Mostrando entradas con la etiqueta Hunting. Mostrar todas las entradas
Mostrando entradas con la etiqueta Hunting. Mostrar todas las entradas

miércoles, 22 de julio de 2020

Top 10 Free Threat-Hunting Tools


Here are three types of hypotheses that analysts look for while threat hunting:
  • Analytics-Driven: Considers user and entity behavior analytics (UEBA) and machine learning to develop accumulated risk scores and further hypotheses
  • Intelligence-Driven: Fueled by threat intelligence reports, feeds, malware analysis and vulnerability scans
  • Situational-Awareness Driven: Uses enterprise risk assessments or Crown Jewel analysis, evaluating a company or individual’s trends

Analytics-Driven

Maltego CE

This is a data-mining tool that renders interactive graphs for link analysis. It’s used most frequently in online investigations by finding relationships between portions of data from various sources of the internet. Maltego CE automates processes of different query resources and displays a graph that’s useful for link analysis.

Cuckoo Sandbox

Cuckoo Sandbox is a leader in open-source automated malware analysis systems. It enables you to dispose of any suspicious files and receive instantaneous, detailed results that outline what the file in question did when tested in an isolated environment.

Automater

TekDefense’s Automater can analyze URLs, hashes, and URLs to make intrusion analysis a much more seamless process. Simply choose a target, and Automater will fetch relevant results from popular sources. You’re able to modify what sources the system is checking, and what data is taken from them. Modification of Python code is not required to use this application and the interface is very user-friendly, even for a beginner.


Intelligence-Driven

YARA

This multi-platform tool helps users classify malware and create descriptions of similar malware categories based on binary or textual patterns. Each description is comprised of a boolean expression and a set of strings and expressions that determine its identity.
YARA operates on Windows, Mac and Linux, and utilizes Python scripts or its own command-line interface. YARA is often used by commercial software to enhance its performance and abilities.

CrowdFMS

This application is a framework that automatically collects and processes samples from VirusTotal, a website that publishes details of phishing emails, by leveraging the Private API system. CrowdFMS downloads recent samples and triggers an alert to users’ YARA notification feed.

BotScout

The tool BotScout helps fight automated web scripts, more commonly known as “bots,” by preventing them from being able to register on forums that lead to spam, server abuse, and the pollution of databases. BotScout tracks the IP, name and email address so that the source of bots is terminated for future encounters. This powerful yet simple API is used by many companies and universities to keep their online assets safe.

Machinae

Machinae can be utilized by compiling intelligence from public websites and feeds about security-related data such as domain names, URLs, email and IP addresses, and more. This software is free and has better compatibility than other security intelligence collectors on the market. Its configuration is also well-optimized and supports many inputs and outputs.


Situational-Awareness Driven

AIEngine

AIEngine is an interactive tool that revolutionizes your network’s intrusion detection system, capable of learning without human interaction. It is programmable and includes features abilities such as:
  • Network forensics
  • Network collection
  • Spam detection

YETI

Trusted Automated eXchange of Indicator Information (TAXII) is a set of message exchanges and services that enable threat details to be shared seamlessly across product lines, service boundaries and organizations. It empowers companies to share data they choose from trusted partners.


Fuente: resources.infosecinstitute.com



jueves, 25 de junio de 2020

Threat Hunter o “cazador de amenazas”

El término threat hunter o “cazador de amenazas” no es nuevo y lleva siendo trabajado y mejorado desde hace algunos años en el mundo de la seguridad de la información.
Integrando tecnología, procesos y personas, busca detectar y aislar amenazas a través de análisis proactivos de red para aportar valor con técnicas avanzadas que suplan las debilidades de las medidas de seguridad, ya sea por una amenaza externa o interna.
Sin embargo, no todas las organizaciones están preparadas para entrar en este mundo o simplemente no lo necesitan desplegar internamente dentro de sus medidas de protección. Esto es debido a que su despliegue necesita de unos requisitos previos que para nada son un punto de partida en la seguridad de la información y que pueden no aportar nada en el ecosistema de una compañía concreta para la detección y respuesta a los incidentes cibernéticos.

¿Qué debemos tener en cuenta? 
Para la implementación de un modelo de Threat Hunting, las empresas deben considerar unas bases tecnológicas, de procesos y de personal con unas capacidades y características mínimas. Por ejemplo, desde el punto de vista tecnológico, se deben tener bien desplegados los elementos para la detección de amenazas, por lo cual es indispensable contar con un buen sistema de EDR (Endpoint Detection & Response), un sistema de IDS (Intrusion Detection System) y un SIEM (Security Information Event Management). Éstos servirán como fuente primordial de la telemetría de la red y de los sucesos que en ella ocurran de manera regular, periódica y/o extraordinaria.


Fuente: empresas.blogthinkbig.com



 

 

 Link relacionados:
- Threat Hunting ¿Qué es y cómo abordarlo?
- ¿Qué es Threat Hunting y por qué es necesario?
- Cacería de Amenazas - Convirtiendo el BigData en RightData de CiberSeguridad

viernes, 20 de septiembre de 2019

Top Penetration Testing Companies Worldwide In 2019

Penetration Testing Companies and service providers

#1) ScienceSoft
Core Services: Security Testing (Vulnerability Assessment, Penetration Testing, Compliance Testing, Security Code Review, Infrastructure Security Audit), Web Application Protection, Network Protection, Managed IT Services, IoT solutions, Data Analytics.
Products: IBM QRadar for Security Intelligence, QLean for QRadar Health Check and ScienceSoft SIEM for Automated Security Monitoring.


ScienceSoft
#2) Acunetix
It complements the role of a penetration tester by automating tasks that can take hours to test for manually, delivering accurate results with no false positives at top speed. Acunetix fully supports HTML5, JavaScript and Single-page applications as well as CMS systems.It includes advanced manual tools for penetration testers and integrates with popular Issue Trackers and WAFs.
#3) Netsparker
It facilitates the role of a penetration tester since you do not need to waste hours manually verifying the identified vulnerabilities once a scan is finished.It is available as a Windows software and an online service.
#4) CyberHunter
Core Services: Penetration Testing, Network Threat Assessments, Network Security Audits, Cyber Threat Hunting, Network Log Monitoring.
Products: TrendMicro, Ericom, Sucuri, InfoCyte, Sepio Systems, Votiro
#5) Raxis
Core Services: Penetration testing, red team penetration testing, web application penetration testing, mobile application penetration testing, API & secure code review, vulnerability assessments, physical social engineering, phishing, tabletop exercises, incident response, etc.
#6) ImmuniWeb®
Its proven Machine Learning and AI technology were mentioned by Gartner, Forrester and IDC technology analysts for innovation and effectiveness.The hottest products endorsed by verified users at Gartner Peer Insights are:
  • ImmuniWeb® Discovery for a turnkey asset discovery and risk ratings (web, mobile, cloud, domains, certs, IoT);
  • ImmuniWeb® On-Demand for a turnkey web penetration testing (web, API, cloud, AWS);
  • ImmuniWeb® MobileSuite for a turnkey mobile penetration testing (iOS and Android App, Backend API);
  • ImmuniWeb® Continuous for 24/7 continuous security monitoring and penetration testing (web, API, cloud, AWS).

ImmuniWeb’s community offering also provides industry practitioners with FREE:
  • SSL Security Test
  • Website Security Test
  • Mobile App Security Test
  • Phishing Test

#7) Indusface WAS
Features
  • New age crawler to scan single page applications.
  • Pause and resume feature
  • Manual Penetration testing and publish the report in the same dashboard
  • Unlimited proof of concept requests to provide evidence of reported vulnerability and eliminate false positive from automated scan findings
  • Optional integration with the Indusface WAF to provide instant virtual patching with Zero False positive
  • Ability to automatically expand crawl coverage based on real traffic data from the WAF systems (in case WAF is subscribed and used)
  • 24×7 support to discuss remediation guidelines and POC
  • Free trial with a comprehensive single scan and no credit card required
#8) SecureWorks
Core Services: Pen Testing Services, Application Security Testing, Advance Threat/Malware detection and prevention, Log Retention and Compliance Reporting, Vulnerability Management, Risk Assessment, Cloud Security Monitoring, Incident Management etc.
Products: Managed Security Solutions, Information Security Solutions, Compliance Management Solutions, Threat Protection Solutions, Cybersecurity Risk Management Solutions, Industry Solutions etc.
#9) BreachLock Inc
Core Services: Vulnerability Management, Pen Testing as a Service, Third Party Penetration Testing, Vendor Assessments, Phishing as a Service, RED Teaming, Cloud Penetration Testing, Mobile Application Penetration Testing, IoT Penetration Testing, Web Application Penetration Testing, Network Penetration Testing, etc.
Products: RATA Web Application Vulnerability Scanner, and RATA Network Vulnerability Scanner.
#10) FireEye
Core Services: Penetration Testing, Security Program Assessment, Red Team Assessment, Response Readiness Assessment, Training Services, Deployment and Integration Services, Cyber Threat Intelligence Services, etc.
Products: Helix The Security Operations Platform, FireEye Threat Analytics, FireEye Security Suit, Email Security, Network Forensic and Security, Threat Intelligence, Endpoint Security, etc.
#11) Rapid7
Core Services: Penetration Testing, Vulnerability Management, Training, and Certification Services, Advisory Services.
Products: Metasploit for Penetration Testing, Nexpose for Vulnerability Management, Insight VM for Vulnerability Assessment, InsightIDR for User Behaviour Analytics, Insight Ops for IT Operations, InsightPhish for Phishing Simulation, Komand for Automation
#12) CA Veracode
Core Services: Pen Testing Services, Program Management, E-Learning, Third Party Security.
Products: CA Veracode Greenlight for Instant Scanning, CA Veracode Developer Sandbox for Evaluating Code, CA Veracode Static Analysis for Assessing integrated application for policy compliance, CA Veracode Software Composition Analysis for Eliminating Risk in Open Source Component.
#13) Coalfire Labs
Core Services: Penetration Testing, Application Security Assessment, Vulnerability Scanning & Assessment, Research and Development, Red Team Exercise etc.
Products: CoalfireOne Scanning Solution, Cyber Defence for Cyber Security, Compliance Services Products like HIPAA, GDPR etc.
#14) Offensive Security
Core Services: Penetration Testing, Advance Attack Simulation Services, Application Security Assessment, certification etc.
Products: Kali Linux, Exploit Database, Kali NetHunter, BackTrack, Metasploit Unleashed etc.
#15) Netragard
Core Services: Pen Testing Services, Vulnerability Assessment, Point of Sales (PoS) Testing etc.


Fuente: softwaretestinghelp.com


miércoles, 26 de junio de 2019

Lo que dejo BSIDES CÓRDOBA 2019



Descarga de presentaciones:
Nombre de la Charla
Slides
Video
Testeando seguridad en aplicaciones moviles
Dime quien eres y... no no, deja que ya lo sé
Traffic Logs for fun and IDOR's
Preventing attacks to Helm on K8s
CyberWeapons Lab for RedTeamers
Detección de ransomware en tiempo real
Hunting For Memory Resident Malware
Malware Less, infección Sin Archivos
Control Flow Hijacking detection through Intel PT
Web del evento




miércoles, 15 de mayo de 2019

11 Best PHP Code Security Scanner to Find Vulnerabilities

1PMF

PHP Malware Finder (PMF) is a self-hosted solution to help you find possible malicious codes in the files. It is known to detect dodgy, encoders, obfuscators, webshells code.

2RIPS

RIPS is one of the popular PHP static code analysis tools to be integrated through the development lifecycle to find security issues in the real-time. You can categorize the finding by industry compliance and standard to prioritize the fixes.

3SonarPHP

SonarPHP by SonarSource uses pattern matching, data flow techniques to find vulnerabilities in PHP codes. It is a static code analyzer and integrates with Eclipse, IntelliJ.

4SensioLabs

SensioLabs leverage composer.lock file to check for known security risk. Checker is available in three ways.
  • Online – you upload your composer file to perform a test
  • CLI – download the tool to use it locally or integrate within the development lifecycle
  • API – use web service to check vulnerabilities. Results are available in text and JSON format.

5Exakat

A real-time static code analyzer engine to check compliance, risk and reinforce best practices. Exakat got more than 300 analyzers dedicated to PHP. There are framework specific analyzers like WordPress, CakePHP, Zend, etc.

6PHPStan

PHPStan is a fantastic tool to find bugs as you write the code. You don’t need to run anything.

7Psalm

Built on top of PHP Parser, Psalm is good to find errors and help to maintain consistency for better and secure application.

8Checkmarx

Checkmarx, a cloud-based solution to find vulnerabilities in PHP code and get a recommendation on how to fix them. Every vulnerability is explained, so you understand the impact.

9Progpilot

Progpilot static analyzer let you specify the analysis type like GET, POST, COOKIE, SHELL_EXEC, etc. It supports suiteCRM and CodeIgniter framework at the moment.

10PHP Vulnerability Hunter

A fuzzer to look for vulnerabilities using static and dynamic analysis. This hunter is capable of hunting the following.
  • Cross-site scripting
  • SQL injection
  • Arbitrary  file read and command execution
  • Local file inclusion
  • Full path disclosure
The scan is done in three phases – initialization, scan and un-initialization

11Grabber

Grabber, a python based tool to perform hybrid analysis on a PHP-based application using PHP-SAT.
11 Best PHP Code Security Scanner to Find Vulnerabilities
Fuente: geekflare.com


viernes, 11 de mayo de 2018

Best security software 2018

BluVector  Category: Network security

BluVector offers advanced detection and response, and even threat hunting, all performed at machine speeds. BluVector works almost right away, but also has deep machine learning capabilities, so it gets even smarter over time. It will learn the intricacies of each network that deploys it, tweaking its algorithms and detection engines in a way that makes the most sense for the environment. Read the full review.

Bricata  Category: Intrusion detection

At it’s core, Bricata offers advanced IPS/IDS protection with multiple detection engines and threat feeds to defend network traffic and core assets. But it goes a step farther, adding the ability to launch threat hunts based on events, or simply anomalies. Read the full review.

Cloud Defender  Category: Cloud security

Cloud Defender is a user-friendly tool that lets local IT staff inspect their cloud deployments to look for evidence of hidden threats or breaches. But it can also be used in a SaaS model, with the cybersecurity team at Alert Logic taking over most cloud-based cybersecurity functions. Read the full review.



Contrast Security has one of the most elegant solutions out there for application security. The secret sauce is its use of bytecode instrumentation, a feature in Java used to help integrate programs and application features during development. Read the full review.



Digital Guardian  Endpoint security

The Digital Guardian Threat Aware Data Protection Platform is at the forefront of the effort to counter advanced threats, offering ready-to-deploy endpoint security locally on-premises or as a service, and with whatever automation level a host organization feels comfortable supporting. Read the full review.

enSilo  Endpoint security

The enSilo platform offers traditional endpoint protection alongside the ability to offer post-infection protection. It can also trap threats, holding them in place and rendering them harmless until a threat hunter can arrive to investigate. Read the full review.

Intellicta Platform  Category: Compliance

The Intellicta Platform from TechDemocracy acts like an SIEM console, but for compliancy issues. It pulls information from a series of network collectors and correlates that data into a continuously-monitored compliancy dashboard. Read the full review.

Insight Engines  Categories: Network security, threat hunting

Think of the Insight Engines tool as Google for network security, allowing natural language searches and returning honed information to answer each query. This comparison doesn't do the program justice, but is a good starting point for understanding how it works. Read the full review.

Mantix4  Category: Threat hunting

Mantix4 takes threat hunting into the software as a service (SaaS) realm. While the program provides robust threat hunting tools for use by clients, the company also employs a team of experts to hunt on their behalf. Read the full review.


Best security software, 2017

Acalvio ShadowPlex  Category: Deception

Deception is an emerging field, and some of the drawbacks preventing easy, useful deployments are still being worked out. Acalvio ShadowPlex addresses some of those problems, offering clients unlimited deception assets without constant overhead or maintenance. Read the full review.

Attivo  Category: Deception

Attivo addresses the one main weakness of most deception technology, having to rely on other programs to respond to an attack once revealed by the deception network. The Attivo platform offers quick response capabilities and the ability to interact with third-party programs for additional backup, configured using an intuitive drag and drop interface that requires very little training. Read the full review.

Barracuda Web Application Firewall  Category: Network security

Calling the Barracuda WAF a firewall is seriously selling it short. It’s more like the core of an independent bastion of cybersecurity, able to inspect both inbound and outgoing traffic. The WAF functions like a reverse proxy and is placed at the front of the data pathway. Read the full review.



Bay Dynamics Risk Fabric  Category: Vulnerability management

Failure to understand context is one of the major problems in the vulnerability management space that the Bay Dynamics Risk Fabric program is designed to solve. By adding real context to raw scan results, IT teams are given a much better picture of the true risks hiding within their networks, including the potential costs if those problems are not fixed quickly. Read the full review.

Bitdefender HVI  Category: Remote browser

The Bitdefender Hypervisor Introspection (HVI) tool sits below the hypervisor and prevents any of these tactics such as buffer overflows, heap sprays, code injection and API hooking from executing, protecting the virtual browser from ever becoming compromised. Read the full review.

CAWS Continuous Security Validation Platform  Category: Vulnerability management

At its core, CAWS is a testing lab dedicated to finding and fixing threats against networks. Customers who make use of the program can elect to use one of two flavors of the product: A public instance that identifies threats and provides detailed information about how customers can patch their own networks, and a private instance that runs threats against a mirror network. Read the full review.

Crossbow  Category: Vulnerability management

The vulnerability assessment platform is one of the most realistic tools, but also one of the most dangerous, that CSO has ever reviewed. All of the attacks that it can load or create are real, using actual techniques and tactics that have historically broken through cybersecurity defenses at many organizations. Read the full review.

Cyphon  Category: Managed detection

For armored car service Dunbar, protecting its clients' money is more than just building secure physical structures and deploying armored trucks with armed guards. It’s also about protecting the digital infrastructure and cyber assets that support those operations. Cyphon was first created, to be used internally by the company to protect its assets. After that, rolling it out as service to clients easily fit into their protection-as-a-service model. Read the full review.

GreatHorn  Category: Network security

Because most email gateway appliances only scan for known bad domains or the presence of malware, “please hand me the cash”-type social engineering phishing attacks normally breeze through security. GreatHorn was designed to close that security gap, as well as lock down the rest of the mail stream.  Read the full review.

GuardiCore Centra  Category: Network security

Micro segmentation is one of the most advanced security methods that organizations can employ to protect critical assets, users, and data from both outside hackers and malicious insiders. Authorizing every process, app, user and service within a network, and what each of them can do and how they can interact, while denying everything else, is a heck of a gauntlet to throw down. The GuardiCore Centra solution eliminates much of the complexity normally associated with micro segmentation from the initial installation to ongoing program management. Read the full review.

InfoZen  Category: DevOps

For this review, InfoZen was brought in to create a fully-end-to-end DevOps scanning solution using their InfoZen Cloud and DevOps Practice service. Even within our admittedly tiny test environment, the benefits of the InfoZen toolset and automatic processes were obvious. Read the full review.

Kenna Security  Categtry: Vulnerability management

Kenna Security's vulnerability management platform is designed to prioritize the most dangerous vulnerabilities that could potentially harm a protected network. In a nutshell, it monitors most major threat feeds, and compares that data with assets inside a protected network. Read the full review.

Lacework  Category: Cloud security

Managing even a local data center is a tough job. Keeping a cloud secure is even more difficult. Lacework helps to filter all the chaos, removing false positives, and generating actionable threat intelligence in real-time for IT teams tasked with keeping their clouds secure. Read the full review.

Minerva  Category: Endpoint security

Minerva's Anti-Evasion Platform targets the new breed of environmentally-aware malware. The idea is that most normal threats will be blocked by traditional antivirus and Minerva will stop anything that attempts to get around that protection. Read the full review.

Promisec  Category: Endpoint security

Every organization can use a little help managing their detection and response of threats, and the many issues that crop up every day within their enterprise. Promisec can provide that help, wrestling endpoints into compliance, automatically if desired, and keeping a watchful eye over them to ensure they stay that way. Read the full review.

RedSeal  Category: Network security

When CSO's sister site Network World conducted its firewall manager review, the original plan was to invite RedSeal to participate. The problem was that while RedSeal originally did manage firewalls, their product has now evolved into something else. RedSeal shares some similarities to firewall managers, but is now in a separate, unique product group. Read the full review.

SecBI  Category: Traffic analysis

SecBI's new software aims to eliminate two of the problems with using traffic analysis in cybersecurity: volume processing of data for actionable threat intelligence and a reliance on network trapping hardware. We dig into how it works. Read the full review.

Sqrrl  Category: Traffic monitoring

Sqrrl Data turns network traffic monitoring into a true threat hunting platform that is easily capable of unmasking advanced threats that many other programs miss — or fail to identify as the grave threat they truly are. Read the full review.

ThreatConnect  Category: Managed detection

There is no shortage of threat feeds available today. Adding a tool like ThreatConnect, which can bridge the gap between theoretical threat information and the real world, is an invaluable tool for managing and optimizing detection and response capabilities. Read the full review.

vArmour  Category: Cloud security

The vArmour suite of tools is designed, first, to reestablish a software perimeter internally and then to hone the rules and policies that make up that backbone, delving all the way into the realm of micro segmentation. Read the full review.

Waratek  Category: Container security

Waratek is entering this space from a completely different angle compared to other container security firms, relying on just-in-time compiling and focusing exclusively on one of the biggest security risks within most organizations, applications running Java. Read the full review.

XebiaLabs DevOps Platform  Category: DevOps

DevOps is a hot topic in security these days, and for good reason: Software security flaws are often only discovered after an attacker has exploited them, which can cause huge losses of both data and revenue. Here's a look at how XebiaLabs helps navigate DevOps deployments and operations. Read the full review.

Fuente: csoonline.com