SECURITY RESOURCES

Offensive minded security exploit development
What is Threat Modeling?

Threat Modeling

What is Threat Modeling?

A common question asked by people new to the specifics of cybersecurity. Threat modeling is a practical measure used to protect your business’ data and networks from cyber threats and attacks.

Read More
A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

PASTA is not a complicated static framework. It’s an agile methodology that breaks down and solves complex cybersecurity tasks, allows scaling, and evolves with the cybersecurity landscape and business goals.

Read More
The Process for Attack Simulation and Threat Analysis

Cybersecurity Library, Ebooks & Guides, Threat Modeling, VerSprite Security Resources

The Process for Attack Simulation and Threat Analysis

PASTA is the Process for Attack Simulation & Threat Analysis and is a risk-centric threat modeling methodology aimed at identifying viable threat patterns against an application or system environment.

Download eBook
Threat Modeling: A Comprehensive Guide

Threat Modeling: A Comprehensive Guide

In this model, you will see engineers, network professionals, developers, architects, business analysts, project managers, security champions, pentesters, and quality assurance engineers. Because they all have some level of involvement and collaboration at different stages of application, as well as organizational, threat modeling ensures effective results.

Read More
Using Risk-Based Threat Modeling to Protect Your Supply Chain

Cybersecurity Library, Ebooks & Guides, Supply Chains, VerSprite Security Resources

Using Risk-Based Threat Modeling to Protect Your Supply Chain

Why are supply chains a popular target for cybercriminals? VerSprite CEO, Tony UcedaVélez, introduces our risk-based threat modeling approach, PASTA, and how it allows organizations to better protect their supply chain software from threat actors.

Read More
Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

In this article, VerSprite’s Offensive Security team explore the difference between common security risk assessments (vulnerability assessment, penetration testing, and red teaming) as we walk you through real exploits we have used to test organizations’ security protocols.

Read More

Category

View All
Risk-Based Security Threat Modeling: 7-Step Process for Risk Analysis
Security Testing, Threat Modeling, VerSprite Security Resources

Risk-Based Security Threat Modeling: 7-Step Process for Risk Analysis

Organizational Threat Modeling Steps: A Blueprint for Threat Intelligence
Threat Intelligence, Threat Modeling

Organizational Threat Modeling Steps: A Blueprint for Threat Intelligence

Penetration Testing Methodology: Emulating Realistic Attacks by a Malicious Actor
Application Security, Threat Modeling

Penetration Testing Methodology: Emulating Realistic Attacks by a Malicious Actor

How to Approach Integrating Application Security into Your Software Development Lifecycle
Application Security, Security Operations

How to Approach Integrating Application Security into Your Software Development Lifecycle

NordVPN’s Strategic Cybersecurity Partnership with VerSprite
Penetration Testing

NordVPN’s Strategic Cybersecurity Partnership with VerSprite

Reversing Stories: Updating the Undocumented ESTROBJ and STROBJ Structures for Windows 10 x64
Security Research

Reversing Stories: Updating the Undocumented ESTROBJ and STROBJ Structures for Windows 10 x64

Investigating Microsoft Windows Vulnerability CVE-2019-1169
Security Research

Investigating Microsoft Windows Vulnerability CVE-2019-1169

Automating CVE-2019-1436 Variant Analysis: An Intro to Detecting Information Leaks via IDAPython
Security Research

Automating CVE-2019-1436 Variant Analysis: An Intro to Detecting Information Leaks via IDAPython

How Secure Are Your Universally Unique IDentifiers (UUIDs)?
Application Security, Penetration Testing

How Secure Are Your Universally Unique IDentifiers (UUIDs)?

US-Iran Conflict: Increased Geopolitical Risk From Cyber Attacks Based Out of Iran
Integrated Risk Management (IRM)

US-Iran Conflict: Increased Geopolitical Risk From Cyber Attacks Based Out of Iran

Offensive Threat Models Against the Supply Chain
Slides & Presentations, Threat Modeling, VerSprite Security Resources

Offensive Threat Models Against the Supply Chain

Wellness Industry: 10 Ways Data Privacy Can Increase Your Competitive Edge
Cybersecurity Library, Ebooks & Guides, Geopolitical Risk, VerSprite Security Resources

Wellness Industry: 10 Ways Data Privacy Can Increase Your Competitive Edge

Utilizing STIX to Foreshadow Cyber Security Risks
Integrated Risk Management (IRM)

Utilizing STIX to Foreshadow Cyber Security Risks

The Process for Attack Simulation and Threat Analysis
Cybersecurity Library, Ebooks & Guides, Threat Modeling, VerSprite Security Resources

The Process for Attack Simulation and Threat Analysis

Vendor Risk: Product vs. Custom Managed Services
Cybersecurity Library, Ebooks & Guides, VerSprite Security Resources

Vendor Risk: Product vs. Custom Managed Services

ci cd security, devsecops ci/cd, web app penetration testing

Subscribe for Our
Updates

Please enter your email address and receive the latest updates