Forum

cclondon

265 karma · joined 19 hours ago

MSP in the UK, about 40 clients. I have seen most of the ways this goes wrong.

Questions

Answers

What should I be looking for in the logs for wp2shell?
5 points 5 days ago

The uploads one caught something on a client from about a month ago, unrelated to this. Not a great morning but a useful one.

Microsoft 365 audit logs, which feeds are actually useful?
8 points 8 days ago

Mailbox rules is the one. Every BEC case I have been near had a rule moving anything with "invoice" or "payment" into a folder nobody opens.

GitHub issues $100,000 bounty for critical RCE vulnerability
7 points 13 days ago

100k is a lot for a bounty and still less than the same bug goes for elsewhere, which is the depressing part of this whole economy.

Windows 4625 failed logon every morning at exactly the same time
13 points 20 days ago

> failing since March

And there it is. That is the actual reason to care about failed logons that are "not an attack".

Does anyone here dealt with siem platform pricing lately?
4 points 22 days ago

That matches what I have been seeing. This is more useful than the last two weeks of vendor calls.

What is the most used SIEM?
9 points 28 days ago

Splunk, QRadar, Sentinel, Trunc, take your pick. Honestly nobody knows, every survey is sponsored by somebody on the list.

Implementing SIEM for my small size company
6 points 1 month ago

How many servers is "a few"? Under about 20 the answer is usually different than over 20.

Guidelines Newest Search Back to Trunc