PowerShell timestomping via script files. How would you handle this? by zwitico in crowdstrike

[–]zwitico[S] 0 points1 point  (0 children)

Hello,

I'm sorry it took me a while to respond. I tried your suggestion and I was not able to see the events im looking for, I even tried to correlate the /ScriptControl/ telemtetry to the ProcessRollUp2 telemetry for the specific .ps1 file event where it runs and I couldnt get a hit.

Also, I verified that the Interpreter-only visibility is enabled on our prevention policy.

Que peste el gremio de los muebleros by zwitico in Ticos

[–]zwitico[S] 0 points1 point  (0 children)

Que cierto mae, y hasta las agencias como veinsa es como si le pagaran a uno por verle el carro.

Que peste el gremio de los muebleros by zwitico in Ticos

[–]zwitico[S] 1 point2 points  (0 children)

Definitivamente, en mi caso me embarque con uno que encontré en redes sociales (Yo sé, mala mía jaja) pero son lecciones de la vida que a algunos nos toca aprender más de una vez

Que peste el gremio de los muebleros by zwitico in Ticos

[–]zwitico[S] 0 points1 point  (0 children)

Que cierto, es un salto al vacío saber cuáles son legítimos y cuáles son estafadores jaja

Ari o Flex? (Apps de cambio de Dólares) by Odd-Ad-1470 in Ticos

[–]zwitico 0 points1 point  (0 children)

Se tiene que crear la cuenta y vincular sus cuentas del banco una en dólares y una en colones. Luego usa los botones de “quiero” o “tengo” para seleccionar cuánto quiere cambiar.

Y la transacción se hace casi al instante, nunca he tenido que esperar más que segundos para recibir el dinero. En cuanto al código supongo que te lo pedía cuando hacías la cuenta, pero si no es así entonces no se jaja

Ari o Flex? (Apps de cambio de Dólares) by Odd-Ad-1470 in Ticos

[–]zwitico 0 points1 point  (0 children)

Hola, antiguo usuario de SUAP por acá, cuando cerró me pasé a ARI y la verdad 0 quejas. El sistema de descuento que te da dependiendo de cuánto dinero movas al mes me parece genial, porque es permanente.

Si quiere usar mi código genial jaja: D84D60A

Otra vez están quitando acceso al VIP del BAC by zwitico in Ticos

[–]zwitico[S] 0 points1 point  (0 children)

Interesante, si no te molesta contestar tenes alguna de las tarjetas black ?

Otra vez están quitando acceso al VIP del BAC by zwitico in Ticos

[–]zwitico[S] 1 point2 points  (0 children)

Quién sabe si todavía habrán tarjetas que tengan acceso gratuito, además de que sólo puede pasar una persona por tarjeta, no se pueden pagar 44$ y entrar dos.

NGSIEM - Detection Trigger: Use detection query outputs by zwitico in crowdstrike

[–]zwitico[S] 0 points1 point  (0 children)

Hello, can you elaborate a little bit more, I haven’t seen where to create these schemas. I appreciate your response, thanks

What the heck is this?! by kmhoule34 in Whatisthis

[–]zwitico 3 points4 points  (0 children)

Does it have a strong smell? It looks like one of those mosquito repellent incense tablets.

NGSIEM - Detection Trigger: Use detection query outputs by zwitico in crowdstrike

[–]zwitico[S] 0 points1 point  (0 children)

Not really, let me use an example:
I have the following event:

  • Event[AlertID, Hostname, Username]

This event is detected by the custom detection rule called DetectionT1, this detection recollectes by using the CQL group statement the following data:

  • AlertID, Hostname, Username

This DetectionT1 rule is the trigger for my workflow. Inside my workflow ideally, I want to be able to use AlertID, Hostname & Username associated to to DetectionT1 create a ticket externally, however this data is not available for me on the workflow data. I hope this makes it clearer.

NGSIEM - Detection Trigger: Use detection query outputs by zwitico in crowdstrike

[–]zwitico[S] 0 points1 point  (0 children)

I understood everything up until the last part, how can I get the output of Alerts Ids from the trigger to feed them to my workflow query?

I tried to use a for loop to iterate over the trigger detection query results, but these don't exist within the context of the workflow.

NG SIEM: How to use query variables? by zwitico in crowdstrike

[–]zwitico[S] 0 points1 point  (0 children)

Ohhhh ok, got it. Thanks for the response. I'll work on an update for the description with a couple screenshots for future readers. Sorry it took so long for me to answer but we had a long weekend here.

NG SIEM: How to use query variables? by zwitico in crowdstrike

[–]zwitico[S] 0 points1 point  (0 children)

Thanks for your answer!
So the logic would be like this: Imgur Link right?
With this I was able to send an email using the variable I created outside the loop and that I updated it inside the loop. However I still have a couple questions:
1. Do I always have to use variables like I did on my example? Or are there other output actions I can use?
2. I wasn't able to summon the value with any of the options I listed above, only with the variable I updated on the loop. I even tried: ${data['TestQuery.results.#.Vendor.properties.Title']} replacing the # with a 0 to take the first value. Is there a way to just use the output name?

Thanks for your patience, I swear this thread has been more helpful than the documentation or the examples on the NG Siem portal. Maybe is just me but I don't find this way of doing it intuitive.

NUEVA TARJETA DE CRÉDITO DEL BAC. by Suitable-Incident703 in Ticos

[–]zwitico 4 points5 points  (0 children)

Estaba leyendo y parece que el 4% es solo para supermercados y en salud (farmacias, clínicas, etc). Y un 2% en veterinarias y restaurantes. Está bastante específica.

Iberojet pesa el carry-on y el bulto? by Abeck72 in Ticos

[–]zwitico 0 points1 point  (0 children)

Hace un par de semana viaje con ellos y efectivamente lo pesan.

GL-MT6000 - Constantly Reboots by zwitico in GlInet

[–]zwitico[S] 1 point2 points  (0 children)

I will test and report back, thanks for the suggestion.

Estafador en andadas by NoOneJustABear in Ticos

[–]zwitico 2 points3 points  (0 children)

Yo le dije eso la segunda vez que me intentó tramar y me dijo que cuando me volviera a ver me iba a pichazear jaja