Tech, Cloud, Infosec, Motorcycle, Gym and Watersport enthusiast
Retired bartender π»πΈ
Failed blogger π»
Cat dad πββ¬πββ¬
Github | https://github.com/roblangford |
Tech, Cloud, Infosec, Motorcycle, Gym and Watersport enthusiast
Retired bartender π»πΈ
Failed blogger π»
Cat dad πββ¬πββ¬
Github | https://github.com/roblangford |
I used to think packaged pre-cut veg at the supermarket was for lazy people.
Then a disabled person pointed out it was a lifeline for them because they lived alone and couldnβt cut it up themselves most days.
I had never even considered that. It changed my perspective and I think from then on when something seems βlazyβ I always ask myself βis this just accessible?β
And itβs nearly always the latter.
Itβs not hard to listen to someone when they say something is not accessible and itβs not difficult to shift your perspective.
I donβt know why so many people wonβt.
For those working on managing log ingestion, it's worth taking a look at https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/appendix-l--events-to-monitor if you haven't recently.
Last update was in May and it lists Windows Server eventIDs by monitoring priority.
Was working on ingestion stuff and it appears 1 event ID accounting for 60% of our Windows ingestion has no real security value.