Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Lack of Control?

Posted on June 7, 2018 By Michael Kavka No Comments on Lack of Control?

You get a tool to use. The tool looks good, in fact other tools from the same company look good. This tool though seems to be the red-headed stepchild.

Recently, I have been trying to clean up and tune an endpoint solution. It is made by a company I have some respect for, and I had seen in the past. The tool itself seems to work well. The problem, like with so many tools, is getting the best data out of it. The signal to noise ratio on the monitoring aspect is huge! The threat detection and prevention works well enough, but the amount of data to sift through on data that is just being brought in for you to monitor is difficult at best. The issue is a fine line between being able to warn about a potential threat and knowing what normal behavior is. The example I will use here is opening known PDFs. These are seen as an application, each with their own hash by said product, for scanning purposes. All fine and dandy, but when the PDF is opened, certain executables that get called cause a trigger for a monitoring alert to be made. These executables are known and trusted applications (part of the PDF reader), but due to the unknown nature of the PDF, they come up as an alert for running the executable. This creates a ton of noise in the alerts area. The problem is there is no real way to tune out these alerts, as the product is set up now, without risking not seeing alerts that one might need to check on. It makes the monitoring alerts useless, unless you feed the data to a SIEM where you can do the filtering. The kicker is customers have been complaining in the user forums about this for over a year now, and still nothing has been officially announced as being done. The rumor is they stealth fixed this in an update to the product, but there is nothing in the release notes. So in the mean time, I have to go through and keep the alert area clean of the noise, which eats into my time to do other things. A company my size it is nowhere as bad as what could happen in a huge company with tens of thousands of endpoints.

Situations like this can leave a bad taste in the customers mouth. Companies get so overprotective of certain things, and hate admitting mistakes. Personally, I would rather a company be up front and over communicate what is going on with an issue such as this. I am more likely to recommend a company that is upfront and honest, and has good communication with a not quite as mature product than a completely mature product but hides from their customers, especially the smaller ones. They need to remember that while the larger companies bring in the greater money, attackers tend to move from the smaller fish into the bigger ones, therefore showing attention to the smaller companies gives you a good reputation with the larger ones.

Rants, Security, Software

Post navigation

Previous Post: Simple Post
Next Post: Cyclical

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Ransomware forces Lancaster, Ohio, to take city computers offline September 9, 2026 Joseph Topping
  • Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms September 9, 2026 Zack Whittaker
  • FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching September 9, 2026 Tim Starks
  • WeChat worm could pwn a friend before they even answered the call September 9, 2026
  • Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs September 9, 2026 Serhii Melnyk and Timmy Lister
  • Ukraine prosecutor general steps down amid scam call center bribery probe September 9, 2026
  • Claude Fable Solves a Historical Cipher September 9, 2026 Bruce Schneier
  • Fort Scott restores systems after ransomware attack September 9, 2026 Joseph Topping
  • A “proof” of Fermat’s Last Theorem that fits the margin September 9, 2026
  • Over 36,000 exposed Plex servers vulnerable to recent flaws September 9, 2026 Sergiu Gatlan
  • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure September 9, 2026 Rem Dudas
  • Man gets 15 years for extorting women with AI-generated porn videos September 9, 2026 Sergiu Gatlan

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Ransomware forces Lancaster, Ohio, to take city computers offline September 9, 2026 Joseph Topping
  • Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms September 9, 2026 Zack Whittaker
  • FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching September 9, 2026 Tim Starks
  • WeChat worm could pwn a friend before they even answered the call September 9, 2026
  • Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs September 9, 2026 Serhii Melnyk and Timmy Lister
  • Ukraine prosecutor general steps down amid scam call center bribery probe September 9, 2026
  • Claude Fable Solves a Historical Cipher September 9, 2026 Bruce Schneier
  • Fort Scott restores systems after ransomware attack September 9, 2026 Joseph Topping
  • A “proof” of Fermat’s Last Theorem that fits the margin September 9, 2026
  • Over 36,000 exposed Plex servers vulnerable to recent flaws September 9, 2026 Sergiu Gatlan
  • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure September 9, 2026 Rem Dudas
  • Man gets 15 years for extorting women with AI-generated porn videos September 9, 2026 Sergiu Gatlan
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.