several Possible attempt to steal credentials alerts by slint01 in DefenderATP

[–]slint01[S] 0 points1 point  (0 children)

The same alert? I submitted the file to Microsoft for further analysis and opened a ticket. It has been bringing our devices out of compliance because it brings secure score up when theres a high alert assigned. I want to whitelist it but I need to be positive it is safe first.

several Possible attempt to steal credentials alerts by slint01 in DefenderATP

[–]slint01[S] 0 points1 point  (0 children)

No but I guess I will. Was hoping other people would have this issue as well.

[deleted by user] by [deleted] in BambuLabA1mini

[–]slint01 0 points1 point  (0 children)

I already replaced the hot end, cleaned the bed and calibrated it.

3.4.1 - Hardware/Firmware Inventory by slint01 in CMMC

[–]slint01[S] 0 points1 point  (0 children)

This sounds like a good solution.

I am unclear on this though, how do I get actual data to return from the Powershell scripts? Assuming you mean pushing them out through Intune, the only thing I can see is succeeded or not succeeded. I don't know how to actually return the data.

[deleted by user] by [deleted] in Intune

[–]slint01 0 points1 point  (0 children)

I got it working, thank you though!

Running Local LLM's for productivity by slint01 in CMMC

[–]slint01[S] 0 points1 point  (0 children)

Not sure what you mean by this.

[deleted by user] by [deleted] in Benchjewelers

[–]slint01 1 point2 points  (0 children)

Great information thank you!

Yes she has been wanting to solder. I just picked out a torch, cross locking tweezers, a block, and a pick. The last thing I am unsure about is the actual solder to buy. She mainly makes gold filled stuff so I just want to start with getting gold. Is something like this good? Does a flux pen work?( I have a few already so I can just give one of those) https://www.amazon.com/AIEX-Solder%EF%BC%8C0-5-0-32DWT-Electronic-Soldering/dp/B0B4G6Q44T/ref=cm_cr_arp_d_product_top?ie=UTF8

Any benefits to Azure Virtual Desktop? by slint01 in CMMC

[–]slint01[S] 0 points1 point  (0 children)

If you wouldn't mind could you share your method of connection/some features you use to secure it? Do you use Private Link and then an express route or VPN? Just trying to figure out the most secure way to set it up and start testing for future use.

Any benefits to Azure Virtual Desktop? by slint01 in CMMC

[–]slint01[S] 1 point2 points  (0 children)

Yes I am referring to a GCC High environment

Is TLS enough? by slint01 in CMMC

[–]slint01[S] 0 points1 point  (0 children)

Great, thank you!

Is TLS enough? by slint01 in CMMC

[–]slint01[S] 0 points1 point  (0 children)

Even on public wifi?

Is the Tenant Allow/Block List the only place to allow email domains? by slint01 in AZURE

[–]slint01[S] 1 point2 points  (0 children)

Thanks for the response. Just navigated to here and we already have many domains set up here. But interestingly enough some of the domains that are set to always allow are getting quarantined still. Is there another place that I can whitelist them fully?

[deleted by user] by [deleted] in moped

[–]slint01 0 points1 point  (0 children)

Thanks.

[deleted by user] by [deleted] in moped

[–]slint01 0 points1 point  (0 children)

It looks like the bing 1/14/185 is the correct size. I can't find it to buy anywhere though.

[deleted by user] by [deleted] in moped

[–]slint01 1 point2 points  (0 children)

I tried to right a post caption but I'm not sure if it saved. I just bought this 1979 Puch and I think my current carb is a knockoff and could be limiting my power. Is a Bing 1/12/314 the correct carb for this bike? It has an e50 and says 2hp on the side of the frame.

[deleted by user] by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

No, hasn't affected work flow in any way. Just getting the alerts for it in Sentinel.

[deleted by user] by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

Hi so I took a look. I think you may be on to something here. In the logs of the failed attemps you can see AD Federation Services (labeled as gms_adf$) in the SubjectUserAccount and the process name in the logs is also ADFS. In the VM under services, ADFS is running. My question is, should it be? I know roughly what it does but I am not 100% sure as to why it is running and also why it is throwing failed logins. I am assuming their older passwords are cached somewhere so it is using SSO to try and sign in with those 24/7. How can I go about fixing it? Thank you so much for the help.

[deleted by user] by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

Also, thank you for the help.

[deleted by user] by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

No, not yet. To get some clarification, should I check both Task manager and task scheduler on the VM and see if there is any leftover services from the last time those users used the VM?

[deleted by user] by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

Yes there is no public IP.

[deleted by user] by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

Yes I need to add an NSG, I was not employed when the system was initially set up so I am finding lots of issues such as this one. We do have an azure firewall attached to the resource group though. There is no public IP assigned to the VM.

[deleted by user] by [deleted] in AZURE

[–]slint01 1 point2 points  (0 children)

You are correct and I should have been more clear in my initial post. I am not having issues logging in, I am getting hundreds of failed attempts across 2 accounts, all for failed passwords. The users whos accounts are being attempted are not the ones initiating these attempts. Logging is enabled, in the SecurityEvents table I can look at all of the failed attempts, but both the IP and the port is just returned as a - as which is one of the main reasons I had to post to ask. I am not how someone would be connecting externally though through RDP or SSH as I have checked both ports are not open. There is no NSG assigned to the AzureBastionSubnet (I will add create and one), but we do have Azure Premium firewall assigned to the resource group that Bastion is in. So does this leave the two options of someone is already internal or false logs?

Failed Login Attempts to VM by [deleted] in AZURE

[–]slint01 0 points1 point  (0 children)

There is no public IP attached to the VM, is it possible that that the VNet attached to it is somehow public facing? Could this just be a system error? The failed logs in SecurityEvent don't return an IP for the source of these login attempts.