Previous Posts
InfoSec Best Practice - An Unhelpful Term
A short piece about the term “Information Security best practice, and how it’s harming our industry.
A rant about running vulnerability management programmes that work.
Vulnerability Management in 4 Stages
A rant about running vulnerability management programmes that work.
Information Security Risk Management - Benefits & Common Pitfalls
How Information Security Risk Management can practically and significantly improve the security posture of your organisation.
Planned Posts
Title | Description |
---|---|
Microservice architecture isn’t a panacea | A pragmatic look at the pros and cons of different architectural patterns |
Malware Analysis Intro | My first impressions of getting into malware analysis and reverse engineering |
Helpful Resources
- Virus Exchange Underground, the largest collection of malware source code, samples, and papers on the internet.
- A great and exhaustive list of all things infosec. have an explore and find some treasure.
Awesome Security News Letters - Github list
- A good list of security newsletters. Some better than others. Personally, I really like Ollie Whitehouse’s ‘Bluepurple Pulse’, Clint Gibler’s ‘tl;dr sec’ newsletter and Zack Whittaker’s ‘This Week in Security’.
Awesome Cloud Security - Github list
- A good list of resources related to all things Cloud Security.
Alien Vault - Open Threat Exchange (OTX)
- An open source threat intelligence feed and threat data platform that allows security researchers to investigate new threats.
OpenVAS - Open Vulnerability Assessment Scanner
- An free & full-featured network, system/server and application vulnerability scanner.
- An open-source phishing framework that makes it easy to test your organization’s exposure to phishing.
- Snyk is a developer friendly tool that tests for vulnerabilities in code, open source dependencies, container images and infrastructure as code configurations.
SANS Information Security Policy Project
- A repository of very useful policy templates.
Publicly Available ISO Standards
- A repository of free ISO standards to download.
Secure Control Framework’s List of Security Domains
- A repository of InfoSec Domains including information about each.