Saturday, July 6, 2024

Data Analytics - Excel Vs PowerBI

Microsoft Excel already had features like power query and power pivot, but these were not well known 10-12 years ago.


Then data analytics market started growing and solutions such as Tableau became popular.

Microsoft saw an opportunity to enter in data analytics market (they already were in a way because of Excel) and introduced a new tool named as PowerBI (Repackaged Microsoft Excel 😅). Table and model view constitutes the brain of PowerBI where all the processing happens.

Today, Power query is a key component of PowerBI. Microsoft's PowerBI has emerged as a competitor to existing data analytics solutions.

My learning - Adaptability is the key to survival.

These days most job roles related to data analytics require hands-on on PowerBI.

Happy Learning !!
hashtagmicrosoft hashtagmsexcel hashtagpowerBI

Vulnerability Management - (Rapid7) SQL Queries

Rapid 7 InsightVM does not allow few filters to access directly. One of such filters is solution ID. A typical solution ID for a Microsoft patch would look like 'msft-kbXXXXXXX-alphanumeric text'. As we all are aware, patch Tuesday for June month was on 11th. Now, if I want to know the assets missing May month Microsoft patches then I have no option to get this list using standard filters (Why would I want to know this? Because I want to improve my patch compliance).


In such scenarios, SQL queries come to our rescue. There is a specific report template in InsightVM which is based on SQL queries. I can write a SQL query to fetch the list of assets missing a specific KB.

You might be wondering, why can't we just apply filter on 'Vulnerability Solution' column (in report) and get the list? No, we cannot, because for one particular OS, the solution contains all the recently released KBs for all versions of Microsoft OSes. Does not make sense right? Neither to me, I am trying to find out the rationale though.

Please note: You should know the basic concepts of DBMS like fact and dimension table, variety of joins, primary and foreign keys etc. This is where Vulnerability Management overlaps with SQL. Surprised? Remember, we live in a small world :)

Please find the below URL:
https://discuss.rapid7.com/t/sql-query-listing-systems-that-require-specific-kb/27579/2

Happy Learning !!
hashtagvulnerabilitymanagement hashtagcybersecurity hashtagRapid7

Vulnerability Management - (Rapid7) Leftover data from deleted sites and assets

One of our clients has Rapid7-Splunk integration in place. Here Splunk is used exclusively for vulnerability analytics. While Splunk team was performing some data analysis, they found few asset IDs with no corresponding vulnerability/asset data. They gave the list to us for investigation. I tried finding the relevant details in InsightVM but did not find anything.

Now that the context is set, this is why one should perform maintenance procedures on InsightVM database. Regular maintenance helps clean up the database and remove leftover data from deleted sites and assets. You might delete an asset from site/asset group but still the asset exists in InsightVM DB. This in turn results in number mismatch between solutions (wherever integration is in place, for e.g. in this case count of assets between Splunk-Rapid7).

Please find the below URL:
https://help.rapid7.com/insightvm/en-us/Files/Administration.html

Happy Learning !!
hashtagvulnerabilitymanagement hashtagcybersecurity hashtagRapid7

Sunday, April 7, 2024

CyberSecurity - Technical Documentation

One must have the following points documented when a cybersecurity project transition from implementation phase to operational phase:

  1. Scope (Project Scope)
  2. Architecture
  3. Roles and Responsibilities
  4. Escalation Path
  5. Run Books
  6. Asset Lists
  7. SLA Review and Documentation
  8. Metrics and Reporting Documentation
  9. Training Materials
  10. Knowledge Transfer (From Project to BAU team)
Happy Learning
hashtagvulnerabilitymanagement hashtagcybersecurity

Vulnerability Management - Nessus on a Windows Server OS versus a Windows Desktop OS

Microsoft Windows desktop systems have network limitations that may impact the performance of Nessus. The TCP/IP stack limits the number of simultaneous incomplete outbound TCP connection attempts. After the limit is reached, subsequent connection attempts are put in a queue and will be resolved at a fixed rate (10 per second). If too many enter the queue, they may be dropped.


This has the effect of causing a Nessus scan on a Windows desktop OS to potentially have false negatives. For better accuracy, it is recommended that Nessus on a Windows desktop OS have its port scan throttle setting down to the following, which is found in the "Performance" setting type under General Settings of a new policy:

Max number of hosts: 10

Max number of security checks: 4

Max number of packets per second for a port scan: 50

For increased performance and scan reliability, it is highly recommended that Nessus Windows be installed on a server product from the Microsoft Windows family.

Please refer the below URL for more details:
https://www.tenable.com/products/nessus/nessus-faq

Happy Learning
hashtagvulnerabilitymanagement hashtagcybersecurity

Vulnerability Management - Understanding vulnerability posture

Understanding the vulnerability posture of an organisation at a basic level helps you drive remediation efforts. So, I don't know what t...