Sec. Forge Hub
1.02K subscribers
56 photos
11 files
36 links
Security tools, automation, and insights - from pocket helpers to CI/CD integrations.
Built for red teamers, security engineers, and everyone shaping cyber defense.
Download Telegram
πŸ‘‰ I believe the Telegram channel should bring real value to subscribers. πŸ‘ˆ

πŸ’₯ New column for Monday: Job Offers. πŸ’₯

As a Senior Security Engineer, become part of a cross-functional development team engineering experiences of tomorrow. We are seeking a highly skilled and motivated Senior Security & Penetration Tester.

In this role, you will be responsible for identifying and mitigating security vulnerabilities in a project in the biomedicine field. You will proactively test our applications, including infrastructure, ensuring our digital assets are secure against emerging threats.


πŸ’¬ For details, please contact me via direct: @V4nd3R πŸ’¬

#cybersecurity_career #job_offers #security
✍2
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ› οΈ How digital signatures works? πŸ› οΈ

#info_security #cryptography #integrity
πŸ”₯2🀝1
C2 techniques used by hackers.

#ThreatHunting #DFIR #SOC
❀1πŸ‘1
πŸ”₯ SPF Attacks: Quick Overview

1️⃣ Alignment Bypass
SPF checks MAIL FROM, not the visible From - easy spoofing.

2️⃣ SoftFail Abuse
~all / ?all often deliver anyway.

3️⃣ Lookalike Domains
Fake domains with valid SPF look legit.

4️⃣ DNS Poisoning (no DNSSEC)
SPF TXT records can be spoofed.

5️⃣ Macro Abuse
Macros leak info or behave unpredictably.

6️⃣ Oversized SPF
>10 lookups β†’ PermError β†’ sometimes treated as pass.

7️⃣ Subdomain Takeover / Abuse
Forgotten subdomains with weak policies.

8️⃣ Trusted Sender Hijack
Compromised authorized mail services = SPF pass.

πŸ’‘ Takeaway

SPF alone is weak. Use DKIM + DMARC enforcement.
πŸ”₯2πŸ‘1
🚨 110+ Splunk Queries for SOC Analysts ⚑

Collection of real-world detection queries a goldmine for SOC analysts, threat hunters, and blue teamers.

#SOC #Blue_Team #security
πŸ”₯4
☠️ EVADING EDR ☠️

The Definitive Guide to Defeating Endpoint Detection Systems.

#Offensive #Red_Team #penetration_testing
πŸ”₯3
🧨 This github repository contains a collection of 150+ tools and resources that can be useful for red teaming activities. 🧨

Some of the tools may be specifically designed for red teaming, while others are more general-purpose and can be adapted for use in a red teaming context.

Get it πŸ‘‰ Here

#Offensive #Red_Team #penetration_testing
πŸ‘2
πŸ› οΈ Security Operations Centre πŸ› οΈ

Exploring this SOC Analyst guide really highlights how critical structured security operations are in today’s evolving threat landscape.

#SOC #Blue_Team #Cyber_Sec
πŸ”₯3
🧨 JWT Hacking Toolkit: 20 Real Hacker Techniques to Master Authentication Attacks 🧨

Get it πŸ‘‰ Here

#Offensive #Red_Team #penetration_testing
πŸ”₯3
πŸ€– Using Artificial Intelligence (AI) in Cybersecurity: Automate Threat Modeling with STRIDE GPT πŸ€–

The STRIDE methodology has been the gold standard for systematic threat identification, categorizing threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. However, applying STRIDE effectively requires not just understanding these categories but also having the experience to identify how they manifest in specific application architectures.

To solve this problem, we have πŸ’₯ STRIDE GPT πŸ’₯ By combining the analytical power of AI with the proven STRIDE methodology, this tool can generate comprehensive threat models, attack trees, and mitigation strategies in minutes rather than hours or days.

In this article, we’ll walk you through how to install STRIDE GPT, check out its features, and get you started using them.

πŸ‘‰ Let’s get rolling!

#SOC #Blue_Team #Cyber_Sec
πŸ”₯3
Nyx (goddess of the night in Greek mythology) is a self-contained script for cleaning forensic traces on Linux, macOS, and Windows.

GitHub: πŸ”— Here

#Offensive #Red_Team #penetration_testing
❀1πŸ”₯1
πŸ’₯ NEW RECENT THREAT: React2Shell: CVE-2025-55182 πŸ’₯

Learn about CVE-2025-55182 (React2Shell) and understand how the Flight protocol and deserialization work, dissect a working PoC, and exploit a vulnerable server. Furthermore, explore detection and mitigation.

Lear about: πŸ‘‰ Here

#Offensive #Red_Team #penetration_testing
πŸ”₯2
⚑ Kali Linux Wireless Penetration Testing Cookbook ⚑

Identify and assess vulnerabilities present in your wireless
network, Wi-Fi, and Bluetooth enabled devices to improve your
wireless security.

#Offensive #Red_Team #penetration_testing
πŸ‘2
πŸ’€ Practitioners Guide to Ransomware Response and Recovery is a comprehensive guide for responding to and recovering from ransomware incidents. πŸ’€

The guide is designed for industry professionals and includes detailed checklists, resources, and tools.

It offers detailed checklists, resources to aid in effectively managing and mitigating ransomware attacks.

Get it: πŸ‘‰ Here

#SOC #Cyber_Crime #ransomware
πŸ”₯2
Azure Red Team: Azure Security Resources and Notes

Learn about: πŸ‘‰ Here

#Offensive #Red_Team #penetration_testing
πŸ‘1πŸ”₯1