IT Pro Tuesday #293

IT Pro Tuesday #293

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Insider Threats in Microsoft 365,” we focus on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

JA4+ Network Fingerprinting explains how to leverage the new modular network fingerprint methods that replaced the JA3 TLS standard, which can be useful in helping protect your network from threats. aygupt1822 explains, “These are TLS Fingerprinting tools which generate TLS Fingerprints from raw network packets.”

External Attack Surface Management Attack Surface Summary

Scripts

9 Essential PowerShell Scripts for SharePoint Online Security shares a set of curated, precision scripts for monitoring SharePoint online file activities, external user activities, and online permissions/access. Kindly suggested by Shan_1130.

External Attack Surface Management Attack Surface Summary

Security News

Critical Security Flaws within ChatGPT Ecosystem delves into the attack vector introduced by generative AI that can be exploited to compromise user accounts. ElectroPanic0 explains, “While the whole GenAI trend is great and lets employees/teams incorporate external AI tools in their code or daily tasks, the security falls behind.”

A Tip

jamesaepp shares a handy browser shortcut: 

CTRL + Shift + DEL in Chrome/Edge (maybe FF?) brings you to the clear cache dialog box

A Tutorial

How to Build a Custom MacOS Dock is a guide that walks you through how to create a purpose-built onboarding dock for your users. The method has been verified from Sonoma back through Catalina. Recommended by trikster_online, who says, “I have about 7 different docks I use depending on the lab.”

P.S. Bonus Free Tools

Git Commands Cheat Sheet is a nicely organized quick-reference guide where you can easily locate all the essentials for making the best use of Git. Appreciation for the suggestion goes to Extradiscipline_644.

Mimir is an open-source multi-tenant time series database that is a blazingly fast, scalable, high-availability solution for long-term storage for Prometheus. Our thanks for the recommendation go to bilbo-baggins125.

IT Pro Tuesday #293

IT Pro Tuesday #292

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Microsoft vs Midnight Blizzard,” we explore insider threats within M365 with special guest Philip Galea, R&D Manager at Hornetsecurity. The focus is on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

Fiber Cable Maintenance walks you through the proper cleaning procedures that will keep your fiber cable connections working at peak performance. Appreciation for this one goes to -sirKris-, who offers the reminder, “Keep your equipment clean!” 

External Attack Surface Management Attack Surface Summary

A Free Tool

Intunewin Build and Extract is a tool that allows you to either build a new Intune Win32 application or extract the content from one that already exists. The author has written detailed instructions in this blog post. Our thanks for the suggestion go to dcg1k.

External Attack Surface Management Attack Surface Summary

Training Resource

Coursera is an online learning platform with courses from top universities and industry leaders. The catalog of options is designed to provide self-paced training options to suit all skill levels. esgeeks explains, “offers free and paid courses on a wide variety of topics, including technology.”

Humor

In the runup to April Fool’s Day, we thought we’d share this diabolical-yet-harmless prank, compliments of laguna314…

“[W]hen people set their desktop to family photos or pet photos etc., I make many copies of the photo, and change a minor detail … with paint or photoshop; something small but noticeable like adding a mustache. Then I’ll set the background to point to an album of all the copies of the picture. Have it change at like 3-minute intervals so that at some point throughout the day, their background will show the mustache for 3 minutes.

Takes time for them to notice; and when they do, by they time they can point it out to someone, it’s gone!”

A Tip

This nice shortcut was offered courtesy of bobmonkey07: 

Win+pause opens “system” so you’re right where you need [to be] for changing computer name/domain.

P.S. Bonus Free Tools

Bash Cheatsheet is a quick-reference guide that can help you get started with Linux bash shell scripting. Kindly suggested by Extradiscipline_644.

Looking Glass is an easy-to-deploy PHP option that allows you to get network information by executing commands on the router and then gathering the output for the user. thegreattriscuit explains, “[it’s] the project behind equinix’s LG.”

IT Pro Tuesday #293

IT Pro Tuesday #291

Welcome back to IT Pro Tuesday!

In the latest monthly threat report on the Security Swarm Podcast: “Midnight Blizzard, AnyDesk Breach & a $27 Million Ransomware Attack,” Dr. Yvonne Bernard joins us for an in-depth analysis of major security breaches and ransomware attacks that occurred between January and February 2024.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tip

mmpre shares a helpful hint: 

“In notepad++, say you’re working on yaml and need to indent a ton of lines two spaces. Single click on the first line to get your cursor there. Hold down shift + ctrl + alt and single click on the last line.

It selects all of them, and you can do whatever you want to all of those lines at once.”

A Free Tool

PSDiscoveryProtocol allows you to capture and parse CDP and LLDP packets on local or remote computers as well as adding port information to the SCCM Hardware Inventory on Win10. Kindly recommended by Jebedia47

External Attack Surface Management Attack Surface Summary

Training Resource

Kevin Wallace Training, LLC  is a YouTube channel with hundreds of videos geared toward networking certification and career growth. The primary focus is on CompTIA and Cisco, ethical hacking, automation, and wireless. jack_hudson2001 appreciates it for learning about advanced networking.

Another Free Tool

Hyperglass is an open-source network looking glass that offers a faster, easier, more-secure way to provide unattended visibility into a network for customers, peers, and other network operators. sixbux found it “relatively easy to configure and deploy.”

A Script

Connect to All Microsoft 365 Services is a super-easy way to connect 9 essential M365 PowerShell modules. Author KavyaJune explains, “[it] effortlessly installs and connects to… Exchange Online, MS Graph, SharePoint PnP, MS Teams, Compliance Center, Azure AD, and more. The highlight? All this can be achieved with just a single cmdlet.”

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Sass Cheatsheet is a convenient resource that organizes the most-useful features of SASS in a handy, quick-reference format. Our appreciation for directing us to this one goes to Extradiscipline_644.

ASN Database is a fully searchable resource that provides in-depth insights into all ASNs, their announced prefixes, peer information, Internet Exchange (IX) memberships, and more. Author flems77 says, “[I] keep it updated continuously (24/7). Just did a count, and as of now, I see a total of 118.374 ASN’s—of which 82.163 are active (have peers and announce prefixes).”

IT Pro Tuesday #293

IT Pro Tuesday #290

Welcome back to IT Pro Tuesday!

In the latest episode of the Security Swarm Podcast: “Co-Pilot and Misconfigured Permissions – A Looming Threat?,” we explore Microsoft 365 Co-Pilot. This generative-AI tool is embedded within various M365 applications and can execute tasks across different software platforms in seconds. Tune in to learn about some surprising risks that can surface with this productivity powerhouse.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Free Tool

PowerCSR is a Powershell-based GUI that quickly generates a CSR and Private Key file using OpenSSL. Author ReproDev explains, “after banging my head against the wall quite a lot with the command line version freezing or just force closing, I created a tool in Powershell to create the initial CSR and a 2048-bit key… Enter your details for the domain, organisation and the rest, then click Generate CSR”
External Attack Surface Management Attack Surface Summary

A Tutorial

Using DHCP to Boot WDS to BIOS & UEFI with SCCM is a tutorial that walks you through a setup that allows the booting of both BIOS and UEFI machines from the same WDS environment. Covers DHCP Policies and Custom Vendor Classes. Thanks for directing us to this one go to Versed_Percepton.

Training Resource

edureka! is a educational YouTube channel loaded with both quick topical summaries as well as in-depth, instructor-led trainings that can bring you up to speed on a surprisingly broad array of tech subjects. Kindly suggested by Present-Chard.

A Tip

LordCorgo kindly shares the following: Windows 11 will also accept no@thankyou.com with any password as a bypass to their forced online Microsoft Account.

Another Training Resource

Microsoft Azure Administrator is a free, 96-hour course that teaches how to manage your Azure subscriptions, network traffic, and secure identities; administer infrastructure; configure virtual networking; connect Azure and on-prem sites; implement storage solutions, web apps, and containers; and more. Our thanks for this one go to Suspicious-Sky1085.

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Adagios is an intuitive, web-based configuration interface that hides some of the clutter associated with Nagios. It offers a rest interface for both status and config data as well a complete status interface that includes all features, which can be a nice alternative to the standard Nagios web interface. Appreciation for this recommendation goes to Supermop2000.

Vue.js Cheatsheet is a quick reference guide that consolidates the essentials for this open-source JavaScript framework for building user interfaces and single-page applications. You’ll find syntax and a few references that can help you work faster when you’re not super familiar with Vue.js. Kindly suggested by Extradiscipline_644.

IT Pro Tuesday #293

IT Pro Tuesday #289

Welcome back to IT Pro Tuesday!

In the latest episode of the Security Swarm Podcast: “The Dark Side of QR Codes,” you’ll hear about various ways that threat actors are exploiting QR codes and how this poses new cybersecurity challenges for organizations.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

Prometheus + Grafana + Loki in docker explains exactly how to set up comprehensive monitoring capabilities for your host and containers. Do_TheEvolution appreciates the overview on “how to deploy and use prometheus grafana and loki in docker to monitor metrics and logs and have push notifications using ntfy.”

A Tip

LordCorgo kindly shares the following: Windows 11 will also accept no@thankyou.com with any password as a bypass to their forced online Microsoft Account.

Training Resource

MyPlayHouse is a YouTube channel focused on the world of high-end enterprise equipment and IT ventures, as well as home-improvement projects that explore technology and sustainable living. tnskynyrd adds, “He’s over in Denmark (or around that area) and regularly messes around with enterprise equipment in his home lab trying out stuff. Some of his videos are about him working on random projects, but he also has a lot of videos where he’s doing troubleshooting with retired hardware he’s gotten, and sometimes he’ll show some newer servers and stuff that vendors will loan him.”

A Free Tool

OMNeT++ is a C++-based library designed for constructing network simulators, with a focus on modularity and extensibility. FalsePhoenix likes it for simulating a large number of simultaneous connections to wifi so you can make sure you won’t have problems during an event.

External Attack Surface Management Attack Surface Summary

Another Training Resource

Exercism is a free resource to help you develop your skills in any of 67 programming languages. Allows you to learn by doing, through thousands of fun coding exercises that build your understanding of concepts. HeligKo raves, “I can’t recommend anything more… for learning languages”

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

MediaWiki is wiki software that helps you collect and organize knowledge so it is readily available for your team. This powerful option is multilingual, extensible, customisable, and reliable. Recommended by therealmofbarbelo.

KeePassXC is an open-source, ad-free, tracker-free password manager that allows you to auto-fill the appropriate credentials into your favorite apps, so you don’t have to remember anything. draeath explains, “I prefer KeePassXC [to original version]. Generally looks and feels better for me, and it’s cross-platform without requiring Mono. Original used to run soooo slow (and look horrible) on a Linux workstation.”

IT Pro Tuesday #293

IT Pro Tuesday #288

Welcome back to IT Pro Tuesday!

In the latest episode of the Security Swarm Podcast: “Dissecting Microsoft’s Secure Future Initiative,” you’ll find part two about the Microsoft initiative that stems from the aftermath of last year’s Storm 0558 breach orchestrated by Chinese nation-state threat actors.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Free Tool

reStructuredText facilitates the extraction and formatting of comments and information from Python programs, similar to Javadoc for Java or Plain Old Documentation for Perl. unccvince finds it a nice option for keeping internal documentation current over time.

A Podcast

Security Cryptography Whatever delves into security topics from the specific angle of engineering and real-world events. You’ll hear interesting discussions among hosts David Adrian, Deirdre Connolly, and Thomas Ptacek, as well as with expert guests from the worlds of business, academia, and government. Appreciated by putacertonit.

A Tip

CiscNoAmeraki shares a favorite shortcut:  “The amount of people that don’t know you can use .\ in front of the username to specify a local user account, instead of entering the entire machine name, is too high.”

A Cheatsheet

Ultimate React.js Cheatsheet has organized all the relevant references on building a React application in a single spot. You’ll find not only the correct syntax for functions, but also some helpful pointers and links to relevant tutorials as well. Another great suggestion from Extra_Discipline_644.
External Attack Surface Management Attack Surface Summary

A Training Resource

Microsoft Azure Fundamentals is a free, one-day course that MS provides for those seeking foundational-level knowledge on cloud concepts. Covered topics include core Azure services, Azure management, as well as governance features and tools. Our thanks for the suggestion go to Suspicious-Sky1085.
External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Dada Mail is a mailing list manager that can be self-hosted to provide complete control over your mailing lists while allowing you to share news, announcements, events, and special offers directly from your website.

Ruptime gathers relevant data for multiple networks with encrypted traffic and client-server architecture. Provides instant list of hosts (up/down), inventory of hardware, software, and a comparable list of benchmark results. Output shows system uptime, current number of users, and load averages. Kindly shared by aieidotch.