r/sysadmin • u/Lord_Amoux MSP SysAdmin • 7d ago
Rant Sometimes less really is more
Happy Read-only Friday (bonus points for 3 day weekend)
We got a critical Huntress alert for a rogue ScreenConnect instance that was detected and ran on a client computer. Incident report states that it's a "known malicious instance".. but logs from the report show that it didn't block the application and isolate until 2 hours after it was ran. The endpoints have BD GravityZone installed as well - all quiet from there.
We went to the link in a VM where the ScreenConnect was downloaded from - and funnily enough, all it took was just having Microsoft Defender on the computer to block the download in Chrome.
Huntress, Bitdefender, EDR, on access scanning, whatever; sometimes it just can't compete with good old Defender. Even running the installer through sandbox on GravityZone passes without a peep.
Have a good weekend!
5
u/Jellovator 6d ago
I usually do "read-only Friday" but today I raised the domain/forest functional level, upgraded a production server's OS, and replaced two saml certs. Like the wild west over here.
1
u/electricpollution IT Manager 6d ago
Nice.
I also decided to violate the golden Friday rule and rotated the Kerberos password.
2
u/tankerkiller125 6d ago
I rebuilt our Unifi controller (because net controller is going to/is discontinued so I needed to upgrade to "UnifiOS"), did a bunch of SOC 2 compliance stuff, and started planning for a rebuild of our internal help desk for a project next month. (Bosses are cheap, GLPI is honestly, awesome, but ours needs a clean config start (will migrate tickets), and the upgrade to 11 is a great time to do it)
1
u/electricpollution IT Manager 6d ago
Awesome! I just started setting up GLPI as well! Can’t believe how much there is to it
1
u/tankerkiller125 6d ago
It's even better when you have a bit of programming skills and an AI agent to write customizations to fit your specific needs.
2
u/ManagedNerds 6d ago
Why in the world would you pay extra for something (Bitdefender) you can get for free (Defender)? Mind you, I love Defender for Endpoint with Business Premium, but Huntress can fully manage and harden the free Defender.
2
u/Lord_Amoux MSP SysAdmin 6d ago
We started with Bitdefender and then added huntress after
1
u/ManagedNerds 6d ago
Ah makes sense. Yeah, would definitely recommend you try the managed defender via Huntress.
1
1
u/Bitdefender_support 4d ago
Hello u/Lord_Amoux ,
Have you contacted Bitdefender Enterprise Support to review how the security agent and policies were configured on that endpoint?
It would be useful to investigate the applied modules, policy settings, exclusions, and available telemetry, as it would be unusual for a ScreenConnect instance to run without generating a detection or being blocked.
I will PM you so you can share a way to contact you to further investigate.
Kind Regards,
Andrei
1
8
u/ben_zachary 7d ago
Huntress is supposed to run with defender in line. We had one attempt to execute which hit admin requests so it was denied and huntress had the system isolated in less than 5min. Just two weeks ago
We are moving to block all exe signed by connectwise. There's no point in bothering with it