Archive for the 'Framework' Category
Friday, November 14th, 2008
I discovered today a free security product which addresses one of the fastest growing IT Security Management problem: security logs, events and incidents. The name of the product is QRadar Simple Log and Information Management Free Edition (SLIM FE) and it’s been released by Q1 Labs.
Share This
Leave Comment » | Posted in Framework, Report
Tuesday, August 21st, 2007
In case you neded a place to start in evaluating the steps required for building a Computer Security Incident Response Team (CSIRT) , look no further. CERT/CC has released the Action List for Developing a Computer Security Incident Response Team (CSIRT) .
Share This
Leave Comment » | Posted in Framework, Articles
Wednesday, August 8th, 2007
Today I came across the The Standard of Good Practice for Information Security which has been produced by the Information Security Forum (ISF), an international association of over 260 leading organisations which fund and co-operate in the development of a practical research programme in information security.
The ISF’s work probably represents the most comprehensive and […]
Share This
Leave Comment » | Posted in Framework, Guidelines
Thursday, July 5th, 2007
PIRANA is a SMTP fuzzing and bruteforce exploitation framework that tests the security of a SMTP content filter. By means of a vulnerability database, the content filter to be tested will be bombarded by various emails containing a malicious payload intended to compromise the SMTP server
Share This
Leave Comment » | Posted in Framework, Brute Force, Tools
Friday, June 29th, 2007
The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.
Share This
Leave Comment » | Posted in Vulnerabilities, Framework
Friday, June 15th, 2007
Andres Riancho has released w3af 1.0 - the Web Application Attack and Audit Framework.This framework is written in python and resembles a bit to metasploit having an architecture based on plugins
Share This
Leave Comment » | Posted in Framework, Web Applications, Tools
Friday, June 8th, 2007
One of the objectives of this security standards portal named “ICT Security Standards Roadmap” is to provide a central tracking facility for NIS standards. It facilitates identification of standards and standardization activities, as well as coordination among standardization bodies, reduction of duplicate work and easier identification of existing gaps.
Share This
Leave Comment » | Posted in Framework, Guidelines
Tuesday, June 5th, 2007
NIST publications : Guidelines on Cell Phone Forensics, Guide for Assessing the Security Controls in Federal Information Systems, Guidelines on Securing Public Web Servers, User’s Guide to Securing External Devices for Telework and Remote Acces, Specification for the Extensible Configuration Checklist Description Format (XCCDF)
Share This
1 Comment » | Posted in Framework, Guidelines, Articles
Friday, June 1st, 2007
Ounce Labs released a valuable resource for everybody involved in the Software Security business. “Software Security Assurance: A Framework for Software Vulnerability Management and Audit” is more than a framework, it’s a call to action driven by the need for better understanding of roles and responsibilities in software security assurance.
Share This
Leave Comment » | Posted in Reviews, Code Audit, Framework
Tuesday, March 27th, 2007
Metasploit is pleased to announce the immediate, free availability of the Metasploit Framework version 3.
Share This
Leave Comment » | Posted in Penetration Testing, Framework
Pages (2): [1] 2 »