white2hack 📚 – Telegram
white2hack 📚
12.4K subscribers
4.8K photos
135 videos
1.96K files
2.26K links
Кибербез. Книги, гайды, how to, ликбез. Аналитика, тренды, карьера, эвенты. Этичный хакинг и защита своих данных

🔊 Связь @w2hack_feed_bot
💬 Чат https://news.1rj.ru/str/+VdkEIWudTi5m3dsA
💡 Консультация https://forms.gle/iB9iX3BwyxJM4Ktx5
🏛 Обмен -- private --
Download Telegram
Detect Tactics, Techniques & Combat Threats, Latest version: 1.8.0

DeTT&CT aims to assist blue teams in using ATT&CK to score and compare data log source quality, visibility coverage, detection coverage and threat actor behaviours. All of which can help, in different ways, to get more resilient against attacks targeting your organisation.

The DeTT&CT framework consists of a Python tool (DeTT&CT CLI), YAML administration files, the DeTT&CT Editor (to create and edit the YAML administration files) and scoring tables for detections, data sources and visibility.

GitHub

#pentest #defensive
👍6
WEB APPLICATION PENTESTING CHECKLIST

OWASP Based Checklist 🌟 500+ Test Cases 🚀

#web
👍3
Web Pentesting Checklist _2023.pdf
124.1 KB
WEB APPLICATION PENTESTING CHECKLIST
👍2
Metasploit MS SQL Server, 2023

Metasploit is an excellent framework developed by H. D. Moore. It is a free and lightweight tool for penetration testing. It is open-source and cross-platform and has a range of features. Its popularity rests primarily on the fact that it is a powerful tool for auditing security. While this is true, it also has many features that can help people protect themselves. Personally speaking, this is my go-to tool for testing as it encapsulates the exploit a pentester can ever need.

Through this article, we will learn how to use Metasploit to exploit MSSQL. Therefore, we will go through every exploit Metasploit has to offer step by step, from finding the MSSQL server in the network to retrieving the sensitive information from the database and gaining control. Without any further ado, let us begin.

#pentest
👍4🔥1
MetaSploit_beginner_2023.pdf
2.8 MB
Metasploit MS SQL Server, 2023
👍1🤣1
Те самые ситуации, когда девушка тебе пишет первой, оставляет свой номер и готова на встречу, а потом бац и ghosted 😂😂😂

#fun
🤣5
Ну, и чуть горсти перца сами понимаете кому😂 чисто relax и посмеяться

#fun
🤣9🤩1
HTTP Security Headers

#web
👍4🤣1
HTTPS_Header_Info.pdf
1 MB
HTTP Security Headers
👍2
image_2023-04-11_14-02-38.png
1.5 MB
Session Based Authentication

Understand what is session based authentication and how it is implemented

#useful #web
👍6
IoT and OT Security Handbook, Smita Jain, Vasantha Lakshmi, 2023

Assess risks, manage vulnerabilities, and monitor threats with Microsoft Defender for IoT

#book
👍5
IoT.and.OT.Security.Handbook.pdf
22.4 MB
IoT and OT Security Handbook, Smita Jain, Vasantha Lakshmi, 2023
👍5
Zero TrustтSecurity. An Enterprise Guide,тJason Garbis, Jerry W. Chapman, 2023

Zero Trust security has become a major industry trend, and yet there still is uncertainty about what it means. Zero Trust is about fundamentally changing the underlying philosophy and approach to enterprise security—moving from outdated and demonstrably ineffective perimeter-centric approaches to a dynamic, identity-centric, and policy-based approach. Making this type of shift can be challenging.

Your organization has already deployed and operationalized enterprise security assets such as Directories, IAM systems, IDS/IPS, and SIEM, and changing things can be difficult. Zero Trust Security uniquely covers the breadth of enterprise security and IT architectures, providing substantive architectural guidance and technical analysis with the goal of accelerating your organization‘s journey to Zero Trust.

#book#architecture
👍2🎉1