IT Pro Tuesday #295

IT Pro Tuesday #295

Welcome back to IT Pro Tuesday!

As a reminder, you’re invited to take part in a 5-min survey on IT security awareness training in companies, with a chance to win a Google Nest Hub Max worth $229!

And in the latest Security Swarm Podcast: “Tips and Tricks for Getting Started in Cybersecurity,” we sit down with Grant Collins, an infrastructure security engineer and cybersecurity career coach, to discuss everything from choosing the right degree to navigating the hiring process, acquiring essential skills, and building a robust professional network.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Free Tool

RDS-Shadow allows you to remotely view and control another user’s active session on a Remote Desktop Session Host server, without requiring admin rights. Kindly suggested by stetze88.

External Attack Surface Management Attack Surface Summary

Another Free Tool

Rocketchat is a customizable, open-source communications platform designed with a focus on data protection. Facilitates real-time conversations among team members or customers, regardless of how they connect with you. Thanks for the recommendation goes to Brianinca.

External Attack Surface Management Attack Surface Summary

Yet Another Free Tool

Bitbucket is a Git-based source code repository hosting service with a best-in-class Jira integration and built-in CI/CD. Provides a single spot where teams can plan projects, collaborate on code, test, and deploy.

A Tip

A simple keyboard shortcut appreciated by iamamisicmaker473737:

“Hold Ctrl to pause task manager sorting.”

A Script

CleanBloat is an easy way to remove all the useless bloatware and superfluous Microsoft Office language versions (except English) from Dell computers. This handy script was kindly shared by its author, Cj_Staal.

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Python Cheatsheet is a nice, single-page reference sheet that provides quick access to all the essentials for the Python 3 programming language. Kindly suggested by Extradiscipline_644.

Zypper is a powerful command-line package manager for installing, updating and removing packages in SUSE and openSUSE Linux. It features subcommands, arguments, and options that can be used to perform specific tasks, and it can also be used to manage repositories. This tool is a favorite of donges.

IT Pro Tuesday #295

IT Pro Tuesday #294

Welcome back to IT Pro Tuesday!

First off this week, we’d like to invite you to take part in a 5-min survey on I.T. security awareness training in companies. Help us understand how the human side of security is handled in your organization, and you’ll get a chance to win a Google Nest Hub Max worth $229!

And in the latest Security Swarm Podcast: “Lockbit’s Return, ScreenConnect Vulnerability & a US Healthcare Cyber Attack,” we discuss Hornetsecurity’s Monthly Threat Report analyzing recent security incidents and share expert insights.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tip

A handy shortcut, compliments of ensum: 

sysdm.cpl in the run diaglog/start menu will open System Properties.”

A Free Tool

Scintilla is a source code editing component with the usual text editing features as well as highly useful capabilities for editing and debugging source code. Features include support for syntax styling, error indicators, code completion and call tips; selection margin can contain markers like those used in debuggers to indicate breakpoints and the current line; and better styling choices. Appreciated by GeneMoody-Action1, who adds, “I have IDEs for 6 languages built into this completely portable.”

External Attack Surface Management Attack Surface Summary

A Tutorial

Introduction About BiDi SFP and BiDi Fiber explains specifically how BiDi SFP works and for what, what fiber it should operate with, and the differences between it and common SFP. Thanks for directing us to this one are offered to chaoticbear.

Another Free Tool

Prometheus SNMP Exporter exposes SNMP data in a format that is perfectly mapped for Prometheus. It translates the hierarchical data structure of SNMP to work with the Prometheus n-dimnensional matrix, thus eliminating the need to manually go through data. Our appreciation for this suggestion goes to bilbo-baggins125.

External Attack Surface Management Attack Surface Summary

Humor

A timely yet harmless prank in the category of ‘we didn’t suggest anything’… this one compliments of Ganthet72: 

“One April Fool’s Day, I put a sign on the copiers that they were now ‘voice-activated.’ It was fun listening to people telling the copier, ‘Make two copies’ all day.”

P.S. Bonus Free Tools

HTML Cheat Sheet is a quick guide to useful code examples and web developer tools, markup generators and more, including a nice pdf version you can print out. Kindly recommended by Extradiscipline_644.

Omni OS is an open-source enterprise server OS featuring data storage, lightweight virtualization, full hardware virtualization, software-defined networking, and in-depth tracing. AntranigV says, “I deployed OmniOS for a customer and I fell in love with it. Now I have 5+ deployments of OmniOS and I even setup a local mirror to download packages even faster. illumos Zones with ZFS, boot environments and SMF/FMA is really amazing, best enterprise Unix I’ve ever seen in my life. Can’t believe people are not using this gem.”

IT Pro Tuesday #295

IT Pro Tuesday #293

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Insider Threats in Microsoft 365,” we focus on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

JA4+ Network Fingerprinting explains how to leverage the new modular network fingerprint methods that replaced the JA3 TLS standard, which can be useful in helping protect your network from threats. aygupt1822 explains, “These are TLS Fingerprinting tools which generate TLS Fingerprints from raw network packets.”

External Attack Surface Management Attack Surface Summary

Scripts

9 Essential PowerShell Scripts for SharePoint Online Security shares a set of curated, precision scripts for monitoring SharePoint online file activities, external user activities, and online permissions/access. Kindly suggested by Shan_1130.

External Attack Surface Management Attack Surface Summary

Security News

Critical Security Flaws within ChatGPT Ecosystem delves into the attack vector introduced by generative AI that can be exploited to compromise user accounts. ElectroPanic0 explains, “While the whole GenAI trend is great and lets employees/teams incorporate external AI tools in their code or daily tasks, the security falls behind.”

A Tip

jamesaepp shares a handy browser shortcut: 

CTRL + Shift + DEL in Chrome/Edge (maybe FF?) brings you to the clear cache dialog box

A Tutorial

How to Build a Custom MacOS Dock is a guide that walks you through how to create a purpose-built onboarding dock for your users. The method has been verified from Sonoma back through Catalina. Recommended by trikster_online, who says, “I have about 7 different docks I use depending on the lab.”

P.S. Bonus Free Tools

Git Commands Cheat Sheet is a nicely organized quick-reference guide where you can easily locate all the essentials for making the best use of Git. Appreciation for the suggestion goes to Extradiscipline_644.

Mimir is an open-source multi-tenant time series database that is a blazingly fast, scalable, high-availability solution for long-term storage for Prometheus. Our thanks for the recommendation go to bilbo-baggins125.

IT Pro Tuesday #295

IT Pro Tuesday #292

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Microsoft vs Midnight Blizzard,” we explore insider threats within M365 with special guest Philip Galea, R&D Manager at Hornetsecurity. The focus is on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

Fiber Cable Maintenance walks you through the proper cleaning procedures that will keep your fiber cable connections working at peak performance. Appreciation for this one goes to -sirKris-, who offers the reminder, “Keep your equipment clean!” 

External Attack Surface Management Attack Surface Summary

A Free Tool

Intunewin Build and Extract is a tool that allows you to either build a new Intune Win32 application or extract the content from one that already exists. The author has written detailed instructions in this blog post. Our thanks for the suggestion go to dcg1k.

External Attack Surface Management Attack Surface Summary

Training Resource

Coursera is an online learning platform with courses from top universities and industry leaders. The catalog of options is designed to provide self-paced training options to suit all skill levels. esgeeks explains, “offers free and paid courses on a wide variety of topics, including technology.”

Humor

In the runup to April Fool’s Day, we thought we’d share this diabolical-yet-harmless prank, compliments of laguna314…

“[W]hen people set their desktop to family photos or pet photos etc., I make many copies of the photo, and change a minor detail … with paint or photoshop; something small but noticeable like adding a mustache. Then I’ll set the background to point to an album of all the copies of the picture. Have it change at like 3-minute intervals so that at some point throughout the day, their background will show the mustache for 3 minutes.

Takes time for them to notice; and when they do, by they time they can point it out to someone, it’s gone!”

A Tip

This nice shortcut was offered courtesy of bobmonkey07: 

Win+pause opens “system” so you’re right where you need [to be] for changing computer name/domain.

P.S. Bonus Free Tools

Bash Cheatsheet is a quick-reference guide that can help you get started with Linux bash shell scripting. Kindly suggested by Extradiscipline_644.

Looking Glass is an easy-to-deploy PHP option that allows you to get network information by executing commands on the router and then gathering the output for the user. thegreattriscuit explains, “[it’s] the project behind equinix’s LG.”

IT Pro Tuesday #295

IT Pro Tuesday #291

Welcome back to IT Pro Tuesday!

In the latest monthly threat report on the Security Swarm Podcast: “Midnight Blizzard, AnyDesk Breach & a $27 Million Ransomware Attack,” Dr. Yvonne Bernard joins us for an in-depth analysis of major security breaches and ransomware attacks that occurred between January and February 2024.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tip

mmpre shares a helpful hint: 

“In notepad++, say you’re working on yaml and need to indent a ton of lines two spaces. Single click on the first line to get your cursor there. Hold down shift + ctrl + alt and single click on the last line.

It selects all of them, and you can do whatever you want to all of those lines at once.”

A Free Tool

PSDiscoveryProtocol allows you to capture and parse CDP and LLDP packets on local or remote computers as well as adding port information to the SCCM Hardware Inventory on Win10. Kindly recommended by Jebedia47

External Attack Surface Management Attack Surface Summary

Training Resource

Kevin Wallace Training, LLC  is a YouTube channel with hundreds of videos geared toward networking certification and career growth. The primary focus is on CompTIA and Cisco, ethical hacking, automation, and wireless. jack_hudson2001 appreciates it for learning about advanced networking.

Another Free Tool

Hyperglass is an open-source network looking glass that offers a faster, easier, more-secure way to provide unattended visibility into a network for customers, peers, and other network operators. sixbux found it “relatively easy to configure and deploy.”

A Script

Connect to All Microsoft 365 Services is a super-easy way to connect 9 essential M365 PowerShell modules. Author KavyaJune explains, “[it] effortlessly installs and connects to… Exchange Online, MS Graph, SharePoint PnP, MS Teams, Compliance Center, Azure AD, and more. The highlight? All this can be achieved with just a single cmdlet.”

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Sass Cheatsheet is a convenient resource that organizes the most-useful features of SASS in a handy, quick-reference format. Our appreciation for directing us to this one goes to Extradiscipline_644.

ASN Database is a fully searchable resource that provides in-depth insights into all ASNs, their announced prefixes, peer information, Internet Exchange (IX) memberships, and more. Author flems77 says, “[I] keep it updated continuously (24/7). Just did a count, and as of now, I see a total of 118.374 ASN’s—of which 82.163 are active (have peers and announce prefixes).”

IT Pro Tuesday #295

IT Pro Tuesday #290

Welcome back to IT Pro Tuesday!

In the latest episode of the Security Swarm Podcast: “Co-Pilot and Misconfigured Permissions – A Looming Threat?,” we explore Microsoft 365 Co-Pilot. This generative-AI tool is embedded within various M365 applications and can execute tasks across different software platforms in seconds. Tune in to learn about some surprising risks that can surface with this productivity powerhouse.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Free Tool

PowerCSR is a Powershell-based GUI that quickly generates a CSR and Private Key file using OpenSSL. Author ReproDev explains, “after banging my head against the wall quite a lot with the command line version freezing or just force closing, I created a tool in Powershell to create the initial CSR and a 2048-bit key… Enter your details for the domain, organisation and the rest, then click Generate CSR”
External Attack Surface Management Attack Surface Summary

A Tutorial

Using DHCP to Boot WDS to BIOS & UEFI with SCCM is a tutorial that walks you through a setup that allows the booting of both BIOS and UEFI machines from the same WDS environment. Covers DHCP Policies and Custom Vendor Classes. Thanks for directing us to this one go to Versed_Percepton.

Training Resource

edureka! is a educational YouTube channel loaded with both quick topical summaries as well as in-depth, instructor-led trainings that can bring you up to speed on a surprisingly broad array of tech subjects. Kindly suggested by Present-Chard.

A Tip

LordCorgo kindly shares the following: Windows 11 will also accept no@thankyou.com with any password as a bypass to their forced online Microsoft Account.

Another Training Resource

Microsoft Azure Administrator is a free, 96-hour course that teaches how to manage your Azure subscriptions, network traffic, and secure identities; administer infrastructure; configure virtual networking; connect Azure and on-prem sites; implement storage solutions, web apps, and containers; and more. Our thanks for this one go to Suspicious-Sky1085.

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Adagios is an intuitive, web-based configuration interface that hides some of the clutter associated with Nagios. It offers a rest interface for both status and config data as well a complete status interface that includes all features, which can be a nice alternative to the standard Nagios web interface. Appreciation for this recommendation goes to Supermop2000.

Vue.js Cheatsheet is a quick reference guide that consolidates the essentials for this open-source JavaScript framework for building user interfaces and single-page applications. You’ll find syntax and a few references that can help you work faster when you’re not super familiar with Vue.js. Kindly suggested by Extradiscipline_644.