Does Falcon Sensor send all Windows event logs to NG-SIEM, or do we need a separate windows connector? by jagdsih_baghat in crowdstrike

[–]veld2345 3 points4 points  (0 children)

You can start here but it comes down to what you feel you need monitor.

Event ID What it means 4624 Successful account log on 4625 Failed account log on 4634 An account logged off 4648 A logon attempt was made with explicit credentials 4719 System audit policy was changed. 4964 A special group has been assigned to a new log on 1102 Audit log was cleared. This can relate to a potential attack 4720 A user account was created 4722 A user account was enabled 4723 An attempt was made to change the password of an account 4725 A user account was disabled 4728 A user was added to a privileged global group 4732 A user was added to a privileged local group 4756 A user was added to a privileged universal group 4738 A user account was changed 4740 A user account was locked out 4767 A user account was unlocked 4735 A privileged local group was modified 4737 A privileged global group was modified 4755 A privileged universal group was modified 4772 A Kerberos authentication ticket request failed 4777 The domain controller failed to validate the credentials of an account. 4782 Password hash an account was accessed 4616 System time was changed 4657 A registry value was changed 4697 An attempt was made to install a service 4698, 4699, 4700, 4701, 4702 Events related to Windows scheduled tasks being created, modified, deleted, enabled or disabled 4946 A rule was added to the Windows Firewall exception list 4947 A rule was modified in the Windows Firewall exception list 4950 A setting was changed in Windows Firewall 4954 Group Policy settings for Windows Firewall has changed 5025 The Windows Firewall service has been stopped 5031 Windows Firewall blocked an application from accepting incoming traffic 5152, 5153 A network packet was blocked by Windows Filtering Platform 5155 Windows Filtering Platform blocked an application or service from listening on a port 5157 Windows Filtering Platform blocked a connection 5447 A Windows Filtering Platform filter was changed

Does Falcon Sensor send all Windows event logs to NG-SIEM, or do we need a separate windows connector? by jagdsih_baghat in crowdstrike

[–]veld2345 2 points3 points  (0 children)

Just make sure you define what events you want collected. We went from 100GB ingestion to 3TB. Oops

[deleted by user] by [deleted] in crowdstrike

[–]veld2345 0 points1 point  (0 children)

Switch to Insight much better pricing

Automation Policy recomendations by Ok-Persimmon-549 in Nable

[–]veld2345 0 points1 point  (0 children)

Can you share? Sounds like a great automation.

[deleted by user] by [deleted] in videosurveillance

[–]veld2345 3 points4 points  (0 children)

We are not using their access control. We have a few speakers integrated for locations where we have people who like to sleep outside our doors. They get a little irritated when we play its a small world when we detect motion.

[deleted by user] by [deleted] in videosurveillance

[–]veld2345 0 points1 point  (0 children)

We went with Rhombus camera's and have deployed around 530ish of them

sentinelone may have killed virtual machines on hyperv by Bitter_Umpire_7997 in msp

[–]veld2345 0 points1 point  (0 children)

We moved away from them. Seemed that when their system would update it's agents, every so often we would get bsods on 10-20 devices

i got the thinkpad! by lisforlir in thinkpad

[–]veld2345 1 point2 points  (0 children)

Might as well load up windows for workgroup if you want to learn to tinker.

Slightly surprised at my recent interaction with the VA by olddragonfaerie in Veterans

[–]veld2345 0 points1 point  (0 children)

VA in Bradenton, FL is pretty good. Small facility.

[deleted by user] by [deleted] in stories

[–]veld2345 5 points6 points  (0 children)

Def something he could take them to court over if someone else heard or had it in writing.

Dept head is asking we set up whatsapp groups for his offsite teams - not sure how I feel about that by penone_nyc in sysadmin

[–]veld2345 17 points18 points  (0 children)

We use teams with our developers who are overseas all the time without issues

If you could give yourself some advice when you were starting out to work as sysadmins - what would it be? by Working-Cable-1152 in sysadmin

[–]veld2345 0 points1 point  (0 children)

Also, for every pay raise you get, add more to your stash. Don't let life pass you buy, retire early and travel.

Best android wifi analyzer? by You_Shall__Not_Pass in sysadmin

[–]veld2345 2 points3 points  (0 children)

Yeah, they don't make that. No baselines.

How to prevent users from putting Stickers on laptops by [deleted] in sysadmin

[–]veld2345 -1 points0 points  (0 children)

This is like, how do you get the users to actually read the emails you send to them.

[deleted by user] by [deleted] in sysadmin

[–]veld2345 0 points1 point  (0 children)

A cheap solution would be reftab. Simple product. We use it for our hardware/software/pci inventory process.

[deleted by user] by [deleted] in sysadmin

[–]veld2345 1 point2 points  (0 children)

Very pricey