Services
Priority DM . 3 days reply
Video meeting . 30 mins
Video meeting . 30 mins
Video meeting . 60 mins
Video meeting . 30 mins
Video meeting . 30 mins
Video meeting . 30 mins
About me
- [ ] I have experience into Siem technology like QRadar, Logarithm apart from those I have experience into EDR, Crowdstrike.
- [ ] Coming to QRadar my day to day responsibilities are dashboard validations and QDI( QRadar deployment intelligence) health checks and offence investigation on daily basis.
- [ ] Dashboard validation: checking the threat and security monitoring dashboard mostly checking on the most recent offences , most severe offences , top category offences and offences triggering from the top source IP’s.
- [ ] QDI( Radar deployment intelligence): Checking the event collectors and flow collectors, disc spaces and CPU utilization. Monitoring and mentioning it in shift handover.
- [ ] Offences: we use to get mostly user login failures, firewall permits, firewall denies, proxy alerts, IPS related alerts user behaviour analytics related alerts.
- [ ] Coming to EDR I used to work on crowd strike alerts. For example: if someone is using third party applications or if the machine detected any malware alerts, we will contact to employee by using teams, if he is not available we will do RTR and remove particular file.
- [ ] Crowdstrike is dealing with AV in our organisation at present we are not using any Anti-Virus. Some endpoints do have AV we working on same of them. Mostly crowd strike is taking care of all endpoints in our organisation.
- [ ] Coming to Symmentic AV i pull the weekly reports and we used to check whether AV is installed in some endpoints and servers.
- [ ] Coming to Symmentic DLP we used to monitor email gateways and checking , email attachment files whether user is trying to send companies data or personal data.
- [ ] we asked for business justification and we do escalation as per the IS[Info sec] policy violation.
- [ ] we whitelisted the email id’s on users business justification (whether he want to sent any business related documents) by getting approval as per the hierarchy and we used to work on user action block when ever a user is trying to upload or send any data to cloud.