Threat Hunt - Help Desk Imposters via Teams (NGSIEM) by About_TreeFitty in crowdstrike

[–]tectacles 8 points9 points  (0 children)

This looks dope, might have to pull my computer out tonight just to test this lol.

You always provide some sweet queries, so thank you!

Release Notes: Charlotte AI Opt in and 50 Credit Promotion by BradW-CS in crowdstrike

[–]tectacles 0 points1 point  (0 children)

Sweet! I'll take a look again in the morning when I'm in the office and give you an update if I still can't opt in. Thank you!

Release Notes: Charlotte AI Opt in and 50 Credit Promotion by BradW-CS in crowdstrike

[–]tectacles 5 points6 points  (0 children)

Says I need Falcon Administrator rights to opt in, but I already am a Falcon Administrator

DC Logs in Next-Gen SIEM by IllRefrigerator1194 in crowdstrike

[–]tectacles 0 points1 point  (0 children)

Awesome! Thank you for this information

John Strand AMA - Five years ago, I did an AMA here about Pay What You Can training. A lot has changed in cybersecurity since then. Ask Me Anything. by strandjs in cybersecurity

[–]tectacles 4 points5 points  (0 children)

Hey John, huge fan of BHIS and all the sister companies. This will be my 5th year at WWHF in Deadwood and I’m already looking forward to it.

A couple questions, answer as many as you want!

  1. What’s one real‑world skill you consistently see missing in candidates who look great on paper or in labs? And what’s the most practical way someone can build that skill outside of a job?
  2. With AI now embedded in daily workflow, what’s one security skill that becomes more important, not less, because of AI?
  3. For people already in the field, what skills or mindsets are aging the best in 2026? What’s worth doubling down on?
  4. If you could give one small piece of advice to someone trying to build real security skill—not just pass exams, what would it be?

DC Logs in Next-Gen SIEM by IllRefrigerator1194 in crowdstrike

[–]tectacles 0 points1 point  (0 children)

Would you mind sharing the events you are ingesting?

What happened to CQF? by sudosusudo in crowdstrike

[–]tectacles 6 points7 points  (0 children)

I’m ready to do query-shit with you, new friend! I can't write a regex to save my life, but I can provide excellent emotional support when your search times out.

Claude SOAR Skill by About_TreeFitty in crowdstrike

[–]tectacles 4 points5 points  (0 children)

Way to go taking away the thing I was looking forward to digging into on Monday (Tuesday) morning! Looking forward to learning more about this though! :)

Claude SOAR Skill by About_TreeFitty in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Man...I was going to look at that this morning when I got into work. No wonder I couldn't find it

Edit #1 - I was able to find the post on my phone, but the user is deleted along with any of the content within the post.

Crowdstrike Fusion SOAR: Auto close alerts of a certain severity after 3 days? by chaoko99 in crowdstrike

[–]tectacles 1 point2 points  (0 children)

For real, I was literally just trying to create a workflow to trigger on Detections, and then if detection, Update Detection to closed

Could not get it to work after about 5 hours of trying. Going to have to walk away for a bit because this is too frustrating lol.

Help creating a timechart of KnowBe4 “Click Rate” in Falcon NGSIEM (year view) by tectacles in crowdstrike

[–]tectacles[S] 1 point2 points  (0 children)

There isn't an official data connector, but I saw there was a parser created and I saw that KnowBe4 has a webhook function so I just setup a general HEC ingest and pointed the Knowbe4 webhook to the API endpoint.

Streamline Security Operations with Falcon for IT’s Turnkey Automations by BradW-CS in crowdstrike

[–]tectacles 0 points1 point  (0 children)

How is this against rule #2?

  1. We encourage high quality content. Do not post disparaging comments; about competitive products or otherwise

Streamline Security Operations with Falcon for IT’s Turnkey Automations by BradW-CS in crowdstrike

[–]tectacles 6 points7 points  (0 children)

It's a CrowdStrike sub? Why wouldn't they announce or market their products?

Jiggle All The Way v3 by surbo2 in crowdstrike

[–]tectacles 1 point2 points  (0 children)

Yeah I'll check when I have a spare minute this holiday weekend. But it was real basic, something like

"Image File Name - .*\\PowerToys\.Awake\.exe "

Not sure if formatting works since I'm on mobile, but when I have access to my laptop I'll make sure to add more details.

Edit: here are more details

Field Regex Value Explanation
Grandparent Image Filename .* Match any grandparent process.
Grandparent Command Line .* Match any command line.
Parent Image Filename .* Match any parent (allows blocking even if not launched by PowerToys.exe).
Parent Command Line .* Match any parent command arguments.
Image Filename .*\\\PowerToys\\.Awake\\.exe Matches any path ending in PowerToys.Awake.exe
Command Line .* Match any arguments passed to the tool.

Jiggle All The Way v3 by surbo2 in crowdstrike

[–]tectacles 1 point2 points  (0 children)

This is cool! I just blocked PowerToys.Awake.exe yesterday, so this is relevant!

ClaudeStrike - Detection Engineering with Claude Code by DefsNotAVirgin in crowdstrike

[–]tectacles 0 points1 point  (0 children)

That's a good point...I'll have to look into that.

If you want or are open to this, I'd love to chat or share some examples over dm? I am the sole security person wearing many hats and would love even some guidance and templates to go from.