SECURITY RESOURCES

Offensive minded security exploit development
What is Threat Modeling?

Threat Modeling

What is Threat Modeling?

A common question asked by people new to the specifics of cybersecurity. Threat modeling is a practical measure used to protect your business’ data and networks from cyber threats and attacks.

Read More
A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

PASTA is not a complicated static framework. It’s an agile methodology that breaks down and solves complex cybersecurity tasks, allows scaling, and evolves with the cybersecurity landscape and business goals.

Read More
The Process for Attack Simulation and Threat Analysis

Cybersecurity Library, Ebooks & Guides, Threat Modeling, VerSprite Security Resources

The Process for Attack Simulation and Threat Analysis

PASTA is the Process for Attack Simulation & Threat Analysis and is a risk-centric threat modeling methodology aimed at identifying viable threat patterns against an application or system environment.

Download eBook
Threat Modeling: A Comprehensive Guide

Threat Modeling: A Comprehensive Guide

In this model, you will see engineers, network professionals, developers, architects, business analysts, project managers, security champions, pentesters, and quality assurance engineers. Because they all have some level of involvement and collaboration at different stages of application, as well as organizational, threat modeling ensures effective results.

Read More
Using Risk-Based Threat Modeling to Protect Your Supply Chain

Cybersecurity Library, Ebooks & Guides, Supply Chains, VerSprite Security Resources

Using Risk-Based Threat Modeling to Protect Your Supply Chain

Why are supply chains a popular target for cybercriminals? VerSprite CEO, Tony UcedaVélez, introduces our risk-based threat modeling approach, PASTA, and how it allows organizations to better protect their supply chain software from threat actors.

Read More
Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

In this article, VerSprite’s Offensive Security team explore the difference between common security risk assessments (vulnerability assessment, penetration testing, and red teaming) as we walk you through real exploits we have used to test organizations’ security protocols.

Read More

Category

View All
Part II: Analysis of a Vulnerable Microsoft Windows Named Pipe Application
Security Research

Part II: Analysis of a Vulnerable Microsoft Windows Named Pipe Application

Phishing Attacks Through Cloned Websites
Application Security

Phishing Attacks Through Cloned Websites

Google Cloud Platform: Identity and Access Management, Network Security, and Data Loss Protection
Security Operations

Google Cloud Platform: Identity and Access Management, Network Security, and Data Loss Protection

Part I: The Fundamentals of Windows Named Pipes
Security Research

Part I: The Fundamentals of Windows Named Pipes

Leveraging PASTA Threat Modeling for Strategic Security Operations Management & Exploit Testing
Threat Modeling, VerSprite Security Resources, Webinars

Leveraging PASTA Threat Modeling for Strategic Security Operations Management & Exploit Testing

Geopolitical Cyber Threats and Business Operations
Geopolitical Risk, VerSprite Security Resources

Geopolitical Cyber Threats and Business Operations

Analyzing CVE-2019-1436 on Windows 10 v1903
Security Research

Analyzing CVE-2019-1436 on Windows 10 v1903

Secure Your Website: Simple HTTPS with Nginx
Application Security

Secure Your Website: Simple HTTPS with Nginx

Geopolitical Risk Webinar: The Top Geo-Cyber Supply Chain Risks & Opportunities
Geopolitical Risk, Reports, VerSprite Security Resources, Webinars

Geopolitical Risk Webinar: The Top Geo-Cyber Supply Chain Risks & Opportunities

Utilizing Reverse Proxies to Inject Malicious Code & Extract Sensitive Information
Application Security, Security Research

Utilizing Reverse Proxies to Inject Malicious Code & Extract Sensitive Information

5 Techniques to Avoid Unwanted Outcomes with Cloud Security Scanner
Cloud Security, Security Operations

5 Techniques to Avoid Unwanted Outcomes with Cloud Security Scanner

How to Configure Google Cloud Armor as a Multi-Layer Firewall
Cloud Security, Security Operations

How to Configure Google Cloud Armor as a Multi-Layer Firewall

Attacking LastPass: Compromising an Entire Password Database
Application Security, Data Privacy & Development of Security Policies

Attacking LastPass: Compromising an Entire Password Database

5 Key Features of Google Stackdriver
Managed Security, Security Operations

5 Key Features of Google Stackdriver

How to Minimize Data Risk & Strengthen Your Security Posture
Cybersecurity Library, Ebooks & Guides, VerSprite Security Resources

How to Minimize Data Risk & Strengthen Your Security Posture

ci cd security, devsecops ci/cd, web app penetration testing

Subscribe for Our
Updates

Please enter your email address and receive the latest updates