lil_lost · @lil_lost
639 followers · 1200 posts · Server infosec.exchange

Say you have a well managed SIEM and a functional SOAR but with few integrations at this time. What open source tools or tools from potential existing products would you build or like to have to let you SOC be more efficient?

#soc #soclife

Last updated 3 years ago

Axi0kers0s 👾 · @axi0kers0s
81 followers · 456 posts · Server infosec.exchange

I can see alerts popping like mushrooms ... Let me finish my coffee 🤣 mortacci vostri ...

#soclife #securityoperationscentre

Last updated 3 years ago

Axi0kers0s 👾 · @axi0kers0s
68 followers · 364 posts · Server infosec.exchange
Axi0kers0s 👾 · @axi0kers0s
63 followers · 335 posts · Server infosec.exchange

My face when a specific connector hasn't been connected/set properly ...

#soclife

Last updated 3 years ago

Axi0kers0s 👾 · @axi0kers0s
21 followers · 69 posts · Server infosec.exchange

Friday on SOC duty, shift is almost over with the other lot starting soon. It was a relatively quiet and enjoyable day ... But I know that the system knows I am about to finish, and I know that the system is ready to swamp me with alerts 15 minutes before I finish, as it does normally ... So please system hold on until five past ... Please

#blueteam #securityoperationscentre #soclife

Last updated 3 years ago

Syfur ♂️ · @syfur
46 followers · 82 posts · Server defcon.social

I mean, this shows fantastic leadership. He convinced almost an entire shift of 7 analysts to say, "fuck your end-of-year bonuses."

When you can convince those under your leadership to forgo extra pay just to "stick it to the man," you've got leadership skills.

Misguided, but skilled.

#soclife #leadership

Last updated 3 years ago

Syfur ♂️ · @syfur
45 followers · 81 posts · Server defcon.social

Well, any advice from SOC leadership on what to do when a shift manager convinces almost an entire shift to invalidate that shift's end-of-year employee reviews by having them all enter the same low review score in each category for each other (all but one obeyed)?

#soclife #socleadership #leadershiptip

Last updated 3 years ago

Syfur ♂️ · @syfur
45 followers · 80 posts · Server defcon.social

My stress levels at work, today.

#socdirector #soclife #deadlines

Last updated 3 years ago

Syfur ♂️ · @syfur
45 followers · 78 posts · Server defcon.social

Y'all...

Just discovered an alert from mid-September with the following PS command...

powershell.exe -Command Add-MpPreference -ExclusionPath 'C:\Users\username*'

where 'username' is the real username.

WTAF...
Now usernameImAThreatActor has all of their files excluded from Defender scans...

The analyst closed it as "file was not infected."

#soclife #blueteam #screamingintothevoid

Last updated 3 years ago

Syfur ♂️ · @syfur
34 followers · 57 posts · Server defcon.social

When you're called at 5:30am on a Sunday because there's been active alerting on a host for RDP to foreign IP addresses (yes, plural), and the activity was basically ignored for 13 hours, overnight...

Calling the customer's CISO so they can get an immediate response kicked off is not how I like to start my Sunday.

Finding out two shifts passed on escalating this activity is also awful, and I'll be addressing that tomorrow, while I try to reclaim my weekend morning.

#soclife

Last updated 3 years ago

chris!:unverified:​ · @burritosec
150 followers · 139 posts · Server infosec.exchange

When the WHOIS privacy setting points to Panama, your only option is to send the analyst a link to the accompanying Van Halen song during report review.

#music #infosec #soclife

Last updated 3 years ago

DarkCyberMan · @darkcyberman
9 followers · 57 posts · Server nerdculture.de

Advanced hunting in ms defender still going slow or not at all.

#soclife

Last updated 3 years ago

MikeofMany · @mikeofmany
15 followers · 204 posts · Server wandering.shop

Sometimes I am in awe and hate how much other groups can leapfrog ahead of what I'm getting to do just cause they get to design their own strategy.

#soclife #blueteaming

Last updated 6 years ago