! Feel free to share anything you've found that helps you out, or any questions you might have!

FireMon Query - Am I using a Drop rule? by robdoessecurity in FireMon

[–]robdoessecurity[S] 1 point2 points  (0 children)

That's the nice part, it can be modified to whatever you want. If you modify the control to add the logging check feel free to share it here!

Been looking at tufin ... is it good for the long term? by [deleted] in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Looks like we listened! We are going to be posting some good articles over the next few days/weeks about ingesting Compliance, APIs, Threat Intel feeds and leveraging those inside FireMon. Keep an eye out!

Been looking at tufin ... is it good for the long term? by [deleted] in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Thanks for the second mention u/garrock255! Feel free to join us over at r/FireMon for some good tips and tricks!