Does anyone know of a list/can name companies that don't charge for SSO, Audit Logs[0], that have a free edition where you don't have to talk to a salesperson to evaluate etc.?
"An appraised value" could work for companies too! Though, in fairness, for many billionaires the gains are pretty explicit i.e. we know the public stock price or the 409a valuation.
Co-founder of Tines here. This is exactly why we built Tines - I spent years working in security, and tried nearly a dozen different SOAR/SOAR-like solutions and felt the all were too complicated and the "connector" model was way too hard - the integrations were all quirky and limited.
Tines is completely different - we don't rely on any prebuilt integrations - similar to postman, if you have a curl command then you can paste it into Tines, and the response is simply the json from the API you're hitting - makes it a million times easier to do exactly what you want. You can then use that response in the next action. If the API is terrible (it frequently is) we've a ton of templates to help get the relevant data, and a community with experience connecting to most tools.
Would love to talk about the challenges and see if anything we're doing (or could do) which would have made it easier? I hope you're in a better job now anyway!
Thanks for the feedback! We've implemented a ton of features since then, most notably story history & versioning, annotations for documenntation, better alerting on changes (e.g. no event in 24 hours etc.), but recognise there's still a long way to go. I'd love to hear some more feedback if you want to DM me, it sounds like the project was a bit of a horror show!
Co-Founder of tines here, thanks for all of very valid feedback, there’s loads to think about! I’ll respond to a bunch of the comments individually but the one thing I’d say is try it - it’s way more powerful and flexible than any of the products listed here, although it’s marketed as no-code it’s built by engineers for engineers, with tonnes of enterprise features (Retry on status, connecting to external password vaults, global functions and resources, MTLS, forms, free SSO, curl converter etc.)
As mandatum says above “The UX of Tines beats the pants off ALL of their competitors.” And we can talk about price.
It's usually really hard to negotiate a longer post termination exercise window as an individual, as that will have to be written into the options plan (which requires board/investor majority approval and is generally a huge legal doc written before). However a lot of strong startups these days are offering all employees with longer (e.g. >2 years) experience the opportunity to exercise for 3+ years and sometimes significantly longer.
This is quite dangerous unless you know what you’re doing, if you execute the malware then plan to throw away all equipment you’re using to analyze it. For a next-best experience, if you’re curious, you should upload one to an online malware sandbox e.g. app.any.run which allows you interact with it, look at network traffic, inspect file mods etc. - all the fun, much much less risk and hassle!
MalwareBazaar allows users to share live samples of indicators and not just hashes/metadata associated with them which threat Intel platforms like AlienVault do. There are several differences between the two but the biggest advantage (along with providing the actual malware to you) for MalwareBazaar is that it’s higher fidelity - you will get far fewer false positives as the barrier to entry is much higher. Nobody is going to label 8.8.8.8 as malicious which happens occasionally in AlienVault. As such this isn’t really a service, it’s more a way for the more advanced threat Intel analysts and reverse engineers to share data.
I love the lure, and I respect the GitLab team for making it public, but this is a tough read - it’s putting way too much responsibility on the end-user. For example I’m a huge fan of security teams using email headers to analyze suspicious messages, but I think it’s a step too far to expect a user to ever look at an email header, no? We can hardly get regular end-users to hover over a link; encouraging them to open up email headers to see what service the mail was sent from, or to understand what a “received” message header vs an x-originating-ip means is counter-productive. Headers are hard to understand even for a security analyst, asking HR or Recruitment or Sales to analyze them and understand them feels like the red-team are underestimating how little time everyone has and overestimating how technical most employees are!
Most companies will have a firewall on their corp network so new domains, or malicious-categorized websites will usually be blocked which offers additional protection above working from home. You can obviously use an always-on-VPN for wfh companies, or tools like Cisco Umbrella, ZScaler or Netskope, but many companies haven't done that yet.
What’s your use case for this? I scrape a ton of pastebin links and other sources of hashes posted by folks on Twitter about Emotet, trickbot etc. and I’d be happy to point them to a webhook or get them to you another way? Happy to talk through how we do it too.
"Now before you try to tell me "well you should've forwarded the email and been done with it" those guys are going to be pissed as fuck if I pass along every spam link trying to sell me boner pills"
I know you say the team would be pissed, but it's actually the exact opposite! Firstly, most sophisticated companies have automated the abuse inbox management process, but even when it's not automated, I'd rather 100 easily ignorable reports about boner pills than one person not send an actual spear-phishing email. Plus we can use the generic spam reports to better train our spam filters so please do keep sending them, even the Nigerian prince stuff.
There isn't much evidence that Tether Limited is indeed keeping a reserve of USD for each Tether printed [0]. They are minting hundreds of millions of Tethers and there are a lot of skeptics out there who don't believe that they have billions of USD in a bank.
[0] https://seekingalpha.com/article/4133884-bitcoin-additional-...
Do you think the current security risks are an impediment to it being a perfect solution? I don't want my house deed transferred to someone else just because the provider that managed my wallet that held the deed to my house got compromised?
The report shows far more than signs of intrusion - modules for credential theft, data transmission, persistence mechanisms, keylogging etc. were all discovered. I'd call that hostile.
I'm not sure I get your analogy, but no, I wouldn't expel anyone for "radar touching my planes", but in this case that's the equivalent of browsing the DNC website. If someone had broken into my airforce base, stolen security badges to get into other airforce bases, was photographing planes and stealing and leaking blueprints then you better believe I'd take action
If you're looking for firewall logs or hard drives with definitive proof that malware on certain machines was linking back to particular servers then you're out of luck. However Crowdstrike, the firm that the DNC used to investigate the intrusion, published a report that shows some of the code used and other IOCs from the attack [0].
A security firm like Crowdstrike would have lots of familiarity with these APT groups from previous investigations, so when they identify these groups they have evidence (i.e. they found specific malware or tools that are known to have been used in previous attacks, connections to or from known bad domains, IP addresses etc.) that links the attacks to these groups.
This, however, doesn't prove that APT 28 and 29 are Russian, but if you search for information about these groups, their Tools Techniques and Procedures (TTPs), who they have targeted etc. you can draw your own conclusions.
Note, this was long before the election and before there was politics surrounding the attribution. However this data is only about the intrusion into the DNC's network, and not necessarily linked to the release of personal emails of Podesta & co.
I appreciate the sentiment that anyone can phish or password guess, but even a cursory glance at infosec reports shows there was an operation targeting the DNC that was far more sophisticated than a one man job.
Firstly we know that that Podesta's account was targeted by a phishing email with a bit.ly link [0].
We have proof the bit.ly phishing link in this email was clicked twice in March [1], and his wikileaks dump stops two days after that. The bitly link uses the TTP of base64 encoded strings targeting a google account. We know DNC staffers whose information was leaked by DC Leaks, like Rinehart, were targeted the same way [2] and that the same infrastructure hosted the Rinehart and Podesta phishing pages, along with plenty of other phishing sites [3]. You can verify the bitly links if you like.
We have reports long before Wikleaks released Podesta's information, and before DC leaks had released most of their information, that the same TTP of bitly links with base64 encoded strings that targeted Podesta, Rinehart etc. were targeting other high profile targets in Clinton's campaign [4] as well as Russians, Ukranians etc. [5]. According to security firms these were all using the same two bitly accounts.
Those attacks were attributed to APT 28 by private companies long before Wikileaks released any Podesta information.
We also have proof the same infrastructure that hosted dcleaks [6] hosted domains targeting Syrian human rights groups, Ukranians, Turks, Google accounts, Microsoft accounts etc. or that other IPs used were also used in attacks against the German Parliament, Tv5 etc. That's definitely circumstantial, but a one man job would be terribly unlucky to use a private Romanian server seen used in previous attacks attributed to a state actor.
Sure this could all be circumstantial, it definitely doesn't prove Russia did anything, but the suggestion that this is a one man operation is ludicrous - almost 4,000 people were targeted by the group that targeted the Clinton campaign. In relation to your other comment below, Assange has less credibility than the DHS report unless he comes out with some sort proof.
This sounds very like Redmine [0]. It's ostensibly for project "issues" however it's extremely customizable and all of the above are included in the default config and not much more. It sounds like if you removed about 2 default fields it'd be perfect for the ticketing system you describe above. Plus RSS + Notifications + a solid API.
[0] https://audit-logs.tax/