CISO as a Service
5.16K subscribers
4.74K photos
770 videos
1.89K files
6.99K links
Founder @ DiyakoSecureBow | CISO as a Service (vCISO)
About Me
http://about.me/Alirezaghahrood

Follow Me on
🔵LinkedIn
https://www.linkedin.com/in/AlirezaGhahrood
🔴YouTube
https://www.youtube.com/AlirezaGhahrood
X
https://twitter.com/AlirezaGhahrood
Download Telegram
Bug Bounty Bootcamp - The Guide to Finding and Reporting Web Vulnerabilities 2021

Info: https://lnkd.in/dwujwzq


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.10


#bugbounty #bugbountytips #bughunting #bugcrowd #hackerone
Bug_Bounty_Bootcamp_The_Guide_to_Finding_and_Reporting_Web_Vulnerabilities.pdf
3.2 MB
Bug Bounty Bootcamp - The Guide to Finding and Reporting Web Vulnerabilities 2021


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.10


#bugbounty #bugbountytips #bughunting #bugcrowd #hackerone
Researchers warn of ongoing cyberattacks coordinated by a Chinese-speaking threat actor targeting the Afghan government.

https://thehackernews.com/2021/07/indigozebra-apt-hacking-campaign.html


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.10
https://azurecloudai.blog/2021/06/30/how-to-use-the-watchlists-logic-app-connector-for-azure-sentinel/amp/


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.10
Media is too big
VIEW IN TELEGRAM
حاصل نظام تربیت و آموزش

راي به براندازي نظام آموزشي داخل كشور آيا!


- نظر شما چيست!؟-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.10
🔥 WATCH OUT! Microsoft warns of critical PrintNightmare RCE vulnerability (CVE-2021-34527) being exploited in the wild.

Details: https://thehackernews.com/2021/07/microsoft-warns-of-critical.html

It is separate from the Windows Print Spooler issue (CVE-2021-1675) Microsoft patched recently.


FBI and NSA reveal hacking techniques used by Russian military hackers to target U.S. and European military, government, and political entities.
Details — https://thehackernews.com/2021/07/nsa-fbi-reveal-hacking-methods-used-by.html


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
ReDMArk.pdf
470.4 KB
Research
"ReDMArk: Bypassing RDMA Security Mechanisms", 2021.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
smart_contract.pdf
90.6 KB
Whitepaper
"Smart Contract Automated Testing Guidelines", 2021.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
TeeRex.pdf
732.4 KB
Research
"TEEREX: Discovery and Exploitation of Memory Corruption Vulnerabilities in SGX Enclaves", 2020.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
intel_csme_security.pdf
1005.8 KB
Whitepaper
Intel Converged Security and Management Engine (CSME) Security Whitepaper, 2020.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
Obfuscated_Access.pdf
2 MB
Research
"Obfuscated Access and Search Patterns in Searchable Encryption", 2021.
]-> Code to run the evaluation:
https://github.com/simon-oya/NDSS21-osse-evaluation


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
Securing_Remote_Access_in_Palo_Alto_Networks.epub
19.2 MB
Tech book
"Securing Remote Access in Palo Alto Networks: Practical techniques to enable and protect remote users, improve your security posture, and troubleshoot next-generation firewalls", 2021.


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
service_mngmnt_infosec_collaborate.pdf
635.7 KB
Blue Team Techniques
"IT Service Management and Infosec: Collaborate for Mutual Success", 2021


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
Take part in the RangeForce Persistence Challenge July 21 - August 8!

Later this month, we’ll be running exclusive cyber range exercises for members of the RangeForce Community Edition.

Compete for a chance to win prizes while sharpening your cybersecurity skills. Stay tuned for more details about the challenge.

Not yet a member of our free Community Edition? Join now: https://hubs.ly/H0R31lS0


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
وقتي مي‌گوييد به نام خدا،
نشانه آن اين است که خدا با شما باشد.
اگر نيست و حضورش در کارتان آشکار نيست،
پس هنوز به واقع نگفته‌ايد به اسم خدا.

اگر خدا با انسان باشد، نشانه‌ ها دارد.
نشانه حضور خدا چيست؟
نور است، شفا و برکت است، قدرت و توفيق است
بخشش و محبت است، حمايتي عظيم و پشتيباني شديد، قبول نکردن ظلم، چاپلوسی نکردن، بی منت بخشیدن...


پ ن:
گویند مردی از گرسنگی رو به مرگ بود. شیطان برای او غذایی آورد، به شرط آنکه ایمانش را به او بفروشد. مرد پس از سیری، از فروختن ایمان خود ابا کرد و گفت:
آنچه در گرسنگی فروختم، موهوم و معدومی بیش نبود، چرا که: آدم گرسنه دین و ایمان ندارد!


-گرگ گرسنه چو یافت گوشت، نپرسد
کاین شتر صالح است یا خرِ دجال-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
Media is too big
VIEW IN TELEGRAM
-😂🤣-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
ديشب خواب ديدم رفتم واكس بركت بزنم🤓، اشتباهي بهم انسولين زدند! يعني مسولين حتي تو خواب هم نميتونن يه كار درست بكنن🥸


-😂🤣-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.11
Encryption speed comparative table for some ransomware


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.12
security_reference_architecture.pdf
1.5 MB
Cloud Security
AWS Security Reference Architecture:
A guide to designing with AWS security services
(.pdf)
]-> https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/welcome.html
]-> Example solutions demonstrating how to implement the AWS Security Reference Architecture using AWS Control Tower, AWS Landing Zone, and CloudFormation:
https://github.com/aws-samples/aws-security-reference-architecture-examples


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.12
Malware analysis
1. IndigoZebra APT continues to attack Central Asia with evolving tools
https://research.checkpoint.com/2021/indigozebra-apt-continues-to-attack-central-asia-with-evolving-tools
2. Shelob Moonlight - Spinning a Larger Web
From IcedID to CONTI, a Trojan and Ransomware collaboration
https://www.cynet.com/attack-techniques-hands-on/shelob-moonlight-spinning-a-larger-web/?utm_content=171192942&utm_medium=social&utm_source=linkedin&hss_channel=lcp-9363621

Threat Research
1. The Complicated History of a Simple Linux Kernel API
https://grsecurity.net/complicated_history_simple_linux_kernel_api
2. Exploiting Insecure Deserialization Vulnerabilities Found in the Wild
https://macrosec.tech/index.php/2021/06/22/exploiting-insecure-deserialization-vulnerabilities-found-in-the-wild

exploit
CVE-2020-24511:
Improper isolation of shared resources in some Intel Processors may allow an authenticated user to potentially enable information disclosure via local access (PoC)
https://github.com/AlAIAL90/CVE-2020-24511


‎-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.04.12