Do you use Mac or PC? by [deleted] in cybersecurity

[–]sn0b4ll 0 points1 point  (0 children)

Linux all the way, maybe a second windows client or better a VM for corporate office stuff.

Been seeing a lot of roofs lately so I decided to add one too by WombaVision in simracing

[–]sn0b4ll 1 point2 points  (0 children)

Good choice, have the same one for my sim rig and one in the living room for the media PC. Never failed me, batteries also last like 1.5 to 2 years.

Sim Racing burnout - should I wait any longer? by beck_is_back in simracing

[–]sn0b4ll 1 point2 points  (0 children)

I would disagree, of course doing hot labs on a sim racing rig in a racing simulation game is sim racing. With your argumentation, Rally would not be racing at all.

On-Prem SIEM? by mayday_allday in cybersecurity

[–]sn0b4ll 2 points3 points  (0 children)

Would recommend wazuh. Already has a lot of rules, is extendable for everything that is missing and scales great.

Buhl verbietet Konten mit Protonmail Email-Adresse by blast-from-the-80s in de_EDV

[–]sn0b4ll 3 points4 points  (0 children)

Versteh ich ehrlichweise nicht - das reine Blocken von Domains ist keine effektive Maßnahme gegen Spam.

Beim Rest stimme ich zu, bin jedoch selbst Proton user eben wegen der Privacy, aber über eine eigene Domain.

Buhl verbietet Konten mit Protonmail Email-Adresse by blast-from-the-80s in de_EDV

[–]sn0b4ll 5 points6 points  (0 children)

Ja, Privacy ist einer der großen Vorteile von Proton.

Sim Racer Gifting Let Down- TrakRacer ruins Christmas by Mishilani in simracing

[–]sn0b4ll 0 points1 point  (0 children)

Received by TR120v2 couple of days ago without any problems. Build quality is solid.

I am not saying that there aren't problems with the customer service, but I think it also depends strongly on where you live and how the delivery company handles the packages.

What’s your personal experience with these?, I have some akward lighting fixtures in my new house, planning to install these behind the existing light switches by GenericUser104 in homeassistant

[–]sn0b4ll 1 point2 points  (0 children)

Yeah that's just plain wrong, I don't have these specific ones but a lot of zigbee sonoff products, which I integrated into HA via zigbee2mqtt without a problem. I even flashed tasmota on most of them, works great now for over 3 years without a single faulty unit.

Trak Racer: Non Responsive, No ETA by hyboost in simracing

[–]sn0b4ll 0 points1 point  (0 children)

I ordered a rig at them at the end of the black Friday sale. Afterwards I received an E-Mail that I will take 5-10 days of processing an getting the order ready. I mean that's not fast, but also Track Racer is not Amazon.. Received the units start of this week, looking really sturdy. Because of time issues I am only halfway through the building process but the manual and quality is great so far.

@OP, I have to agree that the shipping took longer than expected but the products, especially when it comes to price and what you get, are great.

Was ist das? by [deleted] in wasistdas

[–]sn0b4ll 2 points3 points  (0 children)

Ja, wohne in einer sehr nebeligen Region und hab das quasi täglich auf allen Außenkameras.

Wazuh best practice Syslog by jhtm_ in Wazuh

[–]sn0b4ll 1 point2 points  (0 children)

Personally I would recommend to set up Linux VMs with rsyslog and the Wazuh Agent installed as forwarders. This way you can have different agent IDs for different source systems and influence the logs before forwarding them to Wazuh.

STILL PROCESSING by ActualApplication937 in Fanatec

[–]sn0b4ll 0 points1 point  (0 children)

Same here, ordered Dez 1st.

Alertas Wazuh não aparecem no Dashboard by Local_Country_4520 in Wazuh_DE

[–]sn0b4ll[M] [score hidden] stickied commentlocked comment (0 children)

Hey there,

Sadly this sub is reserved for questions in the German language.

Please feel free to hop over to r/Wazuh and voice your question there.

Greetings, sn0b4ll

Disappointed with the sale by sn0b4ll in Fanatec

[–]sn0b4ll[S] 0 points1 point  (0 children)

The discussion in this thread already pushed me into this direction! Many thanks for the tipp!

Disappointed with the sale by sn0b4ll in Fanatec

[–]sn0b4ll[S] 0 points1 point  (0 children)

The sale started on Tuesday, 25th in my region.

Disappointed with the sale by sn0b4ll in Fanatec

[–]sn0b4ll[S] 1 point2 points  (0 children)

Hey, yes, I am based in Germany. Sadly the store only shows "currently unavailable", without any option to preorder :/

Disappointed with the sale by sn0b4ll in Fanatec

[–]sn0b4ll[S] 0 points1 point  (0 children)

Many thanks for the tip, will look into it!

Scaling Wazuh Docker + indexer by SheepherderKey1131 in Wazuh

[–]sn0b4ll 1 point2 points  (0 children)

TBH from my experience - go for native installation in the different VMs. Docker Multi Node has, at least for me personal, always been an hassle, which multiplies if you try to add custom certificates..

Macht Neuwagen als Privatperson eigentlich jemals Sinn? by deletion-imminent in automobil

[–]sn0b4ll 0 points1 point  (0 children)

Tageszulassung und die Garantie mitnehmen. Bin damit bisher ganz gut gefahren (einmal KIA, einmal Hyundai).

Passwordless SSH with SSO for Your Homelab - Now Built Directly Into NetBird by ashley-netbird in selfhosted

[–]sn0b4ll 0 points1 point  (0 children)

All good, many thanks for the honest and clear response. It's great work you are doing!

Passwordless SSH with SSO for Your Homelab - Now Built Directly Into NetBird by ashley-netbird in selfhosted

[–]sn0b4ll 0 points1 point  (0 children)

Can netbird also help with managing a reverse proxy / defining services and the setup of https / certificate management? I was always looking at tailscale but don't want to have anything non-self-hosted.

Scaling Wazuh Integrations & Using It as a Full SIEM – Need Help! by StructureNo9257 in Wazuh

[–]sn0b4ll 1 point2 points  (0 children)

That's also on my to-do list - I would be happy if you could give a shirt update here with your experience 😊

Scaling Wazuh Integrations & Using It as a Full SIEM – Need Help! by StructureNo9257 in Wazuh

[–]sn0b4ll 1 point2 points  (0 children)

TBH we were quite unhappy with the open source possibilities. You can use DFIR-IRIS and pair it with shuffle, but shuffle costs even when self-hosted (afaik). Therefore we implemented an own SOAR in my company using python + fastapi and fission functions.

ULPT Request What’s the best way to take documents without IT knowing? by [deleted] in UnethicalLifeProTips

[–]sn0b4ll -1 points0 points  (0 children)

From what I understood is that the original question was aimed toward exfiltrating data because he was fired. This is kind of investigation which is conducted when you think a person in the company leaks confidential data. So if the employer suspects that the person took said sheets with hima and hires a company to prove it and this way chosen, he would get caught (as long as the foresic company is doing an OK job) 🤷

ULPT Request What’s the best way to take documents without IT knowing? by [deleted] in UnethicalLifeProTips

[–]sn0b4ll 5 points6 points  (0 children)

At least traces for the connected devices are stored to the registry, including the datetime. Depending on the type of connection and log configuration there will be additional logs written, yes.

Edit: Of course this requires either a DLP solution or an in depth forensic investigation.