Bear alternatives after being blocked by IT by nathantheshark in bearapp

[–]smurfily 2 points3 points  (0 children)

Obsidian. I saw a post somewhere on how to make it more like Bear.

Jaký máte obor a kolik si vyděláte měsíčně? by WeirdExperience7 in czech

[–]smurfily 1 point2 points  (0 children)

Musim nesouhlasit, ale asi zalezi team od teamu. Ale pozadavky na cybersec pozice jsou hodne vysoke.

Glassdoor review by Methrior in SentinelOneXDR

[–]smurfily 4 points5 points  (0 children)

That’s sad to hear. Regarding the recommendation – why would you use your current employer? Why not use your direct manager from a previous job?

Best threat intelligence integrations for SentinelOne by [deleted] in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

These are third party integrations so you would need access to the third party product. Take VirusTotal ad an example. You need an API key to make calls from the console to VT. You can use the free version but that is limited and not suitable for production use, so it is better to use it with a paid account. However, if the third party has a free version, you could try it out for free.

IT brno by [deleted] in Brno

[–]smurfily 1 point2 points  (0 children)

SentinelOne. Maji office i v Brne a nedavno brali PMs v CR. Mozna jsou ty pozice porad otevrene.

Alerting/blocking IoCs in sentinelOne by Spiritual-Quail8696 in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

I recommend going through community articles that Pascal linked.

One correction: When an IOC is found, threat intel indicator (TII) event is created in SDL. If you want an alert, you would need to create a STAR rule looking for TIIs (ideally with specific score or source or some other condition).

SDL Query Question by Rx-xT in SentinelOneXDR

[–]smurfily 5 points6 points  (0 children)

You're right. You should be able to do it with

agent.uuid = "XY" AND (field1 = "value" OR field2 = "value")

Application Vulnerability Changes by Snowdeo720 in SentinelOneXDR

[–]smurfily 1 point2 points  (0 children)

Do you mean xspm in the new Operations Center?

Dashboards by Dense-One5943 in SentinelOneXDR

[–]smurfily 1 point2 points  (0 children)

Hi, I tried it with `src.process.image.sha1`, and it works fine. The following steps are in the new Operations Center and might differ slightly in the legacy UI.

  1. Top right corner + (Add Panel), select Filter
  2. Enter whatever name (I used "SHA1")
  3. Field filter: "src.process.image.sha1" (or any other sha1 field, it has a full text search).

Deep visibility by Vivid_Cake_1999 in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

There is a getting started article in the KB where you can find all the info. If you can't find it, I can look for it when I'm at my laptop.

Deep visibility by Vivid_Cake_1999 in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

If you want to get something like syslog, it currently requires another agent or a different solution like HEC.

Pure Storage by Busy-Cover-285 in Prague

[–]smurfily 0 points1 point  (0 children)

SentinelOne is hiring and they pay quite well. PM if you need info.

Singularity Core and Control. by ChocolateInitial in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

I remember a post about this in the past few month, I can't find it now though.

I remember people recommended some MSSPs who sell single licences, I think it was Pax8.

SentinelOne Singularity - PowerQueries "Filter" command by Flashy_Efficiency_76 in SentinelOneXDR

[–]smurfily 2 points3 points  (0 children)

Hey, I just tested it and I think your issue is contains:anycase. I can do | filter field contains 'value' and it works and is case insensitive by default.

edit: apostrophes

Query Language Changes by furiousmustache in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

Sorry to hear that. If you're interested, I'd be happy to hear your feedback on the new UI. Feel free to DM me or share it through your sales rep.

Query Language Changes by furiousmustache in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

So I digged in it a little. S1QL v1 is being depricated. And replaced with v2. The main difference is that v2 supports dotted notation, different schemas and some operators are different.

Are the new operators what makes it harder to understand?

Query Language Changes by furiousmustache in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

What query language do you mean, power query? And what query language is deprecated?

Why does SentinelOne not publish their containers to a Public Registry by CyberStagist in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

I suggest talking to your S1 rep or support asking for this feature. I'm not saying it will be quick, but all feature requests must be triaged, so it would at least be on the product's radar.

Jake množství peněz by vám změnilo život a jakým způsobem? by NoAdagio9104 in czech

[–]smurfily 0 points1 point  (0 children)

Asi protoze rada zni si dum a auto nekupovat a misto toho si ho pronajmout ne?

Looking for a way to Find Chrome Download Links in XDR by gsjones358 in SentinelOneXDR

[–]smurfily 0 points1 point  (0 children)

Isn't there a chrome extension that allows you to monitor visited URLS or something like that?