@chrissanders88 Finally, saw Rapid7's write up on the issue with actual IOCs so switched over to searching for those in the SIEM, but again, no hashes or network IOCs found during those time frames.
@chrissanders88 Second, found a couple of users that appeared to be redirected to a suspicious site, so reviewed logs again to try & find any files downloaded around those timestamps. After review, no downloads appeared related / suspicious.
@Tailscale got a typo on https://t.co/CxQVY8Ei7J page, Sec. 5 - UFW command to delete all old "22/tcp" rules - get a syntax error if you run "sudo ufw delete 22/tcp" - needs to be "sudo ufw delete allow 22/tcp". Let me know if there's a better way to submit?
With two days left, we just broke the 65K mark on our fundraiser, unlocking another 15K match. That's over 130K total raised for charity. Remarkable!
Our next goal is $75K, which is the BBQ tier! Will we make it?
Prize list and entry instructions here: https://t.co/UeVGrDd5rC
I had the opportunity to give back some #cybersecurity knowledge this year and wanted to share in case anyone else finds these useful. This first one is an intro to Network Security Monitoring (#NSM): https://t.co/46vq2gbZhf
Would love to be able to deliver these or similar talks elsewhere if anyone's interested. The next one I'm working on is using cybersecurity for your competitive advantage in business.
Peace ✌🏾: I'm a non-traditional, recent, Cybersecurity Grad who's been in #infosec since Backtrack R1. I have 10 consecutive yrs. combined infosec/IT and academic experience. My formal infosec experience is with @greyhatdev; since 2016. My remote dev role ended in Jan when -->>
Just passed the first quiz Current State Assessment, SOCs, and Security Architecture in @SANSInstitute SEC511: Continuous Monitoring and Security Operations (F01_05_HL_CM_7145) https://t.co/eJUXo7L9y3 🥳
Use case is multiple apps within same Kubernetes node reaching back to static infra in co-lo. Want to enforce segmentation for nodes to ensure they are only speaking to approved DBs, etc. Thanks!
Need help from #InfoSecTwitter - @IanColdwater@kelseyhightower - any resources you can point me to for securing cloud Kubernetes in hybrid environments with static infra? Looked at Cisco Tetration & Illumio but both don't (yet) control pod-to-pod comms within a single node.