CISO as a Service
5.17K subscribers
4.74K photos
770 videos
1.89K files
6.99K links
Founder @ DiyakoSecureBow | CISO as a Service (vCISO)
About Me
http://about.me/Alirezaghahrood

Follow Me on
🔵LinkedIn
https://www.linkedin.com/in/AlirezaGhahrood
🔴YouTube
https://www.youtube.com/AlirezaGhahrood
X
https://twitter.com/AlirezaGhahrood
Download Telegram
آمار قابل توجه برای الویت دهی ریسک های امنیت محور


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
NIST.SP.800_161r1_draft.pdf
4 MB
NIST SP 800-161 Rev.1 (Draft):
"Cyber Supply Chain Risk Management Practices for Systems and Organizations", 2021.
]-> https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/draft


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
D3FEND.pdf
1.7 MB
Research
"Toward a Knowledge Graph of Cybersecurity Countermeasures", MITRE, 2021.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
Atlassian_ATO.pdf
1.9 MB
Whitepaper
"A supply-chain breach:
Taking over an Atlassian account".


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
Dark_Web_Investigation.pdf
5.4 MB
Tech book
"Dark Web Investigation
(Security Informatics and Law Enforcement)", 2021.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
ZenGRC is a cloud-based and on-premise governance, risk and compliance (GRC) management solution. It serves businesses of all sizes in any industry, including technology, retail, consumer goods, health care and finance. Primary features include audit management, compliance management, contract and policy management, risk assessment and reporting.
ZenGRC helps users in internal auditing, compliance and information security teams. With it, these teams can manage and implement audit and compliance processes. It automates audit evidence collection, routine compliance and helps with the creation of new compliance programs. Other features include team collaboration, role-based access, project management, import and export and dashboards.

Managing compliance isn’t getting any easier.
Managing it with spreadsheets only makes it harder

https://www.linkedin.com/posts/alirezaghahrood_managing-compliance-isnt-getting-any-easier-activity-6814806100257333248-O9ug


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
Forwarded from HamidReza
سلام استاد
اگر دوست داشتین خدمت حضرتعالی:

https://events.sophos.com/americatha2021?cmp=123157
This media is not supported in your browser
VIEW IN TELEGRAM
مميزي ميبايست بصورت فني و سيستمي در يك چرخه مشخص براي حوزه فناورانه و آي تي
سازمان لحاظ گردد، تا بتوان اشراف داشت به شرايط جاري سازمان، ريسك ها و چالش هاي جاري

و سپس برنامه ريزي كرد براي بهبود معماري، …. امنيت سازمان!


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
https://courses.thecyberinst.org/collections
Free OSINT Courses and Free OSINT Challenges.

Payed also available if interested. Check this institution.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
Dell_Bios_Disconnect.pdf
450.1 KB
Threat_Research
"BIOS Disconnect", 2021.
// Eclypsium Discovers Multiple Vulnerabilities Affecting 128 Dell Models via Dell Remote OS Recovery and Firmware Update Capabilities
]-> https://eclypsium.com/2021/06/24/biosdisconnect


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
BPF_Internals.pdf
2.7 MB
Research
"BPF Internals (eBPF):
Tracing Examples
", 2021.
]-> https://brendangregg.com/blog/2021-06-15/bpf-internals.html


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
This media is not supported in your browser
VIEW IN TELEGRAM
🤣😂😅🤪🤲🏻


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.06
#جذب #استخدام

جذب دو متخصص، كارشناس مجازي سازي ، ترجيحا آشنا به استوريج EMC
رنج حقوق ٧-١١ م ت
يك شركت خصوصي خوش نام

ارسال رزومه مرتبط و به روز به
اي دي تلگرام
@alirezaghahrood
912/196 4383


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.07
The hackers Hackers responsible for the SolarWinds breach also compromised a Microsoft customer service agent and attempted to further target company's customers.
Details — https://thehackernews.com/2021/06/solarwinds-hackers-breach-microsoft.html


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.07
4_5962959424979994922.pdf
657.7 KB
این متن پیش نویس نهایی طرح جنجالی مجلس برای محدودیت اینترنته

طرحی که به گفته ی خیلی از مردم حتی اصولگرایان منجر به وقوع حوادثی مشابه آبان می شه


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.07
Cisco Adaptive Security Appliances (ASA) have been actively targeted by hackers following the release of exploit code for a security vulnerability (CVE-2020-3580)
Read: https://thehackernews.com/2021/06/cisco-asa-flaw-under-active-attack.html


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.07
Threat Research
Pandora FMS 754 - Stored XSS and RCE
https://k4m1ll0.com/cve-pandorafms754-chained-xss-rce.html

WLAN Security
RomBuster is a router exploitation tool that allows to disclosure network router admin password😨
https://github.com/EntySec/RomBuster

Generate .NET dropper with AES and XOR obfuscated shellcode
https://securityonline.info/sharperner-generate-net-dropper-with-aes-and-xor-obfuscated-shellcode
]-> https://github.com/aniqfakhrul/Sharperner/releases

exploit
CVE-2021-31955:
Windows Kernel Information Disclosure Vulnerability (PoC)
https://github.com/mavillon1/CVE-2021-31955-POC


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.07
Offensive security
1.LEXSS: Bypassing Lexical Parsing Security Controls
https://labs.bishopfox.com/tech-blog/lexss-bypassing-lexical-parsing-security-controls
2,MODeflattener - Miasm's OLLVM Deflattener
https://mrt4ntr4.github.io/MODeflattener

Red Team Tactics
1. Bypassing 403 Forbidden Error
https://infosecwriteups.com/403-forbidden-bypass-leads-to-hall-of-fame-ff61ccd0a71e
2. A Glossary of Blind SSRF Chains
https://blog.assetnote.io/2021/01/13/blind-ssrf-chains

exploit
CVE-2021-1757:
AppleH10CamIn OOB Write (PoC)
https://github.com/b1n4r1b01/n-days


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.07