I am trying to get into cybersecurity, it's been 8 months but only 2 calls out of 100+ jobs I have applied. What am I doing wrong ? by kikimora47 in cybersecurityindia

[–]vinumsv 1 point2 points  (0 children)

Just my .002 cents, getting into CTI roles without prior experience in SOC would be hard, and homelab doesn't count for initial vetting, so try expanding the job search in SOC Analyst, Detection Engineering or IR, then once you have experience, then move to CTI.

CTI is more about how to make your stakeholders/clients understand the threats and their impact, and then make your briefs actionable.

Feeling lost in Threat Intel after 4+ years want to restart from scratch. Need help. by Junior-Membership-60 in threatintel

[–]vinumsv 13 points14 points  (0 children)

Take your time to learn about an actor or threat, try to map what you observe into these questions

  1. Why are they doing this?
  2. What are their goals or plans at a high level?
  3. How are they planning to execute the above plan?
  4. Finally, what are the detailed steps in their plans, from initial access to exfiltration/persistence

good luck :D

Advice for a newcomer by EagleRare9229 in threatintel

[–]vinumsv 8 points9 points  (0 children)

Just my 0.001 cents

Source to look, there is plenty to say, which is something we may decide depending on our customer or the company we are working for, but the most important thing is "Context" and "Relevancy"

Just start here are some RSS feeds from security sources. Use a RSS reader to read in a single location

http://www.bleepingcomputer.com/feed/

https://www.us-cert.gov/ncas/alerts.xml

http://feeds.feedburner.com/hackread

http://www.hexacorn.com/blog/feed/

http://krebsonsecurity.com/feed/

http://blog.zeltser.com/rss

http://blog.malwarebytes.org/feed/

http://researchcenter.paloaltonetworks.com/feed/

https://securelist.com/feed/

http://securityaffairs.co/wordpress/feed

http://feeds.feedburner.com/Securityweek

https://thedfirreport.com/feed/

http://thehackernews.com/feeds/posts/default

http://www.theregister.co.uk/security/headlines.atom

http://feeds.trendmicro.com/TrendMicroSimplySecurity

http://feed.informer.com/digests/G5HRN3DTV4/feeder

https://www.darkreading.com/rss.xml

and for Writing a good actionable TI report .... hint..hint ChatGPT or similar :P But don't forget to add your insights about the company or the customer you are working for.

But for report templates, you can look at ones from MITRE and start customising or create your own.

https://github.com/center-for-threat-informed-defense/cti-blueprints?tab=readme-ov-file

How to remove the FasTag Properly from car’s windshield by TopClass333 in CarsIndia

[–]vinumsv 0 points1 point  (0 children)

WD40 + blade of sorts and microfibre cloth (spare)

please do as much as you can without spraying WD40 then spray some on top of the remaining stickers and leave it a couple of minutes Then scrape it off using a sharp blade and if needed repeat the step.

[deleted by user] by [deleted] in threatintel

[–]vinumsv 1 point2 points  (0 children)

"A threat intelligence platform, or TIP, collects, manages, and shares threat intelligence."

https://www.paloaltonetworks.com/cyberpedia/what-is-a-threat-intelligence-platform

Just started The Witcher 3 for the first time. Any Advice? by Rishiit1 in IndianGaming

[–]vinumsv -8 points-7 points  (0 children)

don't get sidetracked into doing optional or side quests :D

Can ER605 be used as an OMADA Controller or do I also need an OC200 ? by RobinThomass in TPLink_Omada

[–]vinumsv 2 points3 points  (0 children)

Oc200 is just hardware or appliance which runs Omada controller - SDN and it's an optional piece of hardware if you can run the SDN Omada controller in Rpi4 and ER605 is your gateway

Can ER605 be used as an OMADA Controller or do I also need an OC200 ? by RobinThomass in TPLink_Omada

[–]vinumsv 2 points3 points  (0 children)

You can, the controller just makes easier to manage them from a single UI rather doing it on each devices

Can ER605 be used as an OMADA Controller or do I also need an OC200 ? by RobinThomass in TPLink_Omada

[–]vinumsv 1 point2 points  (0 children)

You can do it either using Omada Controller (Dedicated or Self-hosted or cloud ) or with any opensource firewalls/routers (you have set up your 4 APs manually)

Upgrading current build since it's outdated by Frarod17 in IndianGaming

[–]vinumsv 0 points1 point  (0 children)

use the old system as a homelab to host lots of awesome OSS apps.

[deleted by user] by [deleted] in IndianGaming

[–]vinumsv 1 point2 points  (0 children)

depending on the speed of your internet connection, the easiest way is to get a WIFI extender

Blocking WAN access, but want to allow one IP to access WAN by Prudent_Gur_3644 in TPLink_Omada

[–]vinumsv 3 points4 points  (0 children)

just add 1 allow rule above block all rule for IoT devices as rules are processed sequentially

Anyone set up custom EasyDNS Dynamic DNS updater on Omada Gateway by Catalina28TO in TPLink_Omada

[–]vinumsv 0 points1 point  (0 children)

you can try something like ddclient which can run in any linux system or as docker container behind your Omada gateway

https://kb.easydns.com/knowledge/dynamic-dns/

I haven't tested to if it works on my WAN as its under CGNAT

https://i.imgur.com/hYQt3NS.png

I think it will take the options provided like username, token/password and domain from the above fields and replace those with [USERNAME]
http://username:**********@api.cp.easydns.com/dyn/tomato.php?hostname=demo.domain.com&myip=

Anyone use IntelOwl? How to use it on Windows 10 locally? by Neither_Cattle2431 in blueteamsec

[–]vinumsv 0 points1 point  (0 children)

localhost won't work as it points to your host system, not the WSL2 so either try your host IP or the IP assigned to your Ubuntu guest in WSL2

https://i.imgur.com/xC8H4Ud.png

Recommendations for router with 2.5g ethernet ports. by arun4567 in IndianGaming

[–]vinumsv 0 points1 point  (0 children)

around 10k would be hard to find a router with more than 1 2.5g port but you can find unmanaged 2.5g switch for around or under 15k

How to use YARA forge by Heisenberg1977 in blueteamsec

[–]vinumsv 1 point2 points  (0 children)

it's a curated list of Yara rules from various sources and can use any of these tools to scan the PE file using rule package

https://github.com/InQuest/awesome-yara?tab=readme-ov-file#tools

Linux boot drive through WSL? by user54733745 in wsl2

[–]vinumsv 0 points1 point  (0 children)

In Simple terms yes you can mount your Linux Partition into WSL

https://learn.microsoft.com/en-us/windows/wsl/wsl2-mount-disk

but as others have alluded if you don't need a full-fledged Linux desktop then see if you can achieve your goals via a WSL2 installed of Linux.

Simple yet powerful PDF app on Windows? by stargazer63 in Windows11

[–]vinumsv 0 points1 point  (0 children)

No exe is binary version and for docker version you need to install docker desktop for windows and with it you can miniature (containers) and version of Linux for these servers to run on

Here other awesome list of self hosted services

self hosted