how2itsec
Pages
(Move to ...)
Home
▼
(Move to ...)
Startseite
▼
Nextcloud VM updater shows permissions error
›
When trying to update your Nextcloud VM using the updater in the GUI the following error might be shown: Check for write permission...
PIP in Anaconda3 on Windows for Python
›
If you are using Anaconda3 on Windows for python development you may want to know, which version of pip is installed: Start Anaconda Shell (...
How to increase IT security of a company using quick wins
›
How to increase my companys IT security? Of course there are many, many, many topics, processes, systems, parameters, awareness and a lot mo...
Example of Spear Phishing Attack in detail
›
The McAfee blog released an article about how a current spear phishing attack (T1566) looks like in detail: (Picture from McAfee Blog ) Mo...
Windows file or folder in use - cant be deleted or modified
›
When trying to delete files or folders, clean malware, or just modify something on your Windows system, windows won't let you, because t...
FortiAnalyzer reports - how to group subdomains to only show the root domain
›
Most Fortinet FortiAnalyzer reports use the full domain including subdomains, e.g. www.google.com or maps.google.com. If you want to group s...
Debugging PRTG Enterprise Console Remover
›
Paessler just released for PRTG a remover for the deprecated Enterprise Console: PRTG Enterprise Console Remover.exe: You can uninstall sta...
Restore CHK files
›
I just had to restore many broken CHK files of a SD card from a hidden FOUND.000 folder. The program "unchk.exe" helped me: ...
Account Lockout Policy - A possible threat
›
Most companys use an account lockout policy for their directory service like Microsoft Active Directory, LDAP-system, eDirectory or their ow...
Windows 10 Core Isolation deactivation via registry
›
You can deactivate the Windows 10 Core Isolation function by changing the following Registry Key and therefore do "Tampering with Windo...
OS Credential Dumping - Att&ck T1003
›
Some places to start to monitor (e.g. for unexpected processes interacting with one of the following), collector forensics and try to protec...
SIEM IoC regsvr32.exe outbound network connection
›
An easy to find possible indicator of compromise (IoC) for your SIEM, AEP or EDR could be a outbound network connection from Windows own reg...
Sysmon 11 released
›
Many SIEM installations use sysinternals sysmon as one of many data sources. Mark Russinovich (Microsoft Azure CTO, co-creator of sysintern...
Geographically redundant datacenters - their performance issues and designs solutions
›
Performance problem - Distance and Latency More and more companys face the challenging requirement to provide available services, which su...
List FortiGate Certificates via CLI - CA certificates and local Certificates
›
You can either use the GUI of the FortiGate to list all certificates, or use the CLI. Either using the commands: Using the "get...
VMWare ESXi VM CPU Performance Over Commitment "CPU Stuck"
›
Many VMWare ESXi installations make the same mistake: They overcommit vCPUs, don't monitor CPU metrics like %RDY, %CSTP and don't kn...
Small/Medium Businesses - New network devices (switches, routers,..) - Minimum ToDo list
›
Most small/medium businesses don't do much configuration, monitoring, cfg-baselineing or follow best practises with their network device...
FortiGate allows Ping from "not trusted hosts" since FortiOS 6.0
›
Recently I discovered something after updating a FortiGate cluster, which I intensively monitor, not only via working monitoring queries, bu...
1 comment:
Advanced Endpoint Protection Testing from MITRE using ATT&CK
›
If you are searching for test results about current Advanced Endpoint Protection/Endpoint Detection and Response tools: MITRE is transparent...
1 comment:
Solution for Skybox connection issue to Fortinet FortiGate or FortiManager
›
If you are using the Skybox ( https://www.skyboxsecurity.com/ ) solution for your environment, during the initial setup there might be an is...
Malware using PowerShell - PowerShell Logging "Script Block Logging"
›
More and more so called "fileless malware" uses powershell in order to execute malicious actions. In order to find possible malici...
Use OpenSSL to decrypt private key
›
Use OpenSSL to decrypt private key openssl rsa -in *encrypted-key-file* -out *decrypted-key-file* Example: Encrypted private key file:...
‹
›
Home
View web version