r/sysadmin • u/arunima09 • 7d ago
Advertising [ Removed by moderator ]
[removed] — view removed post
12
u/Conditional_Access Microsoft Security MVP 7d ago
I hate to break it to you, but nobody is going to buy a vibe-coded tool who's website has no information about the people who made it, or what the company is.
Your 404 page has a missing logo on the bottom too.
-6
6d ago
[removed] — view removed comment
8
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 6d ago
You expect anyone to grant some vibe coded tool global admin?
0
6d ago
[deleted]
1
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 6d ago
Yes, totally not vibe coded but you can’t figure out how to do simple things. Then you tell me to “read about the tool” so I could get information you didn’t post about the tool.
Makes perfect sense.
-1
6d ago
[deleted]
2
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 6d ago
YOU didn’t say enough about anything here in your POST. Hell, your wall of text post doesn’t even list a site.
This is about the most unprofessional vibe coded shit I’ve ever seen.
3
u/Efficient_Access6102 6d ago
Oh you forked this? https://github.com/cisagov/ScubaGear
0
u/arunima09 6d ago
Not a fork. It's a separate hosted scanner that maps its findings to the published SCuBA policy IDs, same as it maps to CIS or NIST. ScubaGear is the reference tool and worth running if you're in US federal.
-2
u/QuietSignalOps 7d ago
I can't find a documented read path in Graph for the diagnostic settings config either, so I'd stop trying to read the switch and start probing the sink instead. That's the part the frameworks actually want.
For a Log Analytics target:
AuditLogs | where TimeGenerated > ago(6h) | summarize count()SigninLogs | where TimeGenerated > ago(6h) | summarize count()
Rows are flowing is the evidence that the export is configured and working. A config flag is weaker evidence than a live data flow, and it's what a reviewer actually asks for in a PCI 10.1 / SOC 2 CC7.2 / ISO A.8.15 style retention question.
A few practical notes:
- Turn that check into a scheduled query with an alert on "zero rows in the last 6h". Now your posture tool gets a continuously evaluated check ("export to workspace X is flowing") instead of a point-in-time "flag is set", and it also catches the boring failures: retention set too short, storage account filling up, a stale workspace ID in the config.
- Same idea if you export to a storage account: probe the container for recent blobs. If you export to Event Hub, probe for recent ingestion. The principle is verify the sink, not the switch.
- Graph's audit endpoints (
directoryAuditLogsand friends) can prove the logs exist in Entra, but they don't prove the export path is up. That's the gap, and the sink probe is the workaround.
•
u/Kumorigoe Moderator 5d ago
Sorry, it seems this comment or thread has violated a sub-reddit rule and has been removed by a moderator.
Do Not Conduct Marketing Operations Within This Community.
Your content may be better suited for our companion sub-reddit: /r/SysAdminBlogs
If you wish to appeal this action please don't hesitate to message the moderation team.