Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials SyntheticSun : A Defense-In-Depth Security Automation And Monitoring Framework SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, managed AWS security…
iderations for Production deployments

SyntheticSun, by virtue of being something you found on GitHub, is a proof-of-concept and therefore I did not go the extra mile for the first release to absolutely harden everything. Provided you are reading this at a point in time where I have not made the necessary changes, consider the following before you deploy this solution into a production environment (or any environment with heightened security needs). I will put these items on a roadmap and update them as appropiate.

* Train your own IP Insights models using the examples provided in Appendix A. Using your own data, and continually retraining the model, will help accurize findings.
* Deploy your CodeBuild projects, MISP server, and Elasticsearch Service domain in a VPC in order to harden against internet-borne attacks. Consider using AWS’ Client VPN, AWS Site-to-Site VPN, DirectConnect, Amazon Workspaces, and AppStream 2.0 or (if you absolutely have to) a reverse-proxy to access the MISP console and Kibana within a VPC.
* Consider using Cognito for AuthN into Kibana. Go a step further and federate your User Pool with your corporate IdP.
* Consider baking your own AMI for MISP or use Fargate to host it. I would also consider pre-baking Suricata and the Amazon CloudWatch Agent into future builds to help scale deployments of agents and HIDPS across your estate.
* Modify your Suricata configuration to suit the needs of your SecOps teams looking at the logs, since all this solution does is dump them in. You may also consider writing your own rules or importing other sources to harden your hosts against attacks. Download

___________________________
@hacking_Attack
@Hacking_Video
VM labs
https://www.reddit.com/r/Pentesting/comments/t2r2q1/vm_labs/

Hi, is there a trusted source where I can download ISO images for Windows? I’m learning how to pentest. I know there’s the official Microsoft ISO images for Windows 10, 11, and Server on Microsoft’s site. But I’m also looking for XP and 7 as well. Or does it not matter? submitted by /u/j_relic (https://www.reddit.com/user/j_relic)
[link] (https://www.reddit.com/r/Pentesting/comments/t2r2q1/vm_labs/) [comments] (https://www.reddit.com/r/Pentesting/comments/t2r2q1/vm_labs/)

___________________________
@hacking_Attack
@Hacking_Video
Attacking IBM MQ — SWIFT to Steal Money$$$

What is IBM MQ?Continue reading on Medium »
Read more...
Pentesters of the World, join Ukraine in our fight for freedom
https://www.reddit.com/r/Pentesting/comments/t2stew/pentesters_of_the_world_join_ukraine_in_our_fight/

Hello pentesters of the world! Probably you heard of Russian invasion to Ukraine. We are fighting in all spheres and also in cyberspace. Any help is good. There are 20k+ members here, if all of you would spend 1 hour in pentesting any russian service/website/news etc it would be 20k hours of searching. Any information is useful and can and will save lives. They are bombing, shooting and killing people of my country, launching rockets directly to kindergartens and civil houses. I'll send in a short while a link where you can send any information to Ukrainian secure service (Wanted to have an official link so you can be sure it's not any scam. They will put it in their official page). Again, any information is helpful. Thank you for your help! submitted by /u/mrVengr (https://www.reddit.com/user/mrVengr)
[link] (https://www.reddit.com/r/Pentesting/comments/t2stew/pentesters_of_the_world_join_ukraine_in_our_fight/) [comments] (https://www.reddit.com/r/Pentesting/comments/t2stew/pentesters_of_the_world_join_ukraine_in_our_fight/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is college worth it for cybersecurity?

So, I'm 18 and about to graduate, and my parents are kind of pressuring me into college, while I don't really know if I want to go. My aim is to get an IT helpdesk job and work on certifications but now I'm kind of doubting it.

I thought I'd ask here since it's more relevant to the industry, but what are your opinions regarding college and the cybersec field? Am I going to be fucked for choosing to wait?

submitted by /u/TheByteQueen
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How does Anonymous manage to take down Russian websites?

I’m really curious about how they do this. With the rising escalation between countries, hearing about the hacking group has spiked my interest. How is it possible to take down these websites?

submitted by /u/RamenNutella
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Peaky Blinders

Hey can someone tell me how can i watch the peaky blinders. I dont haalve netflix, share some links if you can. Thanks

submitted by /u/yadavrao1869
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Anyone else noticed there has been a MASSIVE increase on social media accounts being hacked 2-3 days before the russian invasion of ukraine??

I manage some instagram theme pages as a side hussle, I started getting spammed with phishing links or people trying to social engineering me. I thought they were trying to hack my pages cause they are a little bit big and they could resell them for a profit, but then my friend's personal accounts also started to get hacked. Lot's of people on Reddit complaining about the issue too. One of my friends was dumb enough to put her password on a phishing link and then what it seemed to be like an automatic bot started messaging everyone related to her the phishing links. And as I said, all of this 1-2-3 days before the invasion, there was always a random individual trying to send some hacking attempts to my accounts from time to time, but this time it was like docens of dms, docens of accounts of people I know getting hacked in this short spawn of days. I read somewhere that one technique to hack important targets like politicians, leaders etc is instead of targeting directly them, which would be extremely difficult, they target accounts massively in hopes of getting the account of a relative of them and try to social engineer them from there. Am I being paranoid or this could really a Russian spy complot? Sorry if this doesn't make any sense XD

submitted by /u/godlike-dawn
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Attacking IBM MQ — SWIFT to Steal Money$$$

What is IBM MQ?Continue reading on Medium »
Read more...