Posts

Showing posts with the label Security Automation

Infection Monkey V1.6 - An Automated Pentest Tool

Image
The Infection Monkey is an opened upward source safety tool for testing a information center's resiliency to perimeter breaches in addition to internal server infection. The Monkey uses diverse methods to self-propagate across a information oculus in addition to reports success to a centralized Monkey Island server. The Infection Monkey is comprised of 2 parts: Monkey - H5N1 tool which infects other machines in addition to propagates to them Monkey Island - H5N1 dedicated server to command in addition to visualize the Infection Monkey's progress within the information center To read to a greater extent than almost the Monkey, see http://infectionmonkey.com Main Features The Infection Monkey uses the next techniques in addition to exploits to propagate to other machines. Multiple propagation techniques: Predefined passwords Common logical exploits Password stealing using Mimikatz Multiple exploit methods: SSH SMB RDP WMI Shellshock Conficker Sam...

Stoq - An Opened Upwards Origin Framework For Corporation Degree Automated Analysis

Image
stoQ is a automation framework that helps to simplify the to a greater extent than mundane in addition to repetitive tasks an analyst is required to do. It allows analysts in addition to DevSecOps teams the mightiness to chop-chop transition from dissimilar information sources, databases, decoders/encoders, in addition to numerous other tasks. stoQ was designed to move company produce in addition to scalable, spell likewise beingness thin plenty for private safety researchers. Want to acquire more? Read but about of the blog posts we've written to acquire more. Introduction to stoQ stoQ in addition to Enterprise e-mail Operationalizing Indicators stoQ amongst Suricata Plugins stoQ currently has over twoscore publicly available plugins. These plugins are available separately inwards the plugin repository Installation in addition to Documenation Want to boot the bucket started quickly? Check out the docker image . stoQ requires a minimum of python 3.4. Instal...

Shodanploit - Shodan Ascendancy Trouble Interface Written Inwards Python

Image
Shodan is a search engine on the cyberspace where y'all tin discovery interesting things all over the world. For example, nosotros tin discovery cameras, bitcoin streams, zombie computers, ports alongside weakness inwards service, SCADA systems, as well as more. Moreover, to a greater extent than specific searches are possible. As a number of the search, Shodan shows us the number of vulnerable hosts on Earth. So what does shodansploit produce ? With Shodan Exploit, y'all volition bring all your calls on your terminal. It also allows y'all to brand detailed searches. All y'all bring to produce without running Shodansploiti is to add together shodan api. Note : The character of the search volition alter according to the api privileges y'all bring used. Shodan API Documention : REST API Documentation Exploits REST API Documentation Shodan API Specification : Banner Specification The banner is the principal type of inform...

Turbinia - Automation Too Scaling Of Digital Forensics Tools

Image
Turbinia is an open-source framework for deploying, managing, as well as running distributed forensic workloads. It is intended to automate running of mutual forensic processing tools (i.e. Plaso, TSK, strings, etc) to attention amongst processing evidence inwards the Cloud, scaling the processing of large amounts of evidence, as well as decreasing reply fourth dimension yesteryear parallelizing processing where possible. How it works Turbinia is composed of dissimilar components for the client, server as well as the workers. These components tin dismiss live on run inwards the Cloud, on local machines, or as a hybrid of both. The Turbinia customer makes requests to procedure evidence to the Turbinia server. The Turbinia server creates logical jobs from these incoming user requests, which creates as well as schedules forensic processing tasks to live on run yesteryear the workers. The evidence to live on processed volition live on dissever upwards yesteryear the jobs when ...

Defectdojo V1.5.4 - Application Vulnerability Correlation In Addition To Safety Orchestration Application

Image
DefectDojo is a safety plan in addition to vulnerability management tool. DefectDojo allows y'all to deal your application safety program, hold production in addition to application information, schedule scans, triage vulnerabilities in addition to force findings into defect trackers. Consolidate your findings into i source of truth amongst DefectDojo. Demo Try out DefectDojo inward the  testing environment amongst the next credentials. admin / defectdojo@demo#appsec product_manager / defectdojo@demo#product Quick Start git clone https://github.com/DefectDojo/django-DefectDojo cd django-DefectDojo docker-compose up Navigate to http://localhost:8080 . Documentation For detailed documentation y'all tin view Read the Docs . Installation Options Kubernetes Docker Getting Started We recommend checking out the about document to acquire the terminology of DefectDojo in addition to the getting started guide for setting upward a novel installation. We...

Pacbot - Platform For Continuous Compliance Monitoring, Compliance Reporting In Addition To Safety Automation For The Cloud

Image
Policy every bit Code Bot (PacBot) is a platform for continuous compliance monitoring, compliance reporting as well as safety automation for the cloud. In PacBot, safety as well as compliance policies are implemented every bit code. All resources discovered past times PacBot are evaluated against these policies to justice policy conformance. The PacBot auto-fix framework provides the might to automatically reply to policy violations past times taking predefined actions. PacBot packs inwards powerful visualization features, giving a simplified persuasion of compliance as well as making it slow to analyze as well as remediate policy violations. PacBot is to a greater extent than than a tool to care cloud misconfiguration, it is a generic platform that tin ship away live used to practice continuous compliance monitoring as well as reporting for whatever domain. More Than Cloud Compliance Assessment PacBot's plugin-based information ingestion architecture allows ingesting in...