Blog Entries

23. 06. 2023 Giuseppe Di Garbo Icinga Web 2, NetEye

Scheduling Downtime on Linux Environments

In one of my previous posts I mentioned the importance of downtime scheduling and shared an interesting example of a PowerShell script for managing downtime in Windows environments. Recently a customer asked me how to manage downtime with a similar solution, but for several hundred Linux servers monitored under NetEye. The reason is very simple:…

Read More
23. 06. 2023 Massimo Giaimo Blue Team, SEC4U

SOC vs. MDR: Understanding the Key Differences for Comprehensive Cybersecurity

Introduction In today’s increasingly complex cybersecurity landscape, it is crucial for organizations to adopt effective solutions to protect their data and digital assets from ever-evolving threats. Two commonly used services in this regard are SOC (Security Operations Center) and MDR (Managed Detection and Response). While both aim to ensure cybersecurity, there are important differences that…

Read More
22. 06. 2023 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.30

We fixed several deprecations in the NetEye SIEM module, which allow NetEye installations to be compliant with the directives of Elastic Stack and to be prepared for future upgrade of the Elastic Stack. Updated packages For NetEye 4.30 we updated the following packages:

Read More
20. 06. 2023 Emil Fazzi Bug Fixes, NetEye

Bug Fixes for NetEye 4.30

We fixed several bugs regarding the NetEye first installation on a cluster. It is now possible to successfully run the neteye_secure_install without worrying about possible problems and interruptions. In addition, we fixed the permissions of some configuration files. Updated packages For NetEye 4.30 we updated the following packages:

Read More
19. 06. 2023 Fabrizio Dovesi Atlassian, Development, Service Management

👀 The AI is coming! The AI is coming!

A brief presentation of the brand new Atlassian Intelligence features and their potential in real use case scenarios. We don’t need Chicken Little to tell us that our lives will be increasingly influenced by the Artificial Intelligence revolution – AI is transforming how we work, enhancing teamwork, and significantly accelerating team achievements. Machine learning is…

Read More
13. 06. 2023 Mirko Ioris Blue Team, Red Team, SEC4U

The New .zip Domains do More Harm Than Good

In this article we’ll discuss the security concerns caused by Google’s introduction of .zip domains. First things first, let’s understand what a domain is and how it’s structured. What is a domain? A domain is a text string that allows a user to access the specified web site once typed into a browser. This string…

Read More
13. 06. 2023 Beatrice Dall'Omo Red Team, SEC4U

What We Know about the MOVEit Transfer 0-day

0-day vulnerabilities are predicted to grow more and more, posing new threats for the cybersecurity. It’s hard to predict them and when their exploit occurs, since developers and vendors are unaware of the flaw until they are actually exploited. Hence, there is no ready patch available for a 0-day vulnerability. MOVEit Transfer 0-day On May…

Read More
12. 06. 2023 Mattia Codato NetEye

Speeding up NetEye Updates with an RPM Mirror

When it comes to upgrading and updating NetEye, many users face a common challenge: the time required for downloading the new package versions. This process can be influenced by connection speed, the number of nodes to update, and sometimes even the number of NetEye systems to manage simultaneously. Fortunately, NetEye 4.30 introduces an effective solution:…

Read More
11. 06. 2023 Massimo Giaimo SEC4U

HackInBo – talk “pompompurin & co. – stories of seizures!”

On Friday 9 June 2023 I had the opportunity to participate as a speaker at the HackInBo Business event, one of the most important conferences on cyber security in Italy. During the talk I presented, I talked about the history of RaidForum, BreachForum and ExposedForum and the Genesis and Solomon marketplaces, recounting the seizures actions…

Read More
09. 06. 2023 Giuseppe Di Garbo ITOA, NetEye

Monitoring, Collection of Metrics and Dashboard of the NetEye Database

As you all know NetEye uses MariaDB as its database. With the nep-monitoring-core module of the NetEye Extension Packs (NEP), the following aspects of MariaDB are monitored: These checks are performed with a default time interval (check_interval) of 180s. To have real time control of many aspects of the MariaDB database operation, I suggest installing…

Read More
09. 06. 2023 Francesco Pavanello Exposure Assessment, SEC4U

Exposure Assessment: The Best Way to Easily Discover a Target’s Infrastructure

Overview of discovering hostnames and IP addresses using OSINT techniques.

Read More
09. 06. 2023 Davide Sbetti Bug Fixes, NetEye

Bug Fixes for NetEye 4.30

We fixed a bug that caused a failed authentication of Alyvix sessions having some special characters in the password, due to an inconsistent encoding. Moreover, we fixed an issue related to the installation procedure of the feature modules packages on satellites, which under some circumstances was not marking the corresponding DNF group as installed. Furthermore,…

Read More
07. 06. 2023 Andrea Mariani NetEye

NEP NRPE

After performing several migrations to NetEye 4, I realized that not all checks present on the old NetEye 3 could be migrated immediately. Sometimes for obsolete host systems on which the new Icinga 2 Agent could not be installed, or for dedicated check types for specific services, it was necessary to continue using our good…

Read More
07. 06. 2023 Federico Corona Red Team, SEC4U

Cracking the Code: Unveiling Data Breach Secrets through OSINT-driven Scripts

Welcome, today’s blog is dedicated to data breach analyses and evaluating their reliability. In an increasingly data-centric digital landscape, it’s crucial to delve into the complexities of data breaches and develop effective methods for determining the trustworthiness of the information they contain. In this blog, we’ll explore a professional approach to data breach analysis using…

Read More
06. 06. 2023 Andrea Mariani NetEye, Service Management

SSSD for Active Directory Authentication

We all know that NetEye can grant access to its Web Interface through local users, or through the use of LDAP queries that can filter and grant GUI access to users or groups of a given Active Directory domain. What I would like to explore today is the possibility of granting SSH access and elevating…

Read More

Archive