Information gathering

Where do I get my information?

Podcasts

  • Risky Business, Patrick Gray, https://podcasts.google.com/?feed=aHR0cHM6Ly9yaXNreS5iaXovcnNzLnhtbA&ep=14
  • Blueprint, John Hubbard, https://podcasts.google.com/?feed=aHR0cHM6Ly9mZWVkcy5idXp6c3Byb3V0LmNvbS8xMTQyNzIwLnJzcw&ep=14
  • Defense In Depth, Allan Alford & David Spark, https://podcasts.google.com/?feed=aHR0cHM6Ly9kZWZlbnNlaW5kZXB0aC5saWJzeW4uY29tL3Jzcw&ep=14

Newsletters

  • Integriti
  • TL/DR sec
  • Daniel Miessler
  • Risky.biz

Twitter

InfoSec List

PingCastle

‘Get 80 percent of your Active Directory audited in 20 percent of your time!’ That’s the catch phrase of this invaluable tool.

It is a joy to use and you’ll get instant, actionable results. A must have for everyone that takes the security of it’s AD seriously.

Developed by the guy that contributed to Mimikatz, Vincent Le Toux.

Https://www.pingcastle.com

Make sure you go and check their site every now and then, they may add new functionalities in the newer version.

Disabling Credential Guard

The Windows feature credential guard can be a great way to tackle the stealing of credentials out of memory, but if you want to run VMs on your Windows 10 machine, it can also be a pain in the ass…

When you get the error “VMware Workstation and Device/Credential Guard are not compatible” and you’ve tried everything outlined here and still your precious Kali VM won’t start.
You also notice that in MSinfo.exe, under System Summary the Virtualization-based security keeps saying: ‘enabled’.

Try this: go to the “Turn features on or off” application -> uncheck “Windows Defender Application Guard“. Reboot pc.
You’re welcome!

BHIS – GPO’s that kill Kill Chains

The guys (and girls) from BHIS have put together an excellent list of GPO’s that every company that takes Information security serious, should apply. Have a look here:
https://www.blackhillsinfosec.com/webcast-group-policies-that-kill-kill-chains/

“What’s a ‘kill chain’ again?”, I hear you asking. I’ve got that covered too 🙂
https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html