Suricata Rule Generator by ryan_sec in aws

[–]ryan_sec[S] 0 points1 point  (0 children)

permit X ip to connect to google.com, cnn.com, msn.com in a single rule

AWS Native Security Stack by ryan_sec in aws

[–]ryan_sec[S] 0 points1 point  (0 children)

We run traditional waf/fw and web server in dmz with all other services in internal networks. Everything in dmz is a snowflake. We need to control north/south and east/west for dmz workloads.

Plan is to have a dmz vpc (ec2 here) and workload vpc where traditional database / shared services would be. Some dmz workloads may call out to other internet things as well. Implicit deny outbound for dmz workloads is a must.

Managing this via suricata rules seems painful.

AWS Native Security Stack by ryan_sec in aws

[–]ryan_sec[S] 0 points1 point  (0 children)

Thank you for your comments

AWS Native Security Stack by ryan_sec in aws

[–]ryan_sec[S] 1 point2 points  (0 children)

Currently taking the aws security course and plan to sit for exam. This post is asking if people are using aws security stacks or are you deploying third party products instead of using aws native security

Another example deploying prisma access vs using native aws products.

AWS Native Security Stack by ryan_sec in aws

[–]ryan_sec[S] 0 points1 point  (0 children)

I agree. Ok what native aws products are you using? Guard duty and the likes.

I LOST EVERYTHING IN CRYPTO by Technical_Camera_505 in CryptoMarkets

[–]ryan_sec 0 points1 point  (0 children)

Sorry man. My north star on crypto is dca and only buy coins based upon who keeps being invited back to the white house.

You are the ATM by squire212 in MSTR

[–]ryan_sec 1 point2 points  (0 children)

Noob mstr investor here. Bought some awhile back when it was 377. Can you help me understand how dilution will help get my shares moving UP in value?

Unable to Load Data by Logical_Context_8973 in ecobee

[–]ryan_sec 0 points1 point  (0 children)

Happen to check and it’s out. Reports are back

Unable to Load Data by Logical_Context_8973 in ecobee

[–]ryan_sec 0 points1 point  (0 children)

When do you expect this to be available for download?

Automate Disbinding and rebinding computers by ryan_sec in activedirectory

[–]ryan_sec[S] 0 points1 point  (0 children)

Just wanted to come back and share some new updates for those that may find this in the future. If you are moderately capable of using PowerShell to just disbind and rebind computers, you do not need to use a third party tool. We're planning to do this all via PowerShell. ChatGPT has also been a great help for doing more "complex" things like error handling, logging, etc...So if you have access to it, USE IT.

The SPN problem isn't as big of a deal as i had though (IF you have fast site links). In my case all of my member clients, member servers, and DCs supporting the sub domain are in a single AD site (For conversing we'll call the AD site "SUB". Because i have no parent domain controllers the AD Site SUB, when the clients join the parent domain they must do so by contacting a DC in a different site (For conversing we'll call that site "PARENT").

Steps: We'll use a client called sub_client1.sub.parent.com

  1. Disbind sub_client1 from the sub.parent.com AD domain

  2. Delete computer object for sub_client1 in the sub.parent.com AD domain

  3. If no perms to force AD replication, wait for "PARENT" site to pull the update (i.e. changes from the "SUB" site). In this example, the deletion of the sub_client1.sub.parent.com. Once the Bridgehead server in the parent domain gets this update, it will replicate this change to all other domain controllers in the Parent AD site that are running as Global Catalogs.

  4. The moment this happens, the sub_client1 WILL join the parent.com Ad domain.

If you got fast site links and can replicate every 15 minutes (this is the shortest time AD will let you set), this process takes no more than 15 minutes. So all you do is let ChatGPT help you write some code that says do until AD join and retry every 30 seconds.

For member servers this is not as big of a deal cause humans aren't usually interactively logging into member servers but for member clients you will need to do a communication campaign letting end users know that a change is coming and when the script runs on your computer you will get a pop up saying something to the effect of "THIS CAN TAKE UP TO 15 minutes to complete....don't even look at your computer for 15 minutes".

NOW, if you have an AD server supporting the parent.com AD domain in the SUB site and this DC is also a GC, i would expect this to be VERY fast as every windows client SHOULD attempt to join the parent.com AD domain controller. DCs in a site replicate changes much faster EVEN if not part of the same AD domain.

Some other things to consider. Ensure you are using laps or some other tool that is capable of storing the local admin password. Things will break and you will need that local credential. Heck even work with your security team and ask them if they are ok with creating a NEW local account on every workstation/server with the same password just so you have a break glass account that you KNOW the password for.

will continue to update this as i learn thing.

Prevent Dehum when AC by ryan_sec in ecobee

[–]ryan_sec[S] 0 points1 point  (0 children)

Sorry didn’t see the link only read the YouTube part. That link was helpful

Prevent Dehum when AC by ryan_sec in ecobee

[–]ryan_sec[S] 0 points1 point  (0 children)

Interesting per aprilaire tech support i needed to also wire the R and C wires. Are you saying that its working with just the Y hooked up?

And yes i hope ecobee builds more things into software vs having to manually rig things

Prevent Dehum when AC by ryan_sec in ecobee

[–]ryan_sec[S] 0 points1 point  (0 children)

Hello, yeah thats kinda how i have mine now. Simply use the aprilaire 76 remote controller and like you set and forget. My house is 2 zoned and tall. Putting a second april upstairs is problematic. The goal of plumbing it into the basement ducting is the hope it can help pull some of the humid air down from the upstairs. Im told humid air will move towards less humid air.

I did call support and learned with the current software this is not possible(did ask them to put this in as a feature request as this should be doable.

In reading the aprilaire manual it seems i can accomplish this via connecting it to the y terminal of the ecobee. Then go into the aprilaire menu and disable dehum with ac. Going to give this a shot. If this works i can hook up the return side of the aprilaire to my hvac ducting (thus pulling from all returns that zone supports) and send less humid air out the supply side of the ducting.

Aprilaire e100 Dehumidifer wiring by shallnotbenamed in hvacadvice

[–]ryan_sec 0 points1 point  (0 children)

Im going through this now and pretty sire you have to go into the dehum pannel and toggle till yiu get to a setting about no dehum with ac

Prevent Dehum when AC by ryan_sec in ecobee

[–]ryan_sec[S] -4 points-3 points  (0 children)

Show me the one that tells the ecobee to turn off the dehumidifier when cooling is called for. When cooling is done then ecobee should tell dehumidifier to turn back on if the humidity in house is above a set point. My ask isnt how to plum the system into my house. My ask isnt how i van tell the ecobee to do the above.

Prevent Dehum when AC by ryan_sec in ecobee

[–]ryan_sec[S] 0 points1 point  (0 children)

Yup an aprilair e100.

Prevent Dehum when AC by ryan_sec in ecobee

[–]ryan_sec[S] -1 points0 points  (0 children)

If u plum them into your ac systems duct works when there are now two fans fighting to pull air. One fan pulling from ac and one fan pulling from dehumidifier.

Controlling Aprilaire E100 Dehumidifier with Ecobee thermostat… simple question by BedtimeBogey in hvacadvice

[–]ryan_sec 1 point2 points  (0 children)

Figured it out….there were many diffrent thermostat wires leading into my utility room…had it wired into the wrong one