Mostrando entradas con la etiqueta Ranking. Mostrar todas las entradas
Mostrando entradas con la etiqueta Ranking. Mostrar todas las entradas

sábado, 27 de noviembre de 2021

Los 8 mejores libros de seguridad cibernética, recomendados por los expertos

Los buenos libros de seguridad cibernética comparten ideas obtenidas de situaciones del mundo real y ejemplos de los que podemos aprender como profesionales. Son los grandes los que nos enseñan a qué debemos prestar atención para que estemos preparados para evitar ser víctimas de los ciber delincuentes.


    1. Hackeo: El Arte de la Explotación (2ª Ed.).
    2. El arte de la invisibilidad: el pirata informático más famoso del mundo te enseña a estar seguro en la era de Big Brother y Big Data.
    3. Ghost in the Wires: Mis aventuras como el hacker más buscado del mundo.
    4. The Code Book: La ciencia del secreto del antiguo Egipto a la criptografía cuántica.
    5. Culto de la vaca muerta: cómo el supergrupo de piratería original podría salvar al mundo.
    6. Ingeniería Social: La Ciencia del Pirateo Humano.
    7. Análisis Práctico de Malware.
    8. La guía del CERT sobre las amenazas internas.



    sábado, 3 de julio de 2021

    Global Cybersecurity Index 2020 (ITU)

    Se presentó la cuarta edición del prestigioso ranking de ciberseguridad mundial Global Cybersecurity Index, desarrollado por la Unión Internacional de Telecomunicaciones (ITU, agencia de las Naciones Unidas especializada en la coordinación de las telecomunicaciones a nivel global), el cual refleja los avances logrados en materia de ciberseguridad por los 194 estados miembros y presentado hoy.

    METODOLOGÍA:

    Este índice recoge 82 preguntas sobre los compromisos de ciberseguridad de los estados miembros en cinco pilares: medidas legales, técnicas, organizativas, de desarrollo de capacidad y de cooperación.

    1.         Medidas legales: Medición de la madurez de las leyes y normativas sobre ciberdelincuencia y ciberseguridad.

    En este pilar se evalúan cuestiones tales como: que los países evaluados cuenten con algún tipo de legislación sobre ciberseguridad, normativa de protección de datos y normativa sobre infraestructuras críticas.

    2.         Medidas técnicas: Medición de la aplicación de las capacidades técnicas a través de los organismos nacionales y sectoriales.

    En este pilar se evalúan cuestiones tales como: que los países evaluados tengan CSIRT activos, participen en un CSIRT regional y que cuenten con mecanismos de notificación para la protección de la infancia en línea.

    3.         Medidas organizativas: Medición de las estrategias nacionales y las organizaciones que aplican la ciberseguridad.

    En este pilar se evalúan cuestiones tales como: que los países evaluados tengan estrategias nacionales de ciberseguridad, agencias de ciberseguridad, estrategias e iniciativas de protección de la infancia en línea.

    4.         Medidas de desarrollo de capacidad: Medición de las campañas de concientización, la formación, la educación y los incentivos para el desarrollo de capacidades en ciberseguridad.

    En este pilar se evalúan cuestiones tales como: que los países evaluados lleven a cabo iniciativas de concientización en materia de ciberseguridad, que cuenten con programas de I+D en ciberseguridad y que declaren tener industrias nacionales de ciberseguridad.

    5.         Medidas de cooperación: Medición de la colaboración entre agencias, empresas y países.

    En este pilar se evalúan cuestiones tales como: que los países evaluados participen en asociaciones público-privadas de ciberseguridad, que cuenten con acuerdos bilaterales de ciberseguridad y con acuerdos multilaterales de ciberseguridad.

     

    Descarga del reporte

     

     

     

    jueves, 19 de diciembre de 2019

    15 Best Free Penetration Testing Tools 2019

    There is a bunch of penetration testing tools available on the internet. This article brings to you the 12 most coveted, critically acclaimed, and best penetration testing tools.


        1. Netsparker
        2. Coreimpact
        3. Metasploit
        4. W3AF
        5. Nessus
        6. Cain & Abel
        7. Accunetix
        8. Probe.ly
        9. Wiresharker
        10. Kali Linux
        11. Burpsuite
        12. Zedattackproxy(ZAP)
        13. Openvas
        14. Sboxr
        15. Webscarab


    1. Netsparker

    Netsparker is perhaps the most accurate penetration testing tool. It automatically identifies vulnerabilities in both web API’s and applications.

    Features
      penetration testing tools
    • Considered as a pioneer in web application security
    • NETSPARKER eliminates the need for the penetration tester to manually sit and test different vulnerabilities.
    • All the real vulnerabilities are brought into the limelight just with a simple scan and it is capable of finding vulnerabilities like cross-site scripting, SQL injection and so on. You can simply download and install it from the internet.
    • Can easily integrate with CI/CD and other systems in software development, in short a fully customizable work flow can be created
    • Verified bugs are automatically posted to the bug tracking system
    2. Core impact

    It is one of the oldest penetration testing tools present in the market. The range of exploits in this penetration testing tool is impeccable.

    Features
    penetration testing tools
    •  Core Impact has Metasploit exploits, automated wizard processes, PowerShell commands etc. Exploits written by Core Impact are commercial grade and widely used in both companies and security consultancies. The price of this tool is on the higher side but you get exactly what you are paying for.
    • Has the ability to replicate attack across systems, devices and applications
    • Security posture can be validated by methods used by dreaded cyber-criminals
    • An up-to-date library on leading threats
    • Programmable self-destruct capability so that no loose end will be left behind
    • The reporting feature of the tool can be used for compliance validation
    • Can be used for network testing
    • Can capture information shared between a real user and the website

    3. Meta sploit

    It is one of the most prevalent and advanced penetration testing tools for penetration testing. It has a set of exploits that can enter a system bypassing its security. If the exploit successfully enters the system, a payload is run which basically provides a framework for testing.

    Features
      penetration testing tools
    • This is a commercial product; therefore you have to purchase it after the free trial if you want access to all the features. Metasploit is compatible with Windows, Linux, and Mac OS X.
    • There are modules which can send sequence of commands that can focus on particular type of vulnerability
    • Metasploit can be used to gain as much as information to learn about the weakness of a software system.
    • Has a database that can store system log, host data and evidence
    • A multi-function payload module

    4. W3AF

    This is a free penetration testing tool and to be frank, does a great job. It has a bunch of useful features like fast HTTP requests, injecting payloads, various HTTP requests and so on.
    Features
      penetration testing tools
    • The user interface of W3AF is compatible with Windows, Linux, and Mac OS X. Unlike other tools, this one is free to download and use.
    • Has web and proxy servers that can be easily integrated to code of the software
    • Helps in sending lightning speed HTTP request owing to the surplus of extension
    • Various type of logging method such as Console, Text, CSV, HTML and XML
    • Be it any part of the HTTP request, W3af can inject any type of payload

    5.
    Nessus

    Nessus is a very capable vulnerability scanner with website scan, IP scan, and has a sensitive data search specialist module. All these functionalities are built into Nessus and help in finding vulnerabilities in the system, capable of handling all testing environments.

    Features
    • Up-to-date database that’s updated on a daily basis
    • Can be used to expose scalability
    • (Nessus Attack Scripting Language) NASL is used as the scripting language
    • Nessus can identify FTP server on a non-standard port, or even a web server running on  port 8080
    • The tool can make services like https, smtps look like SSL so that it can be injected to a PKI type environment.



    Fuente:www.testbytes.net


    viernes, 20 de septiembre de 2019

    Top Cybersecurity Companies

    Methodology

    Cybersecurity vendors were assigned scores based on their annual revenue, range of products, appearance in eSecurity Planet's Top Security Vendor lists, Gartner Magic Quadrant reports, Gartner Peer Review ratings, and their rankings in the Cybersecurity 500. The top 15 vendors are listed below followed by 10 honorable mentions.

    1. Microsoft

    Cybersecurity product categories: Identity and access managementUEBA, threat protection, information protection, security management, cloud securityDDoS protection, application gateways

    2. Fortinet

    Cybersecurity product categories: Firewallsintrusion prevention and endpoint security


    3. IBM

    Cybersecurity product categories: Security analytics, servicespatch managementencryptionSIEMsecurity orchestrationmobile security, fraud protection, network security, data protection, threat intelligenceapplication security, endpoint protection, identity and access management, mainframe security


    4. KnowBe4

    Cybersecurity product categories: Cybersecurity awareness training


    5. Symantec

    Cybersecurity product categories: Advanced threat protection, managed servicesendpoint securityencryptionweb gatewayemail security, network security, cloud security, antivirus, identity theft protection, website security


    6. Cisco

    Cybersecurity product categories: Next-generation firewallsnext-generation intrusion preventionCASB, web gateway, NAC, advanced malware protection, email security, endpoint security, security management, VPN, security services


    7. Palo Alto Networks

    Cybersecurity product categories: Next-generation firewall, UEBA, cloud security, endpoint protection, threat detection and prevention, application framework


    8. Splunk

    Cybersecurity product categories: Security analytics, SIEM, user behavior analytics, ransomware prevention, security automation


    9. McAfee

    Cybersecurity product categories: consumer antivirus and privacy protection, identity theft prevention, IDPS, web gateways, mobile security, CASB, data protection, encryption, endpoint security, network security, security management, server security, security analytics, SIEM, web security, consulting


    10. Check Point

    Cybersecurity product categories: Advanced threat prevention, next generation firewallUTMencryption, secure gateway appliances, endpoint protection, remote access, cloud security, mobile security

    11. Sophos

    Cybersecurity product categories: Firewallsunified threat management, web gateway, secure email gateway, security management, anti-phishing, endpoint protection, mobile security, encryption, server security, web application firewalls, consumer antivirus and Web filtering.


    12. Proofpoint

    Cybersecurity product categories: CASB, advanced threat protection, email protection, encryption, data loss prevention, threat intelligence


    13. Imperva


    Cybersecurity product categories: Web application firewalls, data masking, database securityDDoS mitigation


    14. RSA (Dell Technologies)


    Cybersecurity product categories: SIEMGRCthreat intelligence, network traffic analysis and forensics, endpoint security, security orchestration, UEBA, malware detection, fraud prevention, identity and access management

    15. Trend Micro
    Cybersecurity product categories: hybrid cloud security, intrusion prevention, advanced threat protection, encryption, endpoint security, email security, Web security, SaaS security, IoT security, threat intelligence
    Appearances on eSecurity Planet's Top Vendors lists: 2

    Honorable Mentions
    The following companies scored well but didn't quite make our top 15.
    1. Kaseya (network and infrastructure monitoring, patch management)
    2. Barracuda (email security, backup, web gateways, NGFWWAFUTM)
    3. Carbon Black (endpoint)
    4. Exabeam (security intelligence, analytics)
    5. FireEye (endpoint and threat detection)
    6. Darktrace (AI for cyber defense)
    7. SonicWall (UTMNGFWWAF)
    8. Tanium (EDR)
    9. LogRhythm (SIEM, UEBA)
    10. Micro Focus (SIEMencryptionpatch managementsingle sign-on)

    Top Penetration Testing Companies Worldwide In 2019

    Penetration Testing Companies and service providers

    #1) ScienceSoft
    Core Services: Security Testing (Vulnerability Assessment, Penetration Testing, Compliance Testing, Security Code Review, Infrastructure Security Audit), Web Application Protection, Network Protection, Managed IT Services, IoT solutions, Data Analytics.
    Products: IBM QRadar for Security Intelligence, QLean for QRadar Health Check and ScienceSoft SIEM for Automated Security Monitoring.


    ScienceSoft
    #2) Acunetix
    It complements the role of a penetration tester by automating tasks that can take hours to test for manually, delivering accurate results with no false positives at top speed. Acunetix fully supports HTML5, JavaScript and Single-page applications as well as CMS systems.It includes advanced manual tools for penetration testers and integrates with popular Issue Trackers and WAFs.
    #3) Netsparker
    It facilitates the role of a penetration tester since you do not need to waste hours manually verifying the identified vulnerabilities once a scan is finished.It is available as a Windows software and an online service.
    #4) CyberHunter
    Core Services: Penetration Testing, Network Threat Assessments, Network Security Audits, Cyber Threat Hunting, Network Log Monitoring.
    Products: TrendMicro, Ericom, Sucuri, InfoCyte, Sepio Systems, Votiro
    #5) Raxis
    Core Services: Penetration testing, red team penetration testing, web application penetration testing, mobile application penetration testing, API & secure code review, vulnerability assessments, physical social engineering, phishing, tabletop exercises, incident response, etc.
    #6) ImmuniWeb®
    Its proven Machine Learning and AI technology were mentioned by Gartner, Forrester and IDC technology analysts for innovation and effectiveness.The hottest products endorsed by verified users at Gartner Peer Insights are:
    • ImmuniWeb® Discovery for a turnkey asset discovery and risk ratings (web, mobile, cloud, domains, certs, IoT);
    • ImmuniWeb® On-Demand for a turnkey web penetration testing (web, API, cloud, AWS);
    • ImmuniWeb® MobileSuite for a turnkey mobile penetration testing (iOS and Android App, Backend API);
    • ImmuniWeb® Continuous for 24/7 continuous security monitoring and penetration testing (web, API, cloud, AWS).

    ImmuniWeb’s community offering also provides industry practitioners with FREE:
    • SSL Security Test
    • Website Security Test
    • Mobile App Security Test
    • Phishing Test

    #7) Indusface WAS
    Features
    • New age crawler to scan single page applications.
    • Pause and resume feature
    • Manual Penetration testing and publish the report in the same dashboard
    • Unlimited proof of concept requests to provide evidence of reported vulnerability and eliminate false positive from automated scan findings
    • Optional integration with the Indusface WAF to provide instant virtual patching with Zero False positive
    • Ability to automatically expand crawl coverage based on real traffic data from the WAF systems (in case WAF is subscribed and used)
    • 24×7 support to discuss remediation guidelines and POC
    • Free trial with a comprehensive single scan and no credit card required
    #8) SecureWorks
    Core Services: Pen Testing Services, Application Security Testing, Advance Threat/Malware detection and prevention, Log Retention and Compliance Reporting, Vulnerability Management, Risk Assessment, Cloud Security Monitoring, Incident Management etc.
    Products: Managed Security Solutions, Information Security Solutions, Compliance Management Solutions, Threat Protection Solutions, Cybersecurity Risk Management Solutions, Industry Solutions etc.
    #9) BreachLock Inc
    Core Services: Vulnerability Management, Pen Testing as a Service, Third Party Penetration Testing, Vendor Assessments, Phishing as a Service, RED Teaming, Cloud Penetration Testing, Mobile Application Penetration Testing, IoT Penetration Testing, Web Application Penetration Testing, Network Penetration Testing, etc.
    Products: RATA Web Application Vulnerability Scanner, and RATA Network Vulnerability Scanner.
    #10) FireEye
    Core Services: Penetration Testing, Security Program Assessment, Red Team Assessment, Response Readiness Assessment, Training Services, Deployment and Integration Services, Cyber Threat Intelligence Services, etc.
    Products: Helix The Security Operations Platform, FireEye Threat Analytics, FireEye Security Suit, Email Security, Network Forensic and Security, Threat Intelligence, Endpoint Security, etc.
    #11) Rapid7
    Core Services: Penetration Testing, Vulnerability Management, Training, and Certification Services, Advisory Services.
    Products: Metasploit for Penetration Testing, Nexpose for Vulnerability Management, Insight VM for Vulnerability Assessment, InsightIDR for User Behaviour Analytics, Insight Ops for IT Operations, InsightPhish for Phishing Simulation, Komand for Automation
    #12) CA Veracode
    Core Services: Pen Testing Services, Program Management, E-Learning, Third Party Security.
    Products: CA Veracode Greenlight for Instant Scanning, CA Veracode Developer Sandbox for Evaluating Code, CA Veracode Static Analysis for Assessing integrated application for policy compliance, CA Veracode Software Composition Analysis for Eliminating Risk in Open Source Component.
    #13) Coalfire Labs
    Core Services: Penetration Testing, Application Security Assessment, Vulnerability Scanning & Assessment, Research and Development, Red Team Exercise etc.
    Products: CoalfireOne Scanning Solution, Cyber Defence for Cyber Security, Compliance Services Products like HIPAA, GDPR etc.
    #14) Offensive Security
    Core Services: Penetration Testing, Advance Attack Simulation Services, Application Security Assessment, certification etc.
    Products: Kali Linux, Exploit Database, Kali NetHunter, BackTrack, Metasploit Unleashed etc.
    #15) Netragard
    Core Services: Pen Testing Services, Vulnerability Assessment, Point of Sales (PoS) Testing etc.


    Fuente: softwaretestinghelp.com


    miércoles, 18 de septiembre de 2019

    Top 30 BEST Cyber Security Companies In 2019 (Small To Enterprise Level Firms)



    An In-Depth Look at the Top leading and largest Cyber Security Companies and Venture Firms with Detailed Comparison:



    Last Updated:


    #1) ScienceSoft (McKinney, TX)

    #2) ImmuniWeb® (Geneva, Switzerland)

    #3) Symantec Enterprise Grade Cyber Security (Mountain View, CA)

    #4) Check Point Software Technologies Ltd (Tel Aviv, Israel)

    #5) Cisco (San Jose, CA)

    #6) Palo Alto Networks (SANTA CLARA, California)

    #7) McAfee (SANTA CLARA, California)

    #8) IBM (Armonk, NY)

    #9) Trend Micro Inc. (Shibuya, Tokyo, Japan)

    #10) Microsoft (Redmond, WA)

    #11) Amazon (Seattle, WA)

    #12) CyberArk Software (Newton, MA)

    #13) FireEye (Milpitas, California)

    #14) Imperva (Redwood Shores, California)

    #15) Proofpoint (Sunnyvale, California)

    #16) Fortinet (Sunnyvale, California)


    Cyber security Companies

    Fuente: softwaretestinghelp.com



    jueves, 15 de marzo de 2012

    Barcelona, la ciudad española con mayor riesgo frente a ciberdelitos

    Madrid, 13 mar (EFE).- Barcelona es la novena ciudad europea y la primera española con mayor riesgo frente a "ciberdelitos" según la lista presentada hoy y en la que se analizan factores como las incidencias en conexiones wifi e intentos de códigos malignos en la red.

    Manchester (GB), Amsterdam (Países Bajos), Estocolmo (Suecia), París (Francia), Londres (GB), Dublin (Irlanda), Milán y Roma (Italia), Barcelona y Berlín (Alemania) forman el ránking realizado por Sperling's BestPlaces para la compañía de seguridad informática Symantec.

    El gerente de Marketing para Norton Iberia, Roberto Testa, ha afirmado que el informe resalta los "factores de riesgo" a los que se enfrentan los usuarios cuando están conectados en internet y se encuentran expuestos "ante posibles amenazas en línea".
    Para realizar la clasificación se ha examinado el comportamiento de los consumidores en la utilización del ordenador, la navegabilidad en las redes sociales, el uso de teléfonos inteligentes y la conectividad en redes inalámbricas.

    Así Manchester se sitúa como la ciudad europea con mayor número de incidencias en conexiones wifi e intentos de "malware" (código maligno), explica la compañía que añade que los altos factores de riesgo, no se traducen necesariamente en altos niveles de infección.
    Ello, detallan, se debe a que muchos usuarios adoptan medidas de protección.
    Respecto a Barcelona señalan que ocupa el noveno puesto con la menor tasa de viviendas con PC y menor utilización de redes sociales respecto al resto de ciudades comparadas.
    Como medidas para evitar estos riesgos, los promotores del estudio, aconsejan utilizar con precaución los accesos wifi, y usar redes seguras en las compras en la red o acceso a banca electrónica, con independencia del tipo de dispositivo utilizado (tableta, portátil o smartphone...), así como emplear contraseñas fuertes, que combinen varios elementos. EFE

    Fuente: www.expansion.com


    Link relacionado:
     - Buenos Aires, la ciudad más riesgosa para usar Internet

    lunes, 12 de marzo de 2012

    2012 Internet Browser Software Product Comparisons

    Como complemento al post "Internet Explorer 9, Firefox 10 y Google Chrome 17, hackeados en Pwn2Own" les presentamos a continuación estadísticas de uso por región y el ultimo TOP 10 de toptenreviews.com:
    2012 Internet Browser Software Product Comparisons:


    Rank #1#2#3#4#5




       Excellent
       Very Good
       Good
       Fair
       Poor
    Google Chrome Firefox Internet Explorer Opera Safari




    Google Chrome Firefox Internet Explorer Opera Safari




    Reviewer Comments Read Review Read Review Read Review Read Review Read Review





















    More...

























































    Most Popular Browser By Country



    Significant changes since the last update:

    Firefox has become the most popular browser in Zambia.
    Chrome has become the most popular browser in the following countries:
    • Italy
    • Serbia
    • Georgia
    • Honduras
    • Nicaragua
    • Ecuador
    • Viet Nam

    www.browserrank.com



     

    sábado, 10 de marzo de 2012

    Top 10 Cyber-Security Infographics [Q1 Labs]

    As a marketing professional, I have a confession to make:  I am slightly obsessed with infographics.  That’s why I was so excited when my colleague at Q1 Labs decided to create one of our own.
    But, I’m not the only one who thinks infographics are a great way to visualize large amounts of information; I’ve heard others calling 2011 “the year of the infographic”.  So, why the buzz?  Read this quote from Soshable.com describing the value this tool provides to viewers:
    Rather than read a long article that describes data, infographics puts the data into a format that can be more easily taken in and can add a layer to the understanding by appealing to our natural visual acuity.
    Since one of the problems we solve with our Security Intelligence solutions is consolidating massive amounts of disparate raw data from the entire enterprise (network elements, data center assets, hosts, private and public cloud services, you name it) in the form of logs, events, external threat data, network flows, etc., into actionable, meaningful insight for companies-  I think infographics have a purpose that is similar to our own.  For that reason, in honor of the infographic, I bring you a list of the top cyber-security related posts from around the web.  Enjoy!

    1)      The Evolution of Modern SIEMDepiction of the change SIEM technology has undergone to evolve towards Security Intelligence.
    The Evolution of Modern SIEM
    Click to view full image

    2)      8 levels of information Technology Security“In a world of viruses, malware, and hackers, information security is a big deal. One single method of IT security cannot insure protection of mission-critical data.”
    8-levels of IT Security
    Click to view full image

    3)      Computer Threats: A Breakdown: The Spreading Infection of Software Virus & Scams“Depicts the growing cyber-threat landscape, including viruses, breaches, phishing scams and more.”

    Computer Security Threats Infographic
    Click to view full image


    More ...


    blog.q1labs.com