<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Anything About IT</title><link>https://www.verboon.info/tags/security/</link><description>Recent content in Security on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 08 Jul 2019 22:33:36 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Testing Windows Defender MAPS Connectivity with PowerShell</title><link>https://www.verboon.info/2019/07/testing-windows-defender-maps-connectivity-with-powershell/</link><pubDate>Mon, 08 Jul 2019 22:33:36 +0000</pubDate><guid>https://www.verboon.info/2019/07/testing-windows-defender-maps-connectivity-with-powershell/</guid><description>&lt;p&gt;Whenever I work with customers on Windows Defender or Microsoft Defender Advanced Threat Protection, one of the first things I usually review are the current Windows Defender settings. Having Windows Defender properly configured is key, because otherwise you might not be able to make use of all the capabilities Defender and Defender ATP provides. One of them is MAPS (Microsoft Active Protection Service) or also known as Windows Defender Antivirus cloud-delivered protection service. Quite often I notice that clients have no connection to MAPS, this can be validated by running the following command from an elevated command prompt:&lt;/p&gt;</description></item><item><title>Data Collection Tier in Azure Security Center</title><link>https://www.verboon.info/2018/02/data-collection-tier-in-azure-security-center/</link><pubDate>Sun, 25 Feb 2018 17:22:05 +0000</pubDate><guid>https://www.verboon.info/2018/02/data-collection-tier-in-azure-security-center/</guid><description>&lt;p&gt;Within the Azure Security Center, Security Policy node, you can select a workspace and there define the data collection configuration for security events.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;All Events&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Common&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Minimal&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
 &lt;img src="images/022518_1719_DataCollect1.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;More details about the Azure Data Collection and the data collection tier can be found &lt;a href="https://docs.microsoft.com/en-us/azure/security-center/security-center-enable-data-collection"&gt;here&lt;/a&gt;. The page also has a list of all the Event IDs that are being collected within each tier.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/022518_1719_DataCollect2.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;To better understand the exact meaning of each Event ID, I&amp;rsquo;ve created the below lists containing the Event ID, Description, Event Provider and Event Level information.&lt;/p&gt;</description></item><item><title>MBSA 2.3 Preview Release Available</title><link>https://www.verboon.info/2013/09/mbsa-2-3-preview-release-available/</link><pubDate>Sun, 08 Sep 2013 13:05:08 +0000</pubDate><guid>https://www.verboon.info/2013/09/mbsa-2-3-preview-release-available/</guid><description>&lt;p&gt;Based on a statement made by Microsoft in the August 2012 security bulletin, I wrote a short blog post back in November 2012 that there would be &lt;a href="https://www.verboon.info/index.php/2012/11/no-mbsa-for-windows-8-planned/"&gt;no MBSA version available for Windows 8&lt;/a&gt;. But it looks like plans have changed as Microsoft has now released a preview version of MBSA 2.3 that does provide support for Windows 8, Windows 8.1 as well as the new server editions.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/image_thumb.png" alt="image"&gt;

&lt;/p&gt;
&lt;p&gt;&lt;em&gt;MBSA 2.3 release adds support for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2. Windows 2000 will no longer be supported with this release. The final release of MBSA 2.3 is expected to be available in Fall 2013. Due to the remaining short product cycle, we will be unable to implement any design change requested for this release.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>All security updates on a DVD</title><link>https://www.verboon.info/2008/10/all-security-updates-on-a-dvd/</link><pubDate>Mon, 20 Oct 2008 19:31:19 +0000</pubDate><guid>https://www.verboon.info/2008/10/all-security-updates-on-a-dvd/</guid><description>&lt;p&gt;I do periodically browse through the Microsoft Download Center (&lt;a href="http://www.microsoft.com/beta/downloads/Default.aspx"&gt;Beta&lt;/a&gt;) to see if there is anything new that is of interest to me. Today i came across Article &lt;a href="http://support.microsoft.com/kb/913086/en-us"&gt;913086 &lt;/a&gt;which describes an alternative way of obtaining all Microsoft Security patches for all Operating systems and languages.&lt;/p&gt;
&lt;p&gt;The ISO image files are intended for corporate administrators who:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Manage large multinational organizations.&lt;/li&gt;
&lt;li&gt;Must download multiple individual language versions of each security update.&lt;/li&gt;
&lt;li&gt;Do not use an automated solution such as Microsoft Windows Server Update Services (WSUS).&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>ToolTip - chml.exe manage Windows Integrity Levels</title><link>https://www.verboon.info/2008/10/tooltip-chmlexe-manage-windows-integrity-levels/</link><pubDate>Mon, 20 Oct 2008 19:02:34 +0000</pubDate><guid>https://www.verboon.info/2008/10/tooltip-chmlexe-manage-windows-integrity-levels/</guid><description>&lt;p&gt;To be honest i haven&amp;rsquo;t gone into the details of the Windows Integrity Levels myself but wanted to mention the &lt;a href="http://www.minasi.com/vista/chml.htm"&gt;chml.exe &lt;/a&gt;tool that can be downloaded from Mark Minasi&amp;rsquo;s &lt;a href="http://www.minasi.com/"&gt;web site&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;More details about the Windows Vista Integrity Mechanism can be found &lt;a href="http://msdn.microsoft.com/en-us/library/bb625964.aspx"&gt;here&lt;/a&gt;:&lt;/p&gt;</description></item></channel></rss>