Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Meta Quarterly Adversarial Threat Report [Q3 2022](https://about.fb.com/wp-content/uploads/2022/11/Quarterly-Adversarial-Threat-Report-Q2-2022-1.pdf)
πŸ—£jnazario


πŸŽ–@malwr
Security platform for tracking SOC2 compliance
Hey all,

I'm sharing my project on Github called Gapps. Gapps is a platform to help track/implement SOC2 controls for your organization. It ships with over 200+ controls and 25+ policies.

I created this tool because:

1. I found the SOC2 readiness "process" confusing, compared to other frameworks.
2. I'm not aware of a open-source compliance platform so hopefully people contribute and we can build one. The end goal is to support other frameworks.

Here is the link to the video and the Github link.

Upcoming improvements:

1. Add other frameworks such as NIST CSF, HIPAA, CMMC, CIS CSC, etc.
2. Collection windows and reminders
3. Add documentation for using Gapps "agent" - Mac/Nix/Windows agent that asserts compliance for endpoints (helps with a number of SOC2 controls)

Would be great if others contributed - there are a ton of features that I'd like to add. Feel free to submit issues and/or PM me with questions.
πŸ—£skywalker_1391

Where were you able to find all the controls?
πŸ‘€aflyingpotatoe

Hi just a heads up on licensing, from the Creative Commons FAQ: https://creativecommons.org/faq/#can-i-apply-a-creative-commons-license-to-software

>We recommend against using Creative Commons licenses for software. Instead, we strongly encourage you to use one of the very good software licenses which are already available. We recommend considering licenses listed as free by the Free Software Foundation and listed as β€œopen source” by the Open Source Initiative.
>
>Unlike software-specific licenses, CC licenses do not contain specific terms about the distribution of source code, which is often important to ensuring the free reuse and modifiability of software. Many software licenses also address patent rights, which are important to software but may not be applicable to other copyrightable works.
>
>Additionally, our licenses are currently not compatible with the major software licenses, so it would be difficult to integrate CC-licensed work with other free software. Existing software licenses were designed specifically for use with software and offer a similar set of rights to the Creative Commons licenses.

Since you chose CC-BY-NC-ND license you should probably stick with "source available" software licenses or something like Prosperity Public License (A non-commercial software license), Business Source License (Recently adopted by LightBend / Akka and other big projects), or Fair Source License

There are also some Copy-far-left or Copyfair Licenses that could be appealing to you as similar to CC-BY-NC-ND: https://github.com/LibreCybernetics/awesome-copyfarleft
πŸ‘€fabianhjr

Do HITRUST next. I use field guide and am not a huge fan. Plenty of pop there
πŸ‘€bloopscooppoop


πŸŽ–@malwr
πŸ”₯1
Investigating Infected Windows with Volatility Framework | TryHackMe
In this video walk-through, we covered using the Volatility framework to analyze and investigate the memory of an infected machine with ransomware.

Video is here


πŸ—£MotasemHa


πŸŽ–@malwr
πŸ‘2
Places to find a mentor?
Does anyone have any resources or places to possibly find a mentor for the IR space? I’m an early professional, and started on an IR team a few months ago and am looking for a mentor to guide me more of the technical aspects of DFIR.

Thanks!
πŸ—£hoolahoop222

If you have a job and it is a big company they tend to host mentorships.

If you are in college there tends to host mentorships programs. At least back in the day they used to have FBI and Government employees stop by and help with mentoring and shadowing.

It seems tho with everyone being a university student and graduating but here asking the same question idk if University do this stuff anymore.
πŸ‘€MDCDF

?? Don’t you usually find mentors through networking or at your place of employment?
πŸ‘€ucfmsdf

Take a look at CFCE from IACIS. You will learn a lot and will be assigned a coach to help you.
πŸ‘€lithium630


πŸŽ–@malwr