Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Matano - The Open-Source Security Lake Platform For AWS

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqX3w4a55hJEMy-NZgBEQXV6orLxnR9zMqLFoAwGaVr2rIvB9-Fk2tDQKvTsmigZkR0cxrKFvEKOWTKbfH9P8EldUNDj69w-GCkfqORU6Nt05MAlNxvdGMblhjtmMXpG7cTjDVnORQgVLR73y53lG5JPoiEO8clQY4CuBzqtCyd7WT2zpH1qClkuX6Rw/w640-h260/matano.png Matano is an open source security lake platform for AWS. It lets you ingest petabytes of security and log data from various sources, store and query them in an open Apache Iceberg data lake, and create Python detections as code for realtime alerting. Matano is fully serverless and designed specifically for AWS and focuses on enabling high scale, low cost, and zero-ops. Matano deploys fully into your AWS account. https://blogger.googleusercontent.com/img/a/AVvXsEghH3oRgeqp6V4_fAgJpLhPQm2l9025YQD8EMo6nlCkJ8CVVPVb4zcpH34m9sMZzSi9Ib-d3PzbN0VkcUj4-aj3DscaFqqFajwB65YGe5gFnpRcQau2t171qCmKXwmGm8Zs-NOUbGuOAn3XQwKT03r3vDISVeVZmngXtJte3dX1MXzd3DJTuSUs_96V4A=w640-h324 FeaturesCollect data from all your sourcesMatano lets you collect log data from sources using S3 or SQS based ingestion. Ingest, transform, normalize log dataMatano normalizes and transforms your data using Vector Remap Language (VRL). Matano works with the Elastic Common Schema (ECS) by default and you can define your own schema. Store data in S3 object storageLog data is always stored in S3 object storage, for cost effective, long term, durable storage. Apache Iceberg Data lakeAll data is ingested into an Apache Iceberg based data lake, allowing you to perform ACID transactions, time travel, and more on all your log data. Apache Iceberg is an open table format, so you always own your own data, with no vendor lock-in. ServerlessMatano is a fully serverless platform, designed for zero-ops and unlimited elastic horizontal scaling. Detections as codeWrite Python detections to implement realtime alerting on your log data. InstallingView the complete installation instructions.

You can install the matano CLI to deploy Matano into your AWS account, and manage your Matano deployment. Requirements* Docker InstallationMatano provides a nightly release with the latest prebuilt files to install the Matano CLI on GitHub. You can download and execute these files to install Matano.

For example, to install the Matano CLI for Linux, run: curl -OL https://github.com/matanolabs/matano/releases/download/nightly/matano-linux-x64.sh
chmod +x matano-linux-x64.sh
sudo ./matano-linux-x64.sh
Getting startedRead the complete docs on getting started. DeploymentTo get started with Matano, run the matano initcommand. Make sure you have AWS credentials in your environment (or in an AWS CLI profile).

The interactive CLI wizard will walk you through getting started by generating an initial Matano directory for you, initializing your AWS account, and deploying Matano into your AWS account. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdUK3Bqj7b8cajuoKx8yCaCWNPO9Kw4z1Viin9wfpjMEY9g69mywobrF4HMDwNQ4EXY6kqnq_6ev83VvRhhJxHENDz1FRUeHx5UkGRaG99-p1uAH8-Y4cAeS5v8yLNoKXrOFnrCsSUo-5X4uVzSbJUsyUy6wxumr-WbLnWRDSS3jbzb8dnQzXHVLVR0Q/w640-h360/matano_9_matano-init.gif Initial deployment takes a few minutes. DocumentationView our complete documentation. License* Apache-2.0 License https://blogger.googleusercontent.com/img/a/AVvXsEj-DaZt9qjgneGKVtokDwUlMsD-thDPFseA82GXz6jz4y7alXG80CkSZhc8DPha4RfvcPdSBtt7gdWGJsp0eZX3yRCk7LPCNTHb1Lx_aALQVd4gnkN_E4YhJl-AtX2ZMNKnKjTyMUfrGgOlp1MUPVyR6STd11WMiYXGG3XZv7gyKlfmMY57brHm1OmFLg=s320 Download Matano

___________________________
@hacking_Attack
@Hacking_Video
Story about Escalation of HTML Injection to EC2 Instance credentials leak

Hello all, Thank for overwhelming response here i am with my new finding tale.Continue reading on Medium »
Read more...
Top 10 Best Bug Bounty Tools in 2022

In today’s world, cybersecurity holds top priority for most organizations and governments. Large companies are investing millions of…Continue reading on Medium »
Read more...
CVE-2022–33077: IDOR to change address of any customer via parameter pollution in nopCommerce <= 4.5

TL;DR: A POST request to edit the address endpoint involved two addressID parameters (one in the URL and other in the request body)…Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Concerns Over Fortinet Flaw Mount; PoC Released, Exploit Activity Grows

The authentication bypass flaw in FortiOS, FortiProxy and FortiSwitchManager is easy to find and exploit, security experts say.
Dark Reading: Attacks/Breaches
Fast Fashion Retailer Data Breach Draws $1.9M Fine

New York AG fines Shein and Romwe parent company for failure to protect customer data and downplaying the 2018 compromise of 46 million shopper records.
Dark Reading: Attacks/Breaches
Microsoft 365 Message Encryption Can Leak Sensitive Info

The default email encryption used in Microsoft Office's cloud version is leaky, which the company acknowledged but said it wouldn't fix.