Forum
Top
Newest
Ask
Search
Sign in
Top
Newest
All time
1
▲
CISA advisories page, worth having in your feed reader
(cisa.gov)
1 point by
shadepl
6 days ago
·
answer
2
▲
Getting a lot of 4771 Kerberos pre-authentication failed, should I worry?
3 points by
a8hda
7 days ago
·
answer
3
▲
What does a good log review actually look like on paper?
3 points by
gerald
(Gerald)
8 days ago
·
answer
4
▲
Best way to handle logs from client sites you do not control?
4 points by
cclondon
11 days ago
·
answer
5
▲
Finding Hidden Internal Apps Through Public Certificate Logs
(naveensrinivasan.com)
4 points by
dcid
(Daniel)
16 days ago
·
answer
6
▲
sshd is logging the key fingerprint but not which user it belongs to
2 points by
shadepl
17 days ago
·
answer
7
▲
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
(lavahq.io)
2 points by
dcid
(Daniel)
17 days ago
·
answer
8
▲
Anyone actually reading their logs daily, or is it all alerts?
3 points by
mbxsec
18 days ago
·
1 answer
9
▲
Tailscale found a 16yo bug in SQLite which was the cause of its outages.
(tailscale.com)
3 points by
dcid
(Daniel)
21 days ago
·
answer
10
▲
How do I prove a log was not tampered with, months later?
5 points by
a8hda
22 days ago
·
1 answer
11
▲
Do I need to log who read the logs?
7 points by
tony
(Tony)
22 days ago
·
2 answers
12
▲
Why are my syslog messages truncated at 1024 characters?
8 points by
palegreen
23 days ago
·
1 answer
13
▲
How do you tell a real Googlebot from something pretending to be one?
7 points by
vivida
(David)
23 days ago
·
1 answer
14
▲
Azure sign-in logs showing countries nobody in the company has visited
8 points by
shadepl
24 days ago
·
1 answer
15
▲
Is TLS for syslog worth it on an internal network?
7 points by
rk_ops
24 days ago
·
1 answer
16
▲
How do I stop one broken app from eating all my log storage?
11 points by
aklaha
25 days ago
·
2 answers
17
▲
Sophos XG wireless protection logs, thousands a day, any value?
6 points by
a8hda
25 days ago
·
1 answer
18
▲
Agent based or agentless collection at 200 servers?
8 points by
mbxsec
26 days ago
·
3 answers
19
▲
What should I be looking for in the logs for wp2shell?
14 points by
cclondon
26 days ago
·
3 answers
20
▲
wp2shell: pre-authentication RCE in WordPress core
(wp2shell.com)
18 points by
dcid
(Daniel)
26 days ago
·
answer
21
▲
Sensible brute force threshold before alerting?
7 points by
hgunter
28 days ago
·
2 answers
22
▲
Event 1102, the audit log was cleared. How seriously should I take this?
13 points by
gerald
(Gerald)
28 days ago
·
2 answers
23
▲
Microsoft 365 audit logs, which feeds are actually useful?
10 points by
vivida
(David)
29 days ago
·
2 answers
24
▲
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
(slcyber.io)
21 points by
shadepl
29 days ago
·
2 answers
25
▲
Is it worth normalising logs to ECS or OCSF?
9 points by
aklaha
1 month ago
·
2 answers
26
▲
PCI 10.7, detecting failures of security controls. What does an assessor want to see?
15 points by
tony
(Tony)
1 month ago
·
2 answers
27
▲
Logon Type 3 is flooding my logs, can I filter it out?
10 points by
a8hda
1 month ago
·
1 answer
28
▲
Everyone ignores our alerts. How do we fix that without turning them all off?
24 points by
cclondon
1 month ago
·
4 answers
29
▲
What does srccountry="Reserved" mean in a FortiGate log?
7 points by
indyp
1 month ago
·
2 answers
30
▲
GitHub issues $100,000 bounty for critical RCE vulnerability
(runtimewire.com)
18 points by
dcid
(Daniel)
1 month ago
·
1 answer
More
Guidelines
Newest
Search
Back to Trunc