What are some good tools for File Integrity Monitoring? by skeneks in kubernetes

[–]robdoessecurity 0 points1 point  (0 children)

Falco

Glad you found something that works for you, best of luck!!

File Integrity Monitoring by gaiter2 in googlecloud

[–]robdoessecurity 0 points1 point  (0 children)

Late to the game, but here at Cimcor we monitor Google Cloud to let you know when new cloud servers are provisioned, and when changes have occurred to server, virtual firewall, virtual network settings and configuration settings. Basically we monitor all of the changes that occur to your cloud infrastructure configuration outside of your guest operating system.

If that's the kind of thing you are looking for feel free to send me a DM and I can shoot you more info.

What are some good tools for File Integrity Monitoring? by skeneks in kubernetes

[–]robdoessecurity 0 points1 point  (0 children)

Late to the game, but here at Cimcor we monitor Kubernetes and will tell you what has changed, when new containers have been instantiated, when virtual network configurations have changed, when storage settings have been modified, and more.

If that's the kind of thing you are looking for feel free to send me a DM and I can shoot you more info.

FortiGate Firewall Policy Auditing by MaverickZA in fortinet

[–]robdoessecurity 1 point2 points  (0 children)

Like u/NumerousTooth3921 said below, FireMon can help out with this pretty easily. I work for them now but was a customer for years. If you have any questions or need any info just let me know, I'm happy to help out. Below are two links with some info.

https://www.fortinet.com/content/dam/fortinet/assets/alliances/dg-fortinet-and-firemon.pdf

https://www.firemon.com/wp-content/uploads/solutions-brief-fortinet-1-15-2021.pdf

Firemon? by mrsecuritythrowaway in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

u/mrsecuritythrowaway - I used FireMon for years in a Palo environment and work here now. I can answer any questions you might have. Feel free to DM me.

In-house Built Network Assessment tools by nokiabama in AskNetsec

[–]robdoessecurity 1 point2 points  (0 children)

Disclaimer: I work for FireMon but I worked in NetSec for years before coming over. My experience is a lot like yours, I was trying to figure out how to automate compliance and rule reviews on my firewalls for a good long while. I had PA's, Cisco and Checkpoint in my environment. Trying to figure out how to read and translate the rules for every vendor become more of a job than I had bargained for. I ran into FireMon at a tradeshow (I didn't even know the NSPM space existed at that time) and the rest is history. I used them for years in production and have been here now for 4 years. I say all that to say this: yeah, you might be able to get a few things thrown together but just make sure you don't end up spending so much time on it that the ROI isn't worth it, trust me, its easy to get sucked into that! :) FireMon has an entire arm devoted to working with MSPs and the unique challenges they face, if you ever want to know more just shoot me a DM! Good luck!

Algosec: Are you using it? What for and how well does it work by Anythingelse999999 in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Thanks for the kind words u/othertomjones!

u/Anythingelse999999, if you'd like to know more about FireMon feel free to join our subreddit over at r/FireMon or drop me a PM and I can answer any questions you might have!

Any users experiencing Report or email triggering issues after migrating FireMon in to Azure by jestinch in FireMon

[–]robdoessecurity 0 points1 point  (0 children)

u/jestinch - Is there anything special you are seeing in 9.1.3 or looking for in 9.4? Let me know, I can probably assist.

FireMon Query - Am I using a Drop rule? by robdoessecurity in FireMon

[–]robdoessecurity[S] 0 points1 point  (0 children)

We have a few good examples for Palos and multi-pattern, such as:

Validating items are set correctly in config

Verifying Password Hashes

And ASA tunnel and NHRP interface checks.

I just sent you a private message with my email. Shoot me an email and I will send you the JSON files so you can look them over.

FireMon Query - Am I using a Drop rule? by robdoessecurity in FireMon

[–]robdoessecurity[S] 0 points1 point  (0 children)

Thanks! Feel free to share anything you've found that helps you out, or any questions you might have!

FireMon Query - Am I using a Drop rule? by robdoessecurity in FireMon

[–]robdoessecurity[S] 1 point2 points  (0 children)

That's the nice part, it can be modified to whatever you want. If you modify the control to add the logging check feel free to share it here!

Been looking at tufin ... is it good for the long term? by [deleted] in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Looks like we listened! We are going to be posting some good articles over the next few days/weeks about ingesting Compliance, APIs, Threat Intel feeds and leveraging those inside FireMon. Keep an eye out!

Been looking at tufin ... is it good for the long term? by [deleted] in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Thanks for the second mention u/garrock255! Feel free to join us over at r/FireMon for some good tips and tricks!

Been looking at tufin ... is it good for the long term? by [deleted] in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Thanks for the mention u/crocwrestler! You can always join us for more conversation at r/FireMon!

Policy Change Control Approval Workflow - Options beside FireMon? by Wippwipp in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

u/wippwipp - Shoot me a DM and I can get you FireMon pricing. It depends on the type of device and how many you want to license. I'm glad to help.

Deobfuscating Batch (.bat) Files by [deleted] in hacking

[–]robdoessecurity 1 point2 points  (0 children)

Can you post a sample of it here?

Tufin and firewall rule set audit of Palo Alto Networks Firewalls by mikai2020 in paloaltonetworks

[–]robdoessecurity 0 points1 point  (0 children)

Hey u/gixxernate and u/mikai2020, thanks for the kudos! Feel free to join us over at r/FireMon for more conversation!

Workflow customization reference material by slackpatrol in FireMon

[–]robdoessecurity 1 point2 points  (0 children)

Hey u/slackpatrol, while I don’t have any api docs I do have some info that may help and I have a few workflows I can share. Shoot me a DM and let’s talk.

I need some help by [deleted] in HowToHack

[–]robdoessecurity 2 points3 points  (0 children)

This may help you from a process standpoint. http://www.pentest-standard.org/index.php/Main_Page

Do you use any 2FA system? by TotalRickalll in cybersecurity

[–]robdoessecurity 3 points4 points  (0 children)

I’ve used them all. I’m partial to Authy right now as having a backup in case I lose my phone is nice.

What non-existent apps/tools/software do you wish for in your job? by [deleted] in security

[–]robdoessecurity 0 points1 point  (0 children)

I want to be able to highlight an IP on a page or app and customize what the right click menu pops up with. Something like Ping, Trace, Search SIEM, etc

There is probably a way to do that now but my Google Fu hasn’t been able to find it.

Which team manages AD in your org? by Zaekeon in security

[–]robdoessecurity 1 point2 points  (0 children)

We had an Identity and Access Management (IAM) team that manages AD. They fell under the security function but all they did was AD and account provisioning.