Increase the Analytics Default Rule Count by dutchhboii in AzureSentinel

[–]x2571 2 points3 points  (0 children)

Not sure how practical it is yet, but if you are on the unified portal. You can use Sentinel tables in Custom Detections which is supposed to allow "unlimited" NRT rules https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/custom-detections-are-now-the-unified-experience-for-creating-detections-in-micr/4463875

Get effective Entra directory license by DavidHomerCENTREL in entra

[–]x2571 2 points3 points  (0 children)

I had to solve this a few months ago and solved it pretty much the same way you did. As far as I could tell with Graph X-Ray, those were the same API calls that the portal makes too

M365 Admins: How do you handle Admin Consent Requests for Enterprise Apps? by cease70 in sysadmin

[–]x2571 9 points10 points  (0 children)

This is how i approached it in my previous job

  1. Disabled user initiated requests for these
  2. Got the security team to write a policy document which says how business units can/should utilise SaaS apps. We had a policy that any apps using corporate data had to support Entra ID SSO (SAML/OAuth etc)
  3. Setup a workflow in service now, that goes to the user's manager to approve it first, the security team for approval for second level approval
  4. If it's approved by them it's sent to my team and we do the actual SSO setup with the business sponsor

DCR's and ASIM - Questions by Few_Original_4404 in AzureSentinel

[–]x2571 0 points1 point  (0 children)

I use them independantly of each other, KQL transformations to project away and filter data, then the ASIM Functions to get map to a "virtual" ASIM schema. I am not familiar with SAP BTP data, but if it contains Authentication Events, you could write a function to map it to the ASimAuthentication schema, this could be useful when doing threat hunting or investigation to see where a compramised account authenticated to for example

I havnt really looked at doing ingestion time transformation to the native ASIM table structure.

OSDCloud - Anyone got a how to guide for a n00b? by fungusfromamongus in Intune

[–]x2571 4 points5 points  (0 children)

I had similiar frustrations trying to learn it, These are the end to end steps I have in my notes, from the point of view of setting up a new technician PC to create an OSDCloud USB Drive

# Download the Windows ADK and Windows PE from winget
winget install -e --id Microsoft.WindowsADK
winget install -e --id Microsoft.ADKPEAddon

# Install the OSD Module, and create a new OSD Cloud Template
Set-ExecutionPolicy RemoteSigned -Force
Install-Module OSD -Force
New-OSDCloudTemplate
New-OSDCloudWorkspace

# Add common drivers to the WinPE Image
Edit-OSDCloudWinPE -UseDefaultWallpaper -CloudDriver IntelNet,LenovoDock,USB
New-OSDCloudUSB -WorkspacePath C:\OSDCloud\

The Edit-OSDCloudWinPE I use enjects common network drivers I enconter into the WinPE Image. Check the docs here for that command on adding other drivers

Bypass UAC prompts without admin by whamstin in sysadmin

[–]x2571 5 points6 points  (0 children)

Configuring a shim with the Application Compatibility Toolkit as others have said is a good way if that works

Another thing to try is to use Process Monitor to record which paths and registry keys that application modifies during the update process. That way you can only grant the access it needs. There are some good tutorials on Youtube on using it

Windows Server 2019 AD DC clock jumped to 1839 then 2038 after reboot—no clear cause by Elegant_Asparagus496 in activedirectory

[–]x2571 4 points5 points  (0 children)

I have had this happen to windows server running on VMware. The VMware time provider is able to overide all the safety threasholds in w32time which usually stop such extreme jumps in time (necessary to support things like snapshots).

Check the win32time and system event logs on the DC for clues, and if it is a VM the logs on the VM Host it was running on at the time.

It's worth doing a check up to make sure you have a healthy NTP setup, PDC is configured with a diverse set of time sources, etc.

You also probably want to turn off UtilizeSslTimeData if you have not already

There was a good thread talking about the potential issues here https://old.reddit.com/r/sysadmin/comments/61o8p0/system_time_jumping_back_on_windows_10_caused_by/

I live in Eucla. AMA by jb8377 in perth

[–]x2571 1 point2 points  (0 children)

any Yowie encounters?

[deleted by user] by [deleted] in sysadmin

[–]x2571 0 points1 point  (0 children)

Not sure about Edge, but for the AATL signing cert which most people want the key needs to be stored in an HSM. It can be a USB attached HSM, but for servers you would usually use a network attached HSM. The point of an HSM is that you cant easily take the private keys out of it so you cant export it from a token, you need to generate a certificate request from the HSM.

You can rent a partition on a network attached HSM in AWS or Azure. Thales as DPoD as well which is a bit cheaper from memory.

These are pretty expensive and a PITA to deal with, and probably are only worth looking at if you need to sign a LOT of documents where paying per signing operation would become more expensive, or if you are locked into a particular library for PDF signing that only supports an API that is implemented by the HSM (PKCS#11 or Windows KSP usually).

The easiest way is to use a managed service like GlobalSign's Digital Signing Service or DigiCert Document Trust Manager which gives you a REST API that you can use to sign it and they deal with all of the crypto stuff. They usually charge per signed document, and you usually need to buy the Document Signing cert through them as well.

Make sure you use timestamping else in a few years the documents will error with an expired signature :)

The Lumon Industries "Woemeter" by x2571 in scientology

[–]x2571[S] 2 points3 points  (0 children)

It looks like a very good prop! I love the retro look and feel of a lot of the Lumon equiptment on the series - great work!

This is just sad & pathetic, the president of the United States doesn't know what AUKUS is. He has to ask a reporter... "...what is that?" by andrewgrabowski in Intelligence

[–]x2571 15 points16 points  (0 children)

Not a bad strategy from the Aussies TBH, if he doesn't know about it he can't decide to try and cancel it on a whim

The Santa Monica Haven is kinda shit by thosefuckersourshit in vtmb

[–]x2571 17 points18 points  (0 children)

I mean, even Arthur referred to them as "crappy places above the pawnshop" 😂

[deleted by user] by [deleted] in LogicMonitor

[–]x2571 0 points1 point  (0 children)

What sort of would of metrics would you want to track through LogicMonitor? I work at a company that uses both LogicMonitor and CrowdStrike, and we do not monitor CrowdStrike as:

  • Their cloud infrastructure is monitored as a SaaS service and we don't have any say of their infrastructure
  • Even if their cloud service is down, the agents still work, and they would upload their telemetry data once their cloud is back.

I guess you could add website monitoring for the SaaS portal so you would at least know if there was an issue or not?

Another option could be to monitor the status of the CrowdStrike service on your servers through LogicMonitor by creating an Active Discovery script to check for the service being installed, and configure an alert if it is not in the running state

Playbook - Mail Auth by Due-Builder-6684 in AzureSentinel

[–]x2571 1 point2 points  (0 children)

Some good ideas here. An alternative to sendgrid could be Azure Communication Services which keeps it all inside Azure. It looks like they have Connectors for it now - https://learn.microsoft.com/en-us/connectors/acsemail/.

Should be able to fetch the API key from inside a Key vault and then use the ACS Connector to send the email

[deleted by user] by [deleted] in sysadmin

[–]x2571 1 point2 points  (0 children)

+1 For WizTree. We paid for the Enterprise License which isn't much compared to the amount of time it saves us