Background Continuing the theme of identity management, let’s take a look at [Get-AzureRoleAssignments]. The genesis of this tool was a seemingly simple request from my Security Operations team. What resources and permissions does the Security Analysts L1 group provide? At the time this group had only ever been used in the subscription that housed our Sentinel instance. This made the request…
During a recent conversation someone pointed out that my Github profile is somewhat dusty. Afterwards I took a public view and dang, they’re absolutely right. Nearly all of my recent work has been restricted to private repos or owned by my employers. Let’s fix that, shall we? Starting today I plan to go through all of the various scripts and applications I’ve written over the…
Hi. My name is Scott Pack (he/him/e/esan). I enjoy the build side of tech and enjoy things like system hardening, regulatory compliance, and reliable infrastructure. I mostly talk or read about Security Engineering and Homebrewing, and making sure we enjoy ourselves while it’s happening. As always…. All thoughts are my own and most definitely not representative of any of my employers;…
A fellow Brakeing Down Security slacker, Ceafin asked a fun question question to the group at large. He further went on to explain that he was investigating a potentially compromised system and didn’t trust the standard tools or logs. While there were a few good answers that other users brought up my first instinct was good ole fashioned auditd . Since the auditing subsystem operates as a…
The Setup Let’s paint a picture of a fun scenario. In my home lab I run a mix of CentOS and Windows. Windows for Active Directory and those Windows specific apps, CentOS for most everything else. For CentOS systems I use Spacewalk as an inventory and patch distribution system. While Spacewalk is pretty dang heavy for such a simple workflow it at least keeps me tuned into what is likely to be…
During an infrastructure upgrade we decided to migrate from Observium to LibreNMS for our time-series graphs. That system is one of the last vestiges of the Ubuntu standardization and will be one of the biggest wins. Since it was one of the first forays into Linux for the team some of the build decisions were less than enterprise; for instance this system runs Ubuntu 12.04 Desktop. Part of the…
ServerFault user ewwhite describes a rather interesting situation regarding application distribution wherein code must be compiled in production. In short he wants to keep track of changes to a specific directory path and send alerts via email. Let’s assume that there already exists some basic form of auditd policy in play, so we’ll be building out a snippet to be inserted into your…
A few things to keep in mind. First a name change. During the 0.X versions the software was called Graylog2. Starting with the release of 1.0 the name was changed go Graylog. I’m pretty happy about the change. Graylog2 was a bit of a mouthful and including version numbers in package names has always annoyed me anyway. However, changing the version number makes the upgrade a bit harder. I…
After going through the retention schedule exercise on our infrastructure log management system I ran into a bit of an interesting situation. First, some background. Historically Graylog2 hasn’t provided any capability to perform time based retention, which is pretty dang lame. Instead all retention was performed based purely on message count. If you have good figures on your log generation…
A while ago I wrote a post on how I managed to get my systems integrated with Office365 to send email notifications . At the time the method I used worked well enough but it was annoying. Every system had to log in individually which meant the username and password had to be distributed to every system. Certainly not my favorite thing. Since then I’ve learned that Office 365 has something…
Earlier this week I saw this tweet. There are a few topics that seem to come up with some regularity and running applications on non-standard points is definitely one of them. Like everyone else I have some opinions. The Internet is a wild and scary place, full of malcontents whose motives range from curiosity all the way to criminal enterprise. These unsavories are constantly scanning for…
Sometimes I feel like Records Retention is the red-headed step child. It’s obviously important, almost every regulation that covers us talks about it to one extent or another. There’s a base assumption under the major frameworks that retention is happening 1 . Having a policy around records management is even a requirement under SOX, and for certain classifications of data under…
My tool of choice for vulnerability scanning has always been Nessus, going all the way back to when it was properly OpenSource and the ‘Experimental Checks’ checkbox was a sure fire way to crash your target. Since going full commercial it’s only gotten better and the current interface is very clean and polished. The biggest downside being that each scan is treated as a…
This is the sixth and final post in a multi-part series where I explore the process of transforming an existing Graylog install into a resilient and scalable multi-site installation. Start here for Part 1 . Let me start by saying that the entire process was a huge learning experience for me. Over the course of my career I have dealt with a number of different logging systems of various degrees of…
This is the fifth in a multi-part series where I explore the process of transforming an existing Graylog install into a resilient and scalable multi-site installation. Start here for Part 1 . At this point we have the dedicated ElasticSearch nodes up and running with the legacy node shut down. MongoDB has been split out and is in a Master/Slave replication mode running on the new nodes. Graylog2…
This is the fourth in a multi-part series where I explore the process of transforming an existing Graylog install into a resilient and scalable multi-site installation. Start here for Part 1 . The MongoDB section actually gave me the biggest set of problems. Part of this is because of my utter lack of familiarity with Mongo and partially because of Mongo’s design. Originally I hoped to go…
This is the third in a multi-part series where I explore the process of transforming an existing Graylog install into a resilient and scalable multi-site installation. Start here for Part 1 . Previously we built our servers and reconfigured ElasticSearch . Next up is to build out the new Graylog2 and Graylog2-Web servers themselves. Graylog2 Server Build Software Install Since I sized and…
Sometime in the early 1990s, for reasons I can’t remember, I made the switch from pico to vim and never looked back. Since that time I’ve been slowly tweaking my config, occasionally adding a feature here and there, and always carrying my files along from one computer to another. My config is still mostly stock, unlike some friends who read the O’Reilly book and somehow managed…
This is the second in a multi-part series where I explore the process of transforming an existing Graylog install into a resilient and scalable multi-site installation. Start here for Part 1 . Server Setup At this point we have about 6 months of data in our existing Graylog2 system so I wanted the entire migration to happen without data loss and to be as seamless as possible. For the new…
This is the first in a multi-part series where I explore the process of transforming an existing Graylog install into a resilient and scalable multi-site installation. When I started at ${DayJob} we were using a single server Graylog2 for log storage. Honestly it works out pretty well, the only real resource hog is ElasticSearch which will eat up as much memory as you can ever throw at it.…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Nubby Admin , a fantastic blog from a fellow tech nerd. At my old job I had a bottom of the line box sitting on my desk that I used for some testing. It was a hardware clone of the oldest Snort sensors I had deployed, and by old I mean corporate desktop grade vintage 2003. I kept it…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Nubby Admin , a fantastic blog from a fellow tech nerd. One of the worst problems I have with tabbed consoles is knowing exactly which console I’m working in. Sure, I can simply look at either the shell’s title, or the prompt, but I still inevitably will type a command…
Pulling back from the archives this is a repost of a previous blog post, with minor edits to include a more revent version of the app. This time ripped from a guest spot at The Nubby Admin , a fantastic blog from a fellow tech nerd. I spend a lot of time doing text based data processing. A lot of time. During an analysis, I often want to do things like look at ‘Top Talkers’,…
Some few of us, primarily in consultancy and professional services, are in the position to work in a place surrounded by other Information Security people but for most of us the ratios are a little different. To speak from personal experience, at my previous company there were 6 of us out of a total IT staff of about 170. Based on conversations with others my experience seems somewhat typical, or…
For much of my professional career I have been what I like to call “health care adjacent”. Meaning, my department has HIPAA responsibilities but I personally was only partially involved in them. I was around for conversations around protecting PHI, e- or otherwise, and sometimes called in as a technical resource for addressing specific controls but I was never in a situation where I…
Since writing this post I’ve learned a better way. If you’re using a personal account or only need to relay 1 server the below may be sufficient. If you’re managing more than one server and can manage your Office365 domain please see my updated post Better Use of Office 365 as a Smart Host with Postfix . One great thing about Linux systems is that we can get automagic reporting…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Security Stack Exchange Community Blog . My workplace recently, for some definitions of recent, switched the company we use for certificate signing to InCommon. There were quite a few technical/administrative advantages, and since we’re educational, price was a big factor.…
Some number of days ago my dear Wesley put out the call absolutely begging for our Best .screenrc Files . While mine is very simple it hits all my special points. First the config, then the explanation. startup_message off chdir defutf8 on utf8 on on # Enable window monitoring & notifications monitor on defmonitor on # Change escape command from ctrl-a to ctrl-z escape ^za autodetach on hardstatus…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Security Stack Exchange Community Blog . For quite some time I’ve been running into a tricksome situation with tcpdump. While doing analysis I kept running into the situation where none of my filters would work right. For example, let’s presume I have an existing capture…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Security Stack Exchange Community Blog . This question on Security.SE made me think in a rather devious way. At first, I found it to be rather poorly worded, imprecise, and potentially not worth salvaging. After a couple of days I started to realize exactly how many times I’ve…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Nubby Admin , a fantastic blog from a fellow tech nerd. Let’s face it. NFS is a magical thing. It allows you to centralize your storage, share volumes across systems, and all while maintaining sane permissions and ownership. Unfortunately, it can also be a bit of a fickle beast.…
No matter how much we hope otherwise the foundation of any security program are consistent and used procedures. This means figuring out what we need to be doing, sketching out how we think we should be doing it, finding out we were totally wrong and misguided thinking we could do it that way, then editing it into something that actually works. I knew walking into this job that procedure 1…
Pulling back from the archives this is a repost of a previous blog post. This time ripped from a guest spot at The Security Stack Exchange Community Blog . The auditd subsystem is an access monitoring and accounting for Linux developed and maintained by RedHat. It was designed to integrate pretty tightly with the kernel and watch for interesting system calls. Additionally, likely because of this…
Simplistic Beginnings Whether using a preseed or a manual install the default partitioning setup is to use what Debian calls “atomic”. When using atomic the installer creates two partitions /boot at 250MB LVM physical volume (PV) filled to rest of disk The one PV contains a single Volume Group (VG) which will contain two Logical Volumes (LV). $(hostname)-vg/swap_1 at the same size as…
While trying to implement the time changes discussed earlier I discovered that Windows time is a bit more complicated than I at first believed. Let’s recap my requirements: Keep time synchronized from a network service Always set the time no matter how far off it is Set the time on system startup It seems that requirements 1 and 2 are discussed last time and should be easily set using…
Keeping correct time is understandably pretty important. Without correct time logs are unreliable, for both troubleshooting and investigations, domain logins don’t work since Kerberos tickets have time based expiration, SSL/TLS won’t work for the same reason. In short, invalid time is all kinds of bad for numerous reasons and the failures may not be obviously due to time skew. At…
I’ve had brief dalliances with both Windows and Linux as working environments but for the vast majority of my professional career I’ve used OSX as my desktop and laptop environment. Since I almost exclusively deal with web interfaces and Linux systems 1 . There are a few silly things that only work on Windows, like the vSphere client, so for those I keep a Windows 7 VM available. The…
As old as it is RADIUS is still a pretty nice tool for getting non-Windows services to authenticate against Active Directory. It’s pretty natively supported in most all network devices, has well tested PAM modules, and is well understood by infrastructure systems like load balancers. Hell, it’s even the preferred authentication type for some two-factor systems such as Windows Azure…
Way back in 2013 I was potentially going to be tagging along with my wife as she attended a work conference in Las Vegas. I started looking around the Interweb for security related events happening there in early January to give me something to do. After an hour I was getting somewhat cranky with exactly how totally distributed the information was. Thus InfoSec Happenings was born. I’m now…
#Selection and Installation Coming into a new environment is always interesting. One of the first tasks that came up coming into this one was to throw up a provisioning server. Since we’re already standardized on Ubuntu I didn’t want to immediately jump to Cobbler as the tool of choice. Imagine my surprise when, after reviewing the options, I realized that a tool designed for Redhat is…