white2hack 📚 – Telegram
white2hack 📚
12.4K subscribers
4.8K photos
135 videos
1.96K files
2.26K links
Кибербез. Книги, гайды, how to, ликбез. Аналитика, тренды, карьера, эвенты. Этичный хакинг и защита своих данных

🔊 Связь @w2hack_feed_bot
💬 Чат https://news.1rj.ru/str/+VdkEIWudTi5m3dsA
💡 Консультация https://forms.gle/iB9iX3BwyxJM4Ktx5
🏛 Обмен -- private --
Download Telegram
OSINT CheatSheet, 2023

#OSINT
👍6
OSINT CheatSheet.pdf
662 KB
OSINT CheatSheet
👍2
CISSP Study GuideCISSP Study Guide, 2023

#docs #useful
👍4
CISSP Study Guide.pdf
1.8 MB
CISSP Study GuideCISSP Study Guide
👍1
Hackers use 'net' command to enumerate compromised system. This is why SOC analysts set alert for this command.

But, hackers can use 'net1' command, which will work same as the 'net' command. So, when you're threat hunting, don't search only 'net' command rather, search '*net*' as regex to find malicious commands.

#useful
👍6🤔3
Have published new tool- DFIRT, by Md. Abdullah Al Mamun, 2023

It collects information of Windows PC to help incident response

GitHub

#forensic
🔥6
Where is my popcorn?.. 🍿

#fun
🤣12🙏2
Forwarded from CyberSecBastion
This media is not supported in your browser
VIEW IN TELEGRAM
ChatGPT can fix your buggy code!

Here’s how…

1. Install ChatGPT addon in VSCode.
2. Get an API key from OpenAI and input when prompted in VSCode.
3. Right click part or all of your code and select ChatGPT-Find Bugs.
4. Click insert from the ChatGPT window to fix your code.

BONUS: ChatGPT will also explain the bug!!

#AppSec
🤔81👍1🤣1
Человек из телевизора сказал "Своих не бросаем!". На днях, впервые года так за 3 пришлось обратится за содействием, сначала к одним потом к другим, далее к третьим, четвертым и везде вилы. Сначала, конечно, стало немного грустно, но потом осталась только улыбка! Ведь, эта ситуация как раз как лакмусовая бумажка показала кто есть кто, где п#здешь ради хайпа, а где деловой подход. Оценивая на трезвую голову все кто сейчас отвалились никогда друзьями и партнерами по настоящему и не были. Так что все идет только в благо, а мир полон возможностей и без этих "патриотов", мусор отсечен, на горизонте только те с кем можно "кашу сварить".

А что скажешь ты? - был ли у тебя подобный опыт, попадал ли в схожие ситуации, правда ли что своих не бросают или все зассано п#здешом?
👍7
A Burp Suite extension that integrates OpenAI's GPT

Released BurpGPT, a Burp Suite (PortSwigger) extension that uses OpenAI's GPT models to add an extra layer of security to your passive scan.

With BurpGPT, you can easily interact with Open AI models to identify potential vulnerabilities in your web application using custom prompts.

GitHub

#web
👍6🤔1
А ведь некоторые конторы так и нанимают)

#fun
🤣10👍41
Red Teaming Toolkit

This repository contains cutting-edge open-source security tools (OST) that will help you during adversary simulation and as information intended for threat hunter can make detection and prevention control easier.

The list of tools below that could be potentially misused by threat actors such as APT and Human-Operated Ransomware (HumOR). If you want to contribute to this list send me a pull request.

#pentest
👍7
Burp Suite Intro

Burp Suite, you might have heard about this great tool and even used it in a number of times in your bug hunting or the penetration testing projects. Though, after writing several articles on webapplication penetration testing, we’ve decided to write a few on the various options and methods provided by this amazing tool which thus could help our readers in their further penetration testing analyses.

Today, in this publication, you will experience the complete installation and configuration of thismPort Swigger’s product from its different editions to setting up proxies for web and androidmapplications.

#web
😁4👍1
Detect Tactics, Techniques & Combat Threats, Latest version: 1.8.0

DeTT&CT aims to assist blue teams in using ATT&CK to score and compare data log source quality, visibility coverage, detection coverage and threat actor behaviours. All of which can help, in different ways, to get more resilient against attacks targeting your organisation.

The DeTT&CT framework consists of a Python tool (DeTT&CT CLI), YAML administration files, the DeTT&CT Editor (to create and edit the YAML administration files) and scoring tables for detections, data sources and visibility.

GitHub

#pentest #defensive
👍6
WEB APPLICATION PENTESTING CHECKLIST

OWASP Based Checklist 🌟 500+ Test Cases 🚀

#web
👍3