Archive for the 'Framework' Category

Free alternative to ArcSight ESM ? Hardly..

I discovered today a free security product which addresses one of the fastest growing IT Security Management problem: security logs, events and incidents. The name of the product is QRadar Simple Log and Information Management Free Edition (SLIM FE) and it’s been released by Q1 Labs.

Share This

Starting A Computer Security Incident Response Team ?

In case you neded a place to start in evaluating the steps required for building a Computer Security Incident Response Team (CSIRT) , look no further. CERT/CC has released the Action List for Developing a Computer Security Incident Response Team (CSIRT) .

Share This

The Standard of Good Practice for Information Security

Today I came across the The Standard of Good Practice for Information Security which has been produced by the Information Security Forum (ISF), an international association of over 260 leading organisations which fund and co-operate in the development of a practical research programme in information security.
The ISF’s work probably represents the most comprehensive and […]

Share This

PIRANA, the SMTP fuzzing and bruteforce tool

PIRANA is a SMTP fuzzing and bruteforce exploitation framework that tests the security of a SMTP content filter. By means of a vulnerability database, the content filter to be tested will be bombarded by various emails containing a malicious payload intended to compromise the SMTP server

Share This

Common Vulnerability Scoring System CVSS 2.0 unifies vulnerability scoring

The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.

Share This

w3af, the Web Application Attack and Audit Framework

Andres Riancho has released w3af 1.0 - the Web Application Attack and Audit Framework.This framework is written in python and resembles a bit to metasploit having an architecture based on plugins

Share This

New European ICT Security Standards Roadmap

One of the objectives of this security standards portal named “ICT Security Standards Roadmap” is to provide a central tracking facility for NIS standards. It facilitates identification of standards and standardization activities, as well as coordination among standardization bodies, reduction of duplicate work and easier identification of existing gaps.

Share This

NIST CSRC Special Publications June Update

NIST publications : Guidelines on Cell Phone Forensics, Guide for Assessing the Security Controls in Federal Information Systems, Guidelines on Securing Public Web Servers, User’s Guide to Securing External Devices for Telework and Remote Acces, Specification for the Extensible Configuration Checklist Description Format (XCCDF)

Share This

Software Security Assurance: A Framework for Software Vulnerability Management and Audit

Ounce Labs released a valuable resource for everybody involved in the Software Security business. “Software Security Assurance: A Framework for Software Vulnerability Management and Audit” is more than a framework, it’s a call to action driven by the need for better understanding of roles and responsibilities in software security assurance.

Share This

Metasploit Framework version 3.0 RELEASED

Metasploit is pleased to announce the immediate, free availability of the Metasploit Framework version 3.

Share This
Pages (2): [1] 2 »
Close
E-mail It