• 0 Posts
  • 24 Comments
Joined 1 year ago
cake
Cake day: June 11th, 2023

help-circle

  • Lumilias@pawb.socialtoLemmy Shitpost@lemmy.worldMany such cases
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    2 months ago

    Interesting, never heard of Wazuh until now. That looks closer to what Trellix allows.

    The guy in charge of picking endpoint security products (whose team writes these rules) has tried Defender and found it lacking in comparison. Also, that link is about historical search for threat hunting, so I’m not sure if it’s the correct one.

    Edit: I just saw the section about writing detections, but that seems to be more of a reactive than proactive approach. It still does the detection from searches.


  • On the enterprise side, we use McAfee/Trellix and we’re pretty much glued to them for endpoint security. Why? Nobody else allows you to write custom YARA rules straight to the IPS engine like Trellix does.

    Every other vendor only allows you to use rules they have defined for you and doesn’t give you that low level access. It’s frustrating because their support is dogshit too, but my company has niched itself into a corner.













  • Lumilias@pawb.socialto196@lemmy.blahaj.zoneForget rule
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 months ago

    Yeah we tried a few other systems after our main 5e campaign ended. Ars Magica, Lancer, WH40k Wrath and Glory, Blades in the Dark, Cyberpunk Red. My group is not one for roleplaying much, so we prefer crunchy systems. Lancer was great for that, and so is Pathfinder 2e.


  • Lumilias@pawb.socialto196@lemmy.blahaj.zoneForget rule
    link
    fedilink
    English
    arrow-up
    16
    ·
    7 months ago

    Agreed, we’re about half a year and halfway through Abomination Vaults right now. Using PF2e with Foundry VTT has been amazing, especially with all the built-in automation.

    The thing I like most about Pathfinder is how well documented their rules are. 5e had a bunch of hand wavy DM-fiat rules, while PF2e typically has a rule for almost everything.