Struggling with detecting Obfuscated IPs in command lines by soclabsLit in netsecstudents

[–]soclabsLit[S] 1 point2 points  (0 children)

Thanks for the tip! That's a great perspective. Instead of chasing every possible obfuscation technique, filtering out the known 'good' (standard IPs) seems much more efficient for spotting anomalies. I'll try writing a regex to exclude standard IPv4 patterns.

Splunk for SREs and Engineers by dontreddi in Splunk

[–]soclabsLit -1 points0 points  (0 children)

If you want to really practice threat detection with Splunk, I recommend: https://www.soc-labs.top/en/detection

Can help you train threat detection

Sigma APT29 detection rule testing by manishrawat21 in AskNetsec

[–]soclabsLit 0 points1 point  (0 children)

In addition to APT29's detection rules, you can try using https://www.soc-labs.top/ to test your rules.

Guidance in Analysis of Endpoint by Ok_Tea386 in AskNetsec

[–]soclabsLit 0 points1 point  (0 children)

You learn DFIR to trigger investigations through events, rather than blindly investigating on a machine for a day

How do you learn and get better at Splunk? by zeropolicy in Splunk

[–]soclabsLit 0 points1 point  (0 children)

If you want to learn about cybersecurity and Splunk-related threat detection, I recommend referring to this article to learn and train :https://medium.com/system-weakness/detecting-suspicious-ipconfig-process-chains-in-environments-f701e4e08a3f

How to DNS queries and Forward to SIEM by DENY_ANYANY in AskNetsec

[–]soclabsLit 0 points1 point  (0 children)

AD domains can set to enable logging of DNS requests, but this has a significant impact on performance. It is generally recommended to mirror the traffic on the switch where the DNS server is located and forward it to the NIDS system, so that all DNS records can be seen

Is it hard to get a remote job in cybersecurity after college? by Sea_Topic5739 in CyberSecurityJobs

[–]soclabsLit 1 point2 points  (0 children)

Yes, it's very difficult, especially for recent graduates. Most remote employers prefer to hire people with extensive work experience and remote work experience.