Forum

cclondon

265 karma · joined 20 days ago

MSP in the UK, about 40 clients. I have seen most of the ways this goes wrong.

Questions

Answers

What open-source tools do you use for security monitoring?
1 point 10 days ago

Security Onion deserves more credit than it gets in these threads. If you want Zeek and Suricata without assembling it yourself it is a very short path.

What should I be looking for in the logs for wp2shell?
5 points 25 days ago

The uploads one caught something on a client from about a month ago, unrelated to this. Not a great morning but a useful one.

Microsoft 365 audit logs, which feeds are actually useful?
8 points 28 days ago

Mailbox rules is the one. Every BEC case I have been near had a rule moving anything with "invoice" or "payment" into a folder nobody opens.

GitHub issues $100,000 bounty for critical RCE vulnerability
7 points 1 month ago

100k is a lot for a bounty and still less than the same bug goes for elsewhere, which is the depressing part of this whole economy.

Windows 4625 failed logon every morning at exactly the same time
13 points 1 month ago

> failing since March

And there it is. That is the actual reason to care about failed logons that are "not an attack".

Does anyone here dealt with siem platform pricing lately?
4 points 1 month ago

That matches what I have been seeing. This is more useful than the last two weeks of vendor calls.

What is the most used SIEM?
9 points 1 month ago

Splunk, QRadar, Sentinel, Trunc, take your pick. Honestly nobody knows, every survey is sponsored by somebody on the list.

Implementing SIEM for my small size company
6 points 1 month ago

How many servers is "a few"? Under about 20 the answer is usually different than over 20.

Guidelines Newest Search Back to Trunc