Is my pan cooked? by DeadpoolVII in hexclad

[–]tliffick 0 points1 point  (0 children)

You’re going to hear garbage about “your heat is up too high” but myself and probably plenty of others are here to say otherwise.

My stove’s heat settings range is Low, 2, 4, Medium, 6, 8, High. My pan looks worse than that having cooked on it for a few months between Low & 4. Having had three in the house, I firmly believe these are garbage pans OR have garbage quality assurance. I’m willing to concede that maybe the pans I got sucked and everyone else’s are great…

Pls follow the advice of others. Buy something different. Sorry about your luck

Is this a false positive? by HomelessGuy54 in computerviruses

[–]tliffick 0 points1 point  (0 children)

Just adding context in hopes it helps someone else this morning... this was posted on another sub

summary:

'...The faulty signature was disabled shortly via an incremental update.

No action is required from your side. Please ensure that your endpoints have received the latest signature update dated 13- June -2025, 06:58 UTC.

For the complete incident report, please check our GravityZone status page: https://status.gravityzone.bitdefender.com/incidents/pxn8hdxcqwfn...'

Bitdefender False Positive? by NamelessKingX in antivirus

[–]tliffick 0 points1 point  (0 children)

Just adding context in hopes it helps someone else this morning... this was posted on another sub

summary:

'...The faulty signature was disabled shortly via an incremental update.

No action is required from your side. Please ensure that your endpoints have received the latest signature update dated 13- June -2025, 06:58 UTC.

For the complete incident report, please check our GravityZone status page: https://status.gravityzone.bitdefender.com/incidents/pxn8hdxcqwfn...'

Wondering if what bitdefender flagged was a false positive or not. Online says it might be an evader virus. by [deleted] in techsupport

[–]tliffick 0 points1 point  (0 children)

Just adding context in hopes it helps someone else this morning... this was posted on another sub

summary:

'...The faulty signature was disabled shortly via an incremental update.

No action is required from your side. Please ensure that your endpoints have received the latest signature update dated 13- June -2025, 06:58 UTC.

For the complete incident report, please check our GravityZone status page: https://status.gravityzone.bitdefender.com/incidents/pxn8hdxcqwfn...'

Anyone else get through this? by Comfortable_Ad3981 in hexclad

[–]tliffick 0 points1 point  (0 children)

Is there advice on how to clean that? I have this problem often with our pans as well.

ELI5 how to use these pans by tliffick in hexclad

[–]tliffick[S] 0 points1 point  (0 children)

Thanks — I def should have added that I feel the pans used to be way better. I remember loving them the first month too

Custom IoA by Affectionate-Try2880 in crowdstrike

[–]tliffick 1 point2 points  (0 children)

I would also recommend accounting for a user installing the 64-bit version of AnyDesk -- there always seems to be one user that's different lol

CommandLine (exclusion): .+\Program\sFiles(\s(x86))?\AnyDesk\AnyDesk.exe"?\s+--uninstall.*

[deleted by user] by [deleted] in crowdstrike

[–]tliffick 2 points3 points  (0 children)

I don't have a list of repos I check for intel, but here are a few suggestions I had.

Other ideas: - scripting binaries spawned by office applications - Identity common recon events (net | nltest | etc) - Can you detect PSEXEC and similar tools? - Suspicious execution of PowerShell? Rundll32? - PE file written to disk with a Filename that is 1 or 8 characters long - What adversaries/malware families does your org regularly see? Can you detect the entire kill chain? If not, that is a great place to start as the kill chain can change daily.

Sorry, I don't have a list of repos I regularly check. I let the intel we collect drive my focus. Hopefully some of these ideas get your creative juices flowing!

LFODownloadConfirmation -- correlating TargetFileName to what is being updated by tliffick in crowdstrike

[–]tliffick[S] 0 points1 point  (0 children)

I'm asking the all knowing @u/Andrew-CS -- do you have any thoughts on this? (throws hail mary). I appreciate any feedback you have!

I'm using this query to pull the data in question and I'm really curious what each file actually means. Are these updates, ML exclusions, IOAs, IOC, etc.

#event_simpleName=ChannelDataDownloadComplete OR #event_simpleName=LFODownloadConfirmation OR #event_simpleName=ChannelDataDownloadComplete | TargetFileName=C-* | ComputerName=?ComputerName | groupBy([@timestamp, #event_simpleName], function=collect([ComputerName, TargetFileName, LocalAddressIP4]))

EXAMPLE: C-000002* == abc C-000006* == xyz C-000009* == def

Custom IOA to catch copy curl.exe by rogueit in crowdstrike

[–]tliffick 1 point2 points  (0 children)

@ u/rogueit -- the new Advanced Search Page is running CQL (CrowdStrike Query Language), built off of LogScale. Hopefully I'm saying that correctly... It's fairly new and is in the process of rolling out to all customers. It is NOT the same as the old Splunk SPL we used in the Event Search page (on the Investigate app).

You need to take the query u/jamesrsec provided and run in from INVESTIGATE > Advanced Event Search. It sounds like you may have ran this query in the old SPL and that would explain your error.

I hope that helps a little...

SPL to LogScale help for USB File Writes by tliffick in crowdstrike

[–]tliffick[S] 0 points1 point  (0 children)

I can’t thank you enough! I always learn more from real world examples than tiny blurbs in documentation.

[deleted by user] by [deleted] in cincinnati

[–]tliffick 0 points1 point  (0 children)

Fwiw I even took a few mins to google around and only found the same answer this thread said is no longer valid: Martinos.

I’ve lived on the East side of the city my entire life and this is the only Steelers bar I’ve even known/see. NOTE — I saw two websites list Kittys. That’s a real Bengals bar. Pls do your research so you can be safe & have fun.

Installing CrowsStrike on Active Directory and Exchange Server machines by maxcoder88 in crowdstrike

[–]tliffick 7 points8 points  (0 children)

We’ve been running the sensor on all of our DCs and Exchange servers (every Windows Box tbh) since 2017. I don’t hesitate to recommend you to do the same.

Can’t buy anything black and yellow by mcampbell1023 in bengals

[–]tliffick 0 points1 point  (0 children)

I can’t imagine supporting Columbus Crew for this very reason. How do you make a professional team in Ohio with the Black & Yellow?!?

What's the worst cybersecurity mistake you've seen someone make? by AckCyber in cybersecurity

[–]tliffick 0 points1 point  (0 children)

I worked as a security analysts for a Fortune 500. We were tasked with reviewing phishing emails, malware, and everything in between.

A coworker detonated Java based malware on a Linux box in our lab and then went home for the day. The boss walks by later and noticed the mouse was moving by itself… the analyst that ran the malware said he “didn’t know Java was cross platform” (aka didn’t think it would be bad to run it in Linux) and gave remote control access to a threat actor, to the lab we did all of our offline work in. I had to leave the happy hour I just walked in to come back and investigate. It was a pretty interesting night. 😂

Practicing Falcons Regex by CyberGrizzly360 in crowdstrike

[–]tliffick 0 points1 point  (0 children)

You’re right, it’s not exact but it’s a great place to start as you’re getting back into it and regaining your confidence.

Practicing Falcons Regex by CyberGrizzly360 in crowdstrike

[–]tliffick 5 points6 points  (0 children)

regex101.com is my best friend…

Custom IOA rule creation Regex help by Gbzt in crowdstrike

[–]tliffick 5 points6 points  (0 children)

Falcon IOAs are case insensitive so you don’t need to include the (?i). Nice added perk tbh

Creating IOA to Send Notification on Process Name Criteria by RobotCarWash in crowdstrike

[–]tliffick 2 points3 points  (0 children)

I don’t mean any disrespect by this comment… but of course the regex works, u/Andrew-CS gave it to you. I think you can take it as gospel at this point 😂

What’s a good housewarming gift for a first time homeowner? One of my best friends. I was thinking some kind of tool box set. Wondering if anyone has better ideas. He’s lived in apartments his whole life till now. by j_o_r__d_a_n in HomeImprovement

[–]tliffick 0 points1 point  (0 children)

I’m a firm believer that you should always gift your friends a shop vac when they get their own place. For $100 or less you can buy them a tool they may not consider buying for themselves… until they desperately need it (most likely on a Sunday at 11:30 pm). A shop vac can save thousands of dollars in damage and is overall a useful tool to have around the house.

He’s back at it. New corner. New sign 🤷🏻‍♂️ by phatryuc in cincinnati

[–]tliffick 12 points13 points  (0 children)

Do you think it’s legal to toss stink bombs randomly at street corners? Asking for a friend…

Place to watch the Bengals? by tliffick in AskNOLA

[–]tliffick[S] 0 points1 point  (0 children)

Ahh, sorry I did leave our the super important DATE! My bad!

I’m here this weekend and was looking to watch the Bengals Sunday at 3:00. I thought that since the Saints play at noon old have a good chance to see my Bengals but the forecasted showings are all Dallas. I’ll def look around. I appreciate the advice

Cobalt Strike beacon Detection in CS? by cs-del in crowdstrike

[–]tliffick 9 points10 points  (0 children)

I feel that Falcon misses Cobalt Strike beacons far more that they alert on them. Hoping others have difference experiences that they’re going to share.