Free cybercrime intelligence tool - check any company domain and see how many of their employees and clients were compromised by info-stealers
https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/
<!-- SC_OFF -->Check domains for free across our database of over 5,700,000 computers compromised with info-stealers world wide - https://www.hudsonrock.com/are-you-compromised Also available via https://inteltechniques.com/tools/Breaches.html under "HudsonRock" What is it? - this free tool enables you to search for domains and see how many compromised employees & users they have from our continuously augmented cybercrime database, this can be useful for several reasons: Risk assessment - looking up a company and seeing they have a lot of compromised employees can indicate the company is not up to date with proper security measures, each compromised employee indicates that someone in the company downloaded and executed an info-stealing malware and had all their corporate credentials, cookies, documents, etc stolen by hackers who are using the credentials as an initial attack vector. Pre-breach intel - if you work at a company and see we have data relating to it, you can ask for an ethical disclosure from us for free, we provided hundreds of ethical disclosures regarding compromised credentials which are in the hands of hackers as a result of employees/clients having their computers infected. It is important to note that even with 2FA set in place, when a computer gets infected with an info-stealer they also have their cookies stolen which are then used to steal sessions and bypass 2FA, and that documents containing 2FA backup codes stored anywhere on the computer get captured by the info-stealer and allows the hacker to revoke phone-based 2FA. Assets discovery - we show the top 5 URLs that compromised employees & clients had credentials to, often times these URLs are not attainable anywhere else because internal URLs accessed by clients/employees are not indexed anywhere and cannot be scraped. What is it not? - this is not a tool that provides a full overview around who the employees and users that got compromised are, or how they got compromised. We cannot provide this data publicly as it is very sensitive and is only given as an ethical disclosure to the cybersecurity team of the company. If you work for a company that has compromised employees or clients, be sure to get a free ethical disclosure from us. Our high-fidelity cybercrime intelligence data is sourced directly from threat actors — not from database leaks or scrapes. If you liked this tool please share it, it is also accessible through API along with other free tools we provide such as checking if your own computer was compromised at some point (Preview API - https://cavalier.hudsonrock.com/docs) <!-- SC_ON --> submitted by /u/Malwarebeasts (https://www.reddit.com/user/Malwarebeasts)
[link] (https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/) [comments] (https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/)
https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/
<!-- SC_OFF -->Check domains for free across our database of over 5,700,000 computers compromised with info-stealers world wide - https://www.hudsonrock.com/are-you-compromised Also available via https://inteltechniques.com/tools/Breaches.html under "HudsonRock" What is it? - this free tool enables you to search for domains and see how many compromised employees & users they have from our continuously augmented cybercrime database, this can be useful for several reasons: Risk assessment - looking up a company and seeing they have a lot of compromised employees can indicate the company is not up to date with proper security measures, each compromised employee indicates that someone in the company downloaded and executed an info-stealing malware and had all their corporate credentials, cookies, documents, etc stolen by hackers who are using the credentials as an initial attack vector. Pre-breach intel - if you work at a company and see we have data relating to it, you can ask for an ethical disclosure from us for free, we provided hundreds of ethical disclosures regarding compromised credentials which are in the hands of hackers as a result of employees/clients having their computers infected. It is important to note that even with 2FA set in place, when a computer gets infected with an info-stealer they also have their cookies stolen which are then used to steal sessions and bypass 2FA, and that documents containing 2FA backup codes stored anywhere on the computer get captured by the info-stealer and allows the hacker to revoke phone-based 2FA. Assets discovery - we show the top 5 URLs that compromised employees & clients had credentials to, often times these URLs are not attainable anywhere else because internal URLs accessed by clients/employees are not indexed anywhere and cannot be scraped. What is it not? - this is not a tool that provides a full overview around who the employees and users that got compromised are, or how they got compromised. We cannot provide this data publicly as it is very sensitive and is only given as an ethical disclosure to the cybersecurity team of the company. If you work for a company that has compromised employees or clients, be sure to get a free ethical disclosure from us. Our high-fidelity cybercrime intelligence data is sourced directly from threat actors — not from database leaks or scrapes. If you liked this tool please share it, it is also accessible through API along with other free tools we provide such as checking if your own computer was compromised at some point (Preview API - https://cavalier.hudsonrock.com/docs) <!-- SC_ON --> submitted by /u/Malwarebeasts (https://www.reddit.com/user/Malwarebeasts)
[link] (https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/) [comments] (https://www.reddit.com/r/redteamsec/comments/vvnazm/free_cybercrime_intelligence_tool_check_any/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I created an automated Telegram channel to share cybersecurity news from trusted news sources
https://external-preview.redd.it/26CjbkhmHRTZ15DYiO8sHJ2PTfxTEIzQFsOkMWfFNqM.jpg?width=320&crop=smart&auto=webp&s=c5a953d9f173ef05bf84fe7c13431f78c244c5de submitted by /u/TrulyPain
[link] [comments]
I created an automated Telegram channel to share cybersecurity news from trusted news sources
https://external-preview.redd.it/26CjbkhmHRTZ15DYiO8sHJ2PTfxTEIzQFsOkMWfFNqM.jpg?width=320&crop=smart&auto=webp&s=c5a953d9f173ef05bf84fe7c13431f78c244c5de submitted by /u/TrulyPain
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
JWT Vulnerabilities List (Simple Explanation)
JWT vulnerabilities:
Continue reading on Medium »
JWT Vulnerabilities List (Simple Explanation)
JWT vulnerabilities:
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Easy Web Hacking Can Be
https://cdn-images-1.medium.com/max/2000/0*AUViModNMdVe4fPx.png
I decided to write a write-up about how I managed to find, investigate and exploit a fairly simple web vulnerability. Just to be clear…
Continue reading on Medium »
How Easy Web Hacking Can Be
https://cdn-images-1.medium.com/max/2000/0*AUViModNMdVe4fPx.png
I decided to write a write-up about how I managed to find, investigate and exploit a fairly simple web vulnerability. Just to be clear…
Continue reading on Medium »
hacking: security in practice
I wrote an essay on dissent and its role in the mainstream that I thought fits the hacker ethos. It's called "Dissenting through the Mainstream"
submitted by /u/TimDaub
[link] [comments]
I wrote an essay on dissent and its role in the mainstream that I thought fits the hacker ethos. It's called "Dissenting through the Mainstream"
submitted by /u/TimDaub
[link] [comments]
reddit
I wrote an essay on dissent and its role in the mainstream that I...
Posted in r/hacking by u/TimDaub • 1 point and 0 comments
hacking: security in practice
What do you like more, hack windows or linux?
in terms of ctf, pentesting, real life
submitted by /u/Relative-Raspberry64
[link] [comments]
What do you like more, hack windows or linux?
in terms of ctf, pentesting, real life
submitted by /u/Relative-Raspberry64
[link] [comments]
reddit
What do you like more, hack windows or linux?
in terms of ctf, pentesting, real life
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Phishing de la manera más facil. Solo un par de clicks.
Todos conocemos SET, la herramienta que viene con distribuciones como Kali o Parrot. En esta ocasión veremos NexPhisher.
Continue reading on Medium »
Phishing de la manera más facil. Solo un par de clicks.
Todos conocemos SET, la herramienta que viene con distribuciones como Kali o Parrot. En esta ocasión veremos NexPhisher.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Find Instagram Account Details | How To Check Someone Instagram Account Details | Latest
How to Find Instagram Account Details | How To Check Someone Instagram Account Details | Latest | upload by Allaboutsubha
Continue reading on Medium »
How to Find Instagram Account Details | How To Check Someone Instagram Account Details | Latest
How to Find Instagram Account Details | How To Check Someone Instagram Account Details | Latest | upload by Allaboutsubha
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox’s “Nibbles” Writeup
https://cdn-images-1.medium.com/max/2534/1*eEocv3YesU8bC9HL6FyWRw.png
Nibbles is a box that requires you to pay attention to key words and phrases when they appear during your recon, and to check page sources…
Continue reading on Medium »
HackTheBox’s “Nibbles” Writeup
https://cdn-images-1.medium.com/max/2534/1*eEocv3YesU8bC9HL6FyWRw.png
Nibbles is a box that requires you to pay attention to key words and phrases when they appear during your recon, and to check page sources…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack into a friend’s Facebook Account
https://cdn-images-1.medium.com/max/600/1*LlqOAq0TXa2xG6UtMFl_kg.jpeg
It seems like a magical title, and it is somewhat totally accurate. I will show you how you can log in to a friend's Facebook account…
Continue reading on Medium »
Hack into a friend’s Facebook Account
https://cdn-images-1.medium.com/max/600/1*LlqOAq0TXa2xG6UtMFl_kg.jpeg
It seems like a magical title, and it is somewhat totally accurate. I will show you how you can log in to a friend's Facebook account…
Continue reading on Medium »