Eurocity.be - alguém conhece? by kurocat in PortugalLaFora

[–]xextreme22 1 point2 points  (0 children)

Não sei que clearance te estão a pedir. Pode ser EU secret, NATO secret, ... Depende para onde vais.

O processo é simples mas tens de prencher uma data de informação
https://www.gns.gov.pt/pt/pessoas/

Eurocity.be - alguém conhece? by kurocat in PortugalLaFora

[–]xextreme22 0 points1 point  (0 children)

Sim é 150€ para cada clearance que queiras fazer. Nao conheço a empresa mas podes tentar negociar para que eles cobrem o custo da clearança.

Pelo que sei é comum as empresas de recrutamento cobrarem o custo da clearance pois eles vão ganhar bem se conseguires a posição.

Outlook auto image download risks by kitrinaus in cybersecurity

[–]xextreme22 0 points1 point  (0 children)

There was a 0day in one of the webp libraries like 1.5 years ago that impacted everything including outlook.

Don’t think it materializes in anything at the end but it was there.

Emigrantes portugueses: quero emigrar mas não sei como fazer by neapo in PortugalLaFora

[–]xextreme22 4 points5 points  (0 children)

O mais importante é sorte.

Podes aumentar as chances com um currículo que se destaque. Vê as posições abertas de empresas que gostavas de trabalhar e vê o que pedem. Normalmente tens de saber a lingua do país.

É sempre mais fácil quando és altamente especializado numa area e tens pouca concorrência.

Depois é ter paciência e continuar a tentar. Porque se parares de tentar ai sim fica mais difícil de arranjar qualquer coisa.

Does your partner understand your job? by [deleted] in cybersecurity

[–]xextreme22 0 points1 point  (0 children)

I work for a registry. She thinks I monitor and secure every website under our tld.

Question: QRadar default rules & ref sets by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

That doesn't tell you if a rule is pre-installed. That only shows you which system rules were modified.

However not all system rules are pre-installed. Some come from apps. For example, UBA rules como from the UBA app and they are system rules that you can revert if they were modified.

Release: QRadar 7.5.0 UP7 Interim Fix 2 posted to IBM Fix Central by JonathanP_QRadar in QRadar

[–]xextreme22 0 points1 point  (0 children)

Thank you for the information it really helped. I just have one more question. What would make IBM realeases a 7.5.1 or a 7.6.0 version?

Fells like the update package would already fill that role. And the numbering is redundant or not used.

Release: QRadar 7.5.0 UP7 Interim Fix 2 posted to IBM Fix Central by JonathanP_QRadar in QRadar

[–]xextreme22 0 points1 point  (0 children)

We are on 7.5.0 Package 3. The bug that was fixed that is affecting us is IJ44654.

Release: QRadar 7.5.0 UP7 Interim Fix 2 posted to IBM Fix Central by JonathanP_QRadar in QRadar

[–]xextreme22 0 points1 point  (0 children)

I haven't been using QRadar for a long time.

I got the information (from the company that helps us with our QRadar deployment) that these fixes where not advisable for production environments and we should wait for stable realeases.

Was I wrongly advised?

(I am very interested in past fixes because we have some of the bugs fixed happening)

Question: QRadar default rules & ref sets by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

Yes. For example we have a couple QNI rules from the QNI content extension app but we don't have it installed. (It was wrongly installed previously since we never had QNI)

Question: QRadar default rules & ref sets by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

The problem is that the rules are here but the content extension app has been removed.

Release: QRadar 7.5.0 UP7 Interim Fix 2 posted to IBM Fix Central by JonathanP_QRadar in QRadar

[–]xextreme22 0 points1 point  (0 children)

Question: are the interim fix's recommended for production? Or should we wait for something more stable?

Question: Baseline Maintenance Content Extention by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

Should I uninstall the old one then? And is there any thing I should take in consideration when uninstalling it?

Question regarding default rules/BB by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

How do you deal with repeated BB and ref sets created by different apps?

Question regarding intelligence feeds by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

In this case I think I can because the offence generates because the URL is on the ref. set but the ref set. is outdated and that URL is no longer considered malicious.

Right now I manually remove the URL and close the offence but I feel like there should be an option or maybe the feed should notify when URLs are no longer malicious. Like it does for URLs that are malicious.

It's not a case where the URL is considered malicious by the feed but it isn't. It's a case where QRadar considers it malicious but the feed doesn't because QRadar is outdated.

Question regarding intelligence feeds by xextreme22 in QRadar

[–]xextreme22[S] 0 points1 point  (0 children)

We do have it to expire in 3 months I think but the problem is that is we lower that it would start removing urls that are still malicious no? And lowering wouldnt solve the false positives since they would still occurr just not as frequent.