Hacking on Medium
How did I get my Certificate Ethical hacker certificate at only 16 years old… and now I’m preparing…
https://cdn-images-1.medium.com/max/2278/1*HHIPBXwJ9kjzq3V0L8hGlQ.png
Hello everyone, I hope you are feeling well today and I would like you to listen to one of the good parts of my life.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How did I get my Certificate Ethical hacker certificate at only 16 years old… and now I’m preparing…
https://cdn-images-1.medium.com/max/2278/1*HHIPBXwJ9kjzq3V0L8hGlQ.png
Hello everyone, I hope you are feeling well today and I would like you to listen to one of the good parts of my life.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How did I get my Certificate Ethical hacker certificate at only 16 years old… and now I’m preparing for OSCP and I haven’t entered…
Hello everyone, I hope you are feeling well today and I would like you to listen to one of the good parts of my life. It all started in the…
Hacking on Medium
TGA Weekly Newsletter [11/9/22]
https://cdn-images-1.medium.com/max/2600/0*fz_QNOxS38QygklJ
Hello! Welcome to The Gray Area’s newsletter, with the top posts of the week.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
TGA Weekly Newsletter [11/9/22]
https://cdn-images-1.medium.com/max/2600/0*fz_QNOxS38QygklJ
Hello! Welcome to The Gray Area’s newsletter, with the top posts of the week.
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TGA Weekly Newsletter [11/9/22]
Hello! Welcome to The Gray Area’s newsletter, with the top posts of the week.
Hacking on Medium
Why is Security Important in Cloud Computing?
https://cdn-images-1.medium.com/max/900/0*LTFZzifaTdqB5295.jpeg
To prepare for future success, businesses need to switch from on-premise hardware to the cloud to meet their computing needs. The cloud…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Why is Security Important in Cloud Computing?
https://cdn-images-1.medium.com/max/900/0*LTFZzifaTdqB5295.jpeg
To prepare for future success, businesses need to switch from on-premise hardware to the cloud to meet their computing needs. The cloud…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why is Security Important in Cloud Computing?
To prepare for future success, businesses need to switch from on-premise hardware to the cloud to meet their computing needs. The cloud…
Hacking on Medium
Los 5 principales mitos de seguridad de API que están aplastando su negocio
https://cdn-images-1.medium.com/max/1552/0*ySYzNL-4O46HjhHc
Existen varios mitos y conceptos erróneos sobre la seguridad de las API. Estos mitos sobre la protección de las API están aplastando su…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Los 5 principales mitos de seguridad de API que están aplastando su negocio
https://cdn-images-1.medium.com/max/1552/0*ySYzNL-4O46HjhHc
Existen varios mitos y conceptos erróneos sobre la seguridad de las API. Estos mitos sobre la protección de las API están aplastando su…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Los 5 principales mitos de seguridad de API que están aplastando su negocio
Existen varios mitos y conceptos erróneos sobre la seguridad de las API. Estos mitos sobre la protección de las API están aplastando su…
They See Me Roaming: Following APT29 by Taking a Deeper Look at Windows Credential Roaming | Mandiant
https://www.reddit.com/r/redteamsec/comments/yql8h0/they_see_me_roaming_following_apt29_by_taking_a/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mandiant.com/resources/blog/apt29-windows-credential-roaming) [comments] (https://www.reddit.com/r/redteamsec/comments/yql8h0/they_see_me_roaming_following_apt29_by_taking_a/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/yql8h0/they_see_me_roaming_following_apt29_by_taking_a/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mandiant.com/resources/blog/apt29-windows-credential-roaming) [comments] (https://www.reddit.com/r/redteamsec/comments/yql8h0/they_see_me_roaming_following_apt29_by_taking_a/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
They See Me Roaming: Following APT29 by Taking a Deeper Look at...
Posted in r/redteamsec by u/dmchell • 1 point and 0 comments
Hunting for Canary Tokens in various formats 😈
https://www.reddit.com/r/redteamsec/comments/yqlyqe/hunting_for_canary_tokens_in_various_formats/
https://github.com/C0axx/CanaryHunter submitted by /u/_C0axx (https://www.reddit.com/user/_C0axx)
[link] (https://www.reddit.com/r/redteamsec/comments/yqlyqe/hunting_for_canary_tokens_in_various_formats/) [comments] (https://www.reddit.com/r/redteamsec/comments/yqlyqe/hunting_for_canary_tokens_in_various_formats/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/yqlyqe/hunting_for_canary_tokens_in_various_formats/
https://github.com/C0axx/CanaryHunter submitted by /u/_C0axx (https://www.reddit.com/user/_C0axx)
[link] (https://www.reddit.com/r/redteamsec/comments/yqlyqe/hunting_for_canary_tokens_in_various_formats/) [comments] (https://www.reddit.com/r/redteamsec/comments/yqlyqe/hunting_for_canary_tokens_in_various_formats/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hunting for Canary Tokens in various formats 😈
[https://github.com/C0axx/CanaryHunter](https://github.com/C0axx/CanaryHunter)
Searching for Subdomain Vulnerabilities using Censys
TL;DR- A ‘how-to’ on utilizing a great tool that takes the concept of ‘Google dorking’ to a whole new level. This article is highly…Continue reading on The Gray Area »
Read more...
TL;DR- A ‘how-to’ on utilizing a great tool that takes the concept of ‘Google dorking’ to a whole new level. This article is highly…Continue reading on The Gray Area »
Read more...
What is PKI, and why is it being used?
Ever thought about how you can validate the authenticity of a website and the data we are sending to it is really safe?Continue reading on CodeX »
Read more...
Ever thought about how you can validate the authenticity of a website and the data we are sending to it is really safe?Continue reading on CodeX »
Read more...
Searching for Subdomain Vulnerabilities using Censys
https://medium.com/the-gray-area/searching-for-subdomain-vulnerabilities-using-censys-d5463e77a1eb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/the-gray-area/searching-for-subdomain-vulnerabilities-using-censys-d5463e77a1eb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Searching for Subdomain Vulnerabilities using Censys
TL;DR- A ‘how-to’ on utilizing a great tool that takes the concept of ‘Google dorking’ to a whole new level. This article is highly…
TL;DR- A ‘how-to’ on utilizing a great tool that takes the concept of ‘Google dorking’ to a whole new level. This article is highly…Continue reading on The Gray Area » (https://medium.com/the-gray-area/searching-for-subdomain-vulnerabilities-using-censys-d5463e77a1eb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Searching for Subdomain Vulnerabilities using Censys
TL;DR- A ‘how-to’ on utilizing a great tool that takes the concept of ‘Google dorking’ to a whole new level. This article is highly…
What is PKI, and why is it being used?
https://medium.com/codex/what-is-pki-and-why-is-it-being-used-d757dda823f3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/codex/what-is-pki-and-why-is-it-being-used-d757dda823f3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is PKI, and why is it being used?
Ever thought about how you can validate the authenticity of a website and the data we are sending to it is really safe?
Ever thought about how you can validate the authenticity of a website and the data we are sending to it is really safe?Continue reading on CodeX » (https://medium.com/codex/what-is-pki-and-why-is-it-being-used-d757dda823f3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is PKI, and why is it being used?
Ever thought about how you can validate the authenticity of a website and the data we are sending to it is really safe?
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Protect yourself against fake login screens (by learning how to make one)
https://external-preview.redd.it/vYVHggfeyr0gAKtbrx1azE9ALGGCUR3-Zh6NSvScVOk.jpg?width=320&crop=smart&auto=webp&s=5ebe630a227133363782a2feca7b91e90e07c5a2 submitted by /u/88-mph-
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Protect yourself against fake login screens (by learning how to make one)
https://external-preview.redd.it/vYVHggfeyr0gAKtbrx1azE9ALGGCUR3-Zh6NSvScVOk.jpg?width=320&crop=smart&auto=webp&s=5ebe630a227133363782a2feca7b91e90e07c5a2 submitted by /u/88-mph-
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Protect yourself against fake login screens (by learning how to...
Posted in r/hacking by u/88-mph- • 2 points and 0 comments
Kali Linux Tutorials
Threatest : Threatest Is A Go Framework For End-To-End Testing Threat Detection Rules
Threatest is a Go framework for testing threat detection end-to-end. Threatest allows you to detonate an attack technique, and verify that the alert you expect was generated in your favorite security platform.
Concepts
Detonators
A detonator describes how and where an attack technique is executed.
Supported detonators:
* Local command execution
* SSH command execution
* Stratus Red Team
* AWS detonator
Alert matchers
An alert matcher is a platform-specific integration that can check if an expected alert was triggered.
Supported alert matchers:
* Datadog security signals
Detonation and alert correlation
Each detonation is assigned a UUID. This UUID is reflected in the detonation and used to ensure that the matched alert corresponds exactly to this detonation.
The way this is done depends on the detonator; for instance, Stratus Red Team and the AWS Detonator inject it in the user-agent; the SSH detonator uses a parent process containing the UUID.
Sample usage
See examples for complete usage example.
Testing Datadog Cloud SIEM signals triggered by Stratus Red Team
threatest := Threatest()
threatest.Scenario("AWS console login").
WhenDetonating(StratusRedTeamTechnique("aws.initial-access.console-login-without-mfa")).
Expect(DatadogSecuritySignal("AWS Console login without MFA").WithSeverity("medium")).
WithTimeout(15 * time.Minute)
assert.NoError(t, threatest.Run())
Testing Datadog Cloud Workload Security signals triggered by running commands over SSH
ssh, _ := NewSSHCommandExecutor("test-box", "", "")
threatest := Threatest()
threatest.Scenario("curl to metadata service").
WhenDetonating(NewCommandDetonator(ssh, "curl http://169.254.169.254 --connect-timeout 1")).
Expect(DatadogSecuritySignal("EC2 Instance Metadata Service Accessed via Network Utility"))
assert.NoError(t, threatest.Run())
Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
Threatest : Threatest Is A Go Framework For End-To-End Testing Threat Detection Rules
Threatest is a Go framework for testing threat detection end-to-end. Threatest allows you to detonate an attack technique, and verify that the alert you expect was generated in your favorite security platform.
Concepts
Detonators
A detonator describes how and where an attack technique is executed.
Supported detonators:
* Local command execution
* SSH command execution
* Stratus Red Team
* AWS detonator
Alert matchers
An alert matcher is a platform-specific integration that can check if an expected alert was triggered.
Supported alert matchers:
* Datadog security signals
Detonation and alert correlation
Each detonation is assigned a UUID. This UUID is reflected in the detonation and used to ensure that the matched alert corresponds exactly to this detonation.
The way this is done depends on the detonator; for instance, Stratus Red Team and the AWS Detonator inject it in the user-agent; the SSH detonator uses a parent process containing the UUID.
Sample usage
See examples for complete usage example.
Testing Datadog Cloud SIEM signals triggered by Stratus Red Team
threatest := Threatest()
threatest.Scenario("AWS console login").
WhenDetonating(StratusRedTeamTechnique("aws.initial-access.console-login-without-mfa")).
Expect(DatadogSecuritySignal("AWS Console login without MFA").WithSeverity("medium")).
WithTimeout(15 * time.Minute)
assert.NoError(t, threatest.Run())
Testing Datadog Cloud Workload Security signals triggered by running commands over SSH
ssh, _ := NewSSHCommandExecutor("test-box", "", "")
threatest := Threatest()
threatest.Scenario("curl to metadata service").
WhenDetonating(NewCommandDetonator(ssh, "curl http://169.254.169.254 --connect-timeout 1")).
Expect(DatadogSecuritySignal("EC2 Instance Metadata Service Accessed via Network Utility"))
assert.NoError(t, threatest.Run())
Click Here To Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Threatest : Framework For End-To-End Testing Threat Detection Rules
Threatest is a Go framework for testing threat detection end-to-end. Threatest allows you to detonate an attack technique
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Fuzzing — An Overview For Beginners
https://cdn-images-1.medium.com/max/750/1*LV730os0Yw6Sk1avTVhPhw.png
Fuzzing is a really common technique utilized by security researchers when looking for vulnerabilities in software. Lets get an overview.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Fuzzing — An Overview For Beginners
https://cdn-images-1.medium.com/max/750/1*LV730os0Yw6Sk1avTVhPhw.png
Fuzzing is a really common technique utilized by security researchers when looking for vulnerabilities in software. Lets get an overview.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Fuzzing?
Fuzzing is a really common technique utilized by security researchers when looking for vulnerabilities in software. Lets get an overview.