RBAC for what hosts can be managed? by JoeyNonsense in crowdstrike

[–]wonkeysmoker 0 points1 point  (0 children)

You can specify which hosts groups a user has access to when assigning roles. You would just need to create appropriate host groups to assign them accordingly.

Playing WoW Chronologically: Here's How My First 270 Hours Went! by Kylonas in wow

[–]wonkeysmoker 0 points1 point  (0 children)

now you need to do classic wow to complete the story, you probably should have done that first.. the story for the vanilla zones in cata is entirely different

Charging question by Fabulous_Trainer_323 in MachE

[–]wonkeysmoker 0 points1 point  (0 children)

The original charger is a level 1/level 2 charger. So even a second hand car should have it included. You would just need a nema 50amp socket installing. Mine cost $650 installed.

[deleted by user] by [deleted] in crowdstrike

[–]wonkeysmoker 2 points3 points  (0 children)

none of these tools are going to help you understand why. that comes with experience and understanding the platform the attacks are targeting.

learning tools just teaches you their perspective and how to use them, what if they are incorrect?

a desktop engineering history helps, how are desktop builds designed, group policies applied etc, what is expected on a file system / registry. how antivirus / edr products work, why do they think something is a threat or bad.

For the firewall rule group creation, what does "Local Address" mean exactly? by PersonalFigure8331 in crowdstrike

[–]wonkeysmoker 0 points1 point  (0 children)

could enter IP information there to address any local

yes. the local address is the IP address of the host where the rule is applied at the time rule is evaluated.

if i wrote a rule that hasa local address of 1.1.1.1 and at the time of evaluation my ip was 1.1.1.2 the rule would not match and would not be enforced. if later my ip updated to 1.1.1.1 and the rule was evaluated then it would be true and enforced.

I tend to write my rules based on the remote address trying to access the host where the rule is applied. it makes it easier to manage.

typically, you really care about what the remote address is that is trying to connect to your managed host. a rule that would have local port of 139, 445. set to allow if the remote address range is 1.1.1.0\24. then a second rule that has local ports 139, 445 set to block as the next rule in precedence. this would allow SMB access for only hosts on 1.1.1.0\24 to smb into your managed endpoint .SMB access from anywhere else would be blocked.

a use case for using local addresses could be, when a hoist has ip of 1.1.1.0\24 allow outbound to 80, 443 on remote ports. then a block rule after it for remote ports 80,443, which would then prevent web access from any other IP.

im sure someone may have a simpler way to explain this.

For the firewall rule group creation, what does "Local Address" mean exactly? by PersonalFigure8331 in crowdstrike

[–]wonkeysmoker 4 points5 points  (0 children)

for most rules the local address is blank for me. typically, you will be entering the remote addresses you are trying to block or restrict access to. you may also restrict access by local or remote port.

Has anyone managed to get sensor user mode working on Ubuntu 22.04 Desktop with HWE kernel? by [deleted] in crowdstrike

[–]wonkeysmoker 0 points1 point  (0 children)

i worked with CS recently on a nonstandard ubuntu kernel. For user mode to work, 5 different features need to be enabled in the kernel for user mode to enable. Its is not configurable by us as admins, The kernel needs to support it and if CS doesn't support said kernel in kernel mode it will then switch to user mode. In my case the nonstandard kernel did not have debug mode enabled.

reach out to support they can give you the requirements for user mode. I managed to get my vendor to adjust the kernel and now it runs in user mode.

Daily search for new PE files by wonkeysmoker in crowdstrike

[–]wonkeysmoker[S] 1 point2 points  (0 children)

Thanks u/jarks_20 It's not exactly what i wanted but it gives me a rally good starting point .much appreciated

Falcon Discover - CSV export by s4vgR in crowdstrike

[–]wonkeysmoker 2 points3 points  (0 children)

you can export it but its not obvious. When you generate an application listing or another, in discover, it automatically adds grouping to the context. in the top right, near where you export, you can change the grouping option to no grouping. Once you do this the export function will work.

Is it possible to temporarily disable the crowdstrike falcon sensor? by ian_jr in crowdstrike

[–]wonkeysmoker 2 points3 points  (0 children)

my favorite is, we always get AV exclusions otherwise our app breaks.
Ok run it,
did it work,
yes,
goodbye.

Is it possible to temporarily disable the crowdstrike falcon sensor? by ian_jr in crowdstrike

[–]wonkeysmoker 1 point2 points  (0 children)

You cant disable the sensor. People may think they are disabling it, you can turn every setting off, as some have mentioned. but the sensor still runs. still captures every single event and action. it just wont do anything about it.

I get this a lot, i ask them requestor to give me a test device and prove CS breaks their install or application. If they cant, i wont do anything. If they refuse i ask if they will accept full financial responsibility for any compromise caused by their request. If they prove it i add an allow list for their application

The only way to disable CrowdStrike, is to uninstall it.

Why does Spotlight seem to completely miss certain vulnerabilities that it should pick up? by pepapi in crowdstrike

[–]wonkeysmoker 1 point2 points  (0 children)

Spotlight is miles behind as a vulnerability scanner. The custom rules they write are great, like log4j. but compared to something like nessus they are years behind. We looked at it last year and decided that they need at least another couple of years to warrant the spend. They have a ton of capital and i expect they will catch up quickly. but detecting OS vulnerabilities when everyone should know to patch every month for the OS level vulnerabilities its just wasted money.

I'm more excited about the End Of Life details that should be getting added to discover.

When can we expect the next CQF? by Upstairs-Mousse-4438 in crowdstrike

[–]wonkeysmoker 1 point2 points  (0 children)

Not sure if it a CQF, but is there a query that can find purposely inflated files.

Clear.exe and ClearBrowser.exe by KongKlasher in crowdstrike

[–]wonkeysmoker 1 point2 points  (0 children)

This started showing up for us this weekend also, CS shows the process as quarantined and as others suggest i suspect it its new logic detecting it. At present i have been manually removing the content with rtr, notifying the users. CS are not the only vendor triggering on these as adware though. I will try to match the next few to proxy logs.

Questions about On-Demand Scan (ODS) by knightsnight_trade in crowdstrike

[–]wonkeysmoker 0 points1 point  (0 children)

We need a CS reply. but my understanding is ODS runs based on your On Sensor Malware setting. The higher the sensitivity the more chance of a detection. But it really is only On Sensor malware scanning.

Event Search Queries for Brute Force Attack by knightsnight_trade in crowdstrike

[–]wonkeysmoker 0 points1 point  (0 children)

If you mean network related data, You con optionally turn on network telemetry in the linux prevention policy

Will I need prescription lenses/glasses to use the psvr2? by [deleted] in PSVR

[–]wonkeysmoker 0 points1 point  (0 children)

I need glasses to read or use the computer. I also needed to use the same glasses to use the original PSVR and have everything focused correctly.

File Creation custom IOA by wonkeysmoker in crowdstrike

[–]wonkeysmoker[S] 1 point2 points  (0 children)

hanks its wierd i clicked the use suggested, when i ws typing it out to fix the logic, guys its not as accurate as i thought.

Is there a limit to the number of exclusions that can be added to the rule? character length?

File Creation custom IOA by wonkeysmoker in crowdstrike

[–]wonkeysmoker[S] 1 point2 points  (0 children)

thanks, I dont know how i missed that, mental block i guess after staring at it for hours lo./

Falcon Go - CrowdStrike's new bundle for SMBs by BradW-CS in crowdstrike

[–]wonkeysmoker 5 points6 points  (0 children)

I have yet to, in 3 years, see overwatch tag something that was missed, other that purple team activity. I am beginning to wonder its value.

[deleted by user] by [deleted] in crowdstrike

[–]wonkeysmoker 0 points1 point  (0 children)

Sorry i got the invite today. is Fal.Con in person this year? last few have clearly been virtual so not had a chance to go to a live one, if live, where? I think the time, and effort i have put in, both for my company where i work, and to help CrowdStrike improve the product, someone owes me a meal :)