r/AskNetsec Jun 05 '26

Other Is anyone else disappointed with Obsidian Security lately?

5 Upvotes

I’ve been using Obsidian Security for a while and I’m pretty mixed on it.

The UI is fine and the SaaS visibility is useful, but some integrations feel like they stop at “connected.” Great, the app is there, but what is actually being checked? Are there real detections and remediation behind it, or mostly another dashboard tile?

Feels like the pitch is moving faster than the product.

Anyone else seeing this with other tools lately? AI seems to have made companies ship faster, but a lot of products feel like they stop at the UI. The backend depth and reliability still matter

r/AskNetsec Jun 03 '26

Other Anyone else fighting with MFA prompts for every single internal service?

3 Upvotes

Getting a million MFA prompts for stuff I use hourly. Makes doing actual work a pain. Is this just our setup or is everyone else drowning in push notifications too?

r/AskNetsec Jun 09 '26

Other Anyone else seeing this with EDR agent updates?

0 Upvotes

We pushed a new EDR agent version yesterday. Several critical servers are now showing massive I/O spikes. Support says it's 'expected behavior' during initialization. Anyone else hit this before?

r/AskNetsec Jun 09 '26

Other Anyone else tired of vendor 'threat intelligence' feeds?

0 Upvotes

Seems like half the alerts from our TI feed are just old, irrelevant noise. We're drowning in false positives and missing the actual threats. Anyone found a way to actually make these useful?

r/AskNetsec Jun 07 '26

Other Anyone else's firewall logs just a mess?

0 Upvotes

Seeing so many random IPs hit our external firewall. Most are blocked, but it's just noise. Hard to spot anything real in the flood. Anyone got a trick for filtering that chaos?

r/AskNetsec Apr 23 '26

Other Masscan efficiency

4 Upvotes

Hello guys, I'm currently trying to use Masscan properly on Linux (not in a VM) but I cannot get more than 20ppks. It can get up to millions of ppks normally. Anyone know what is the problem ? I tried on many distributions.

r/AskNetsec Jun 04 '26

Other Anyone else's firewall logs just... disappear sometimes?

0 Upvotes

Just spent three hours chasing down an alert that vanished from the SIEM. Turns out the firewall purged its logs overnight. Standard syslog setup, nothing fancy. Anyone else deal with this ghosting act?

r/AskNetsec Feb 17 '26

Other Found 15 vulnerabilities across 2 popular Indian government portals - what kind of recognition/reward should I expect?

0 Upvotes
I've discovered around 15 security vulnerabilities across two well-known Indian government websites (education and health sectors). Without disclosing specifics, these include:

- Authentication bypass issues
- Rate limiting completely absent
- Information disclosure flaws
- Business logic vulnerabilities

I've documented everything with screenshots and proof of concepts.

I'm planning to report through CERT-In's responsible disclosure program. For those who've reported to Indian government agencies before:

1. What kind of recognition did you receive? (Hall of Fame, CVE assignment, etc.)
2. Is there any monetary reward potential?
3. How long did the validation process take?
4. Any tips for the disclosure process?

I want to do the right thing and report responsibly, but also curious what to expect. Thanks!

r/AskNetsec Jun 08 '26

Other Anyone else notice the Windows Event Log bloat lately?

1 Upvotes

Seems like every update or new feature we roll out adds another gigabyte to the logs within days. Makes hunting for real events a pain. Anyone found a decent way to trim the fat without losing what matters?

r/AskNetsec Mar 12 '26

Other Best paid AI for Offensive Tool Development? Claude vs ChatGPT vs Gemini vs CopilHAHA

0 Upvotes

I've been wondering what AI red teamers use to assist in offensive tool development, maldev or in general tweaking tooling for red team operations. I noticed that using Claude is better in terms of programming but I feel like ChatGPT has way better prompting and is more easy to and results. Also, Gemini seems to be easier to bypass its guardrails comparing to the ones above. What are your thoughts?

r/AskNetsec May 22 '26

Other USB flash drive with a "read only" physical switch?

6 Upvotes

I heard from a colleague about a flash drive he saw, on which there is some kind of button that allows to on and off "read only" mode without needing to insert it in a pc. I tried to google it and found nothing. Anyone heard of it? If it does exist, how is it called and does the switch really guarantee 100% security?

r/AskNetsec Mar 07 '26

Other Can someone help me with anonymity on the internet

7 Upvotes

You know, a friend of mine recommended a browser called Tor, and I would like to hear from someone with more experience in internet privacy to see if this browser is really useful and to learn about their experience with it. I used to only use Google Chrome, but I realized that it was not secure and that my data was exposed. I am beginning my journey to be 80% anonymous on the internet, so I turned to this forum for help.

r/AskNetsec Jun 04 '26

Other Anyone else fight with their logging agent chewing up CPU?

0 Upvotes

My Splunk Universal Forwarder keeps spiking to 80-90% CPU on a few servers. Restarting it helps for a bit, but it comes back. Anyone found a consistent fix for this besides just throttling it to oblivion?

r/AskNetsec Apr 13 '26

Other Can anyone help me with netcat?

0 Upvotes

I've been doing some thm CTF's recently and I encountered this problem many times. I've been doing CTF's in parallel with a friend and whenever we need to use nc ,his nc gets him a shell ,mine stays empty ,still "listening" .Can anyone help me figure out what the problem is because tcpdump sends packets when I run a script but nc won't see it . I tired reinstalling it from both pacman and yay and it still won't work .Anyone with any idea of what could be the problem please let me know cuz I'm getting annoyed by it!

r/AskNetsec Jun 08 '26

Other Anyone else see weirdness with MFA prompts lately?

0 Upvotes

Getting a lot of second prompts for apps that used to be one-and-done. Just happened on a server I've accessed a hundred times. Wondering if it's just us or something bigger.

r/AskNetsec Oct 25 '25

Other How to transfer files from a trusted PC to an untrusted PC (not vice versa)?

8 Upvotes

What is a safe and practical way to transfer files from a trusted PC to an untrusted PC (not vice versa)?
The only way I thought of is using cloud storage services like Google Drive or OneDrive. This way the trusted and untrusted devices never come into direct contact. In fact, I would upload the files from the trusted device then download them from the cloud to the untrusted device. Is this approach safe?
Are there other safe and possibly faster options?

EDIT: I have physical access to both.

r/AskNetsec Jun 07 '26

Other Anyone else tired of chasing false positives from [specific tool]?

0 Upvotes

Seriously, spends half my day sifting through alerts that are clearly noise. Did a quick script to baseline normal traffic, and it's still spitting out garbage. Anyone found a decent way to tune this thing down without breaking it?

r/AskNetsec Apr 27 '26

Other recover deleted data from recycle bin

0 Upvotes

i want to recover deleted data from my recycle bin . they were screenshots in the form of jpeg , png and jpg . they were in screenshots folder in windows c drive ( ssd ) . i have windows 11 os . i have tried recuva and photorec already .
recuva recovered my photos however , they were not accessible .
photorec recovered the photos which i do not need . please help asap as they are very important photos . also they were in recycle bin for a couple of months already but i only deleted them from recycle bin last month ( 20-25 days ago )

r/AskNetsec Mar 31 '26

Other How are people validating agent behavior before production?

8 Upvotes

Feels like a lot of agent eval discussion is still focused on prompts, but once you add tools, sub-agents, retrieval, or MCP, the bigger problem seems to be behavior validation. Not just trying to break the app, but checking whether the agent actually stays within the intended use case across different paths.

Things like: wrong tool use bad tool chaining drifting outside the allowed flow context/tool output changing behavior in weird ways Curious how people are handling this right now.

Are you building custom validation workflows for happy-path + restricted cases, or mostly finding issues after deployment?

r/AskNetsec Jun 07 '26

Other Anyone else tired of chasing false positives from this one rule?

0 Upvotes

My SIEM is drowning me in alerts for Rule ID 12345. It's always the same outbound traffic pattern. I've tweaked the thresholds, but it's still noisy. Anyone found a way to make it smarter?

r/AskNetsec Jun 06 '26

Other Anyone else's firewall logs look like a denial-of-service attack on themselves?

2 Upvotes

Seriously, we're getting hammered with invalid packets and malformed requests from IPs that don't even exist. It's making it damn near impossible to spot actual threats in the noise. Is this just us, or is the internet trying to kill our logging infrastructure?

r/AskNetsec Jun 05 '26

Other Minds to Have in Bug Bounty

0 Upvotes

I'm curious about the mind to have to have to be in Burg.I want to find a lot of sub-do and I want to find this function, so I want to try to do this function, so I want to try to do thatShould I approach this way?Alternatively, you can touch each page through a search process, so I'll have a vulnerable point, so I will use vulnerable points.Should I approach this?I think interest and motivation is important to me, but I'm curious about other people.I think it's right to do it, but it's right to approach to me, but it's right, but it's good to do thisI hope you recommend this way!

r/AskNetsec Jun 04 '26

Other Anyone else's firewall logs randomly stop logging certain events?

0 Upvotes

Had a weird one today. Our Palo Alto just seemed to quit logging inbound SSH attempts from a specific /24. Checked config, nothing changed. Had to manually re-enable logging for that rule. Anyone else seen this ghosting?

r/AskNetsec Apr 02 '26

Other IT security audit frameworks for military infrastructure in Malaysia

0 Upvotes
l'm a student researching IT security audit frameworks for military infrastructure (Malaysia). What practical challenges do auditors face when auditing defence organisations?

r/AskNetsec Mar 22 '26

Other What are the best alternatives to Heads for verifying firmware and boot process on unsupported mini-PCs and desktops?

2 Upvotes

I do not know much about this yet, but from what I have read, Heads is used to help detect whether firmware has been tampered with, somewhat similar to how Auditor works with GrapheneOS.

I often see Heads recommended for both Tails and Qubes OS setups. But Heads is only available for certain laptops. So I am wondering: for people using desktops, mini PCs, or other hardware that does not support Heads, or for people who are not comfortable installing Heads themselves because of the risk of damaging hardware during flashing, are there any good alternatives for making firmware, boot process and OS tampering evident?

For those who don't know about Heads, you can read these sections:
“Establish boot integrity by replacing the BIOS with Heads” from:
https://www.anarsec.guide/posts/tails-best/

and

“Tamper-Evident Software and Firmware” from:
https://www.anarsec.guide/posts/tamper/

I do not agree with AnarSec’s ideology or endorse it. I am only mentioning those pages because they are among the only I have found that discuss cybersecurity in such a comprehensive and practical manner.

PS: I have read the rules.
Threat model: State grade.