SECURITY RESOURCES

Offensive minded security exploit development
What is Threat Modeling?

Threat Modeling

What is Threat Modeling?

A common question asked by people new to the specifics of cybersecurity. Threat modeling is a practical measure used to protect your business’ data and networks from cyber threats and attacks.

Read More
A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

PASTA is not a complicated static framework. It’s an agile methodology that breaks down and solves complex cybersecurity tasks, allows scaling, and evolves with the cybersecurity landscape and business goals.

Read More
The Process for Attack Simulation and Threat Analysis

Cybersecurity Library, Ebooks & Guides, Threat Modeling, VerSprite Security Resources

The Process for Attack Simulation and Threat Analysis

PASTA is the Process for Attack Simulation & Threat Analysis and is a risk-centric threat modeling methodology aimed at identifying viable threat patterns against an application or system environment.

Download eBook
Threat Modeling: A Comprehensive Guide

Threat Modeling: A Comprehensive Guide

In this model, you will see engineers, network professionals, developers, architects, business analysts, project managers, security champions, pentesters, and quality assurance engineers. Because they all have some level of involvement and collaboration at different stages of application, as well as organizational, threat modeling ensures effective results.

Read More
Using Risk-Based Threat Modeling to Protect Your Supply Chain

Cybersecurity Library, Ebooks & Guides, Supply Chains, VerSprite Security Resources

Using Risk-Based Threat Modeling to Protect Your Supply Chain

Why are supply chains a popular target for cybercriminals? VerSprite CEO, Tony UcedaVélez, introduces our risk-based threat modeling approach, PASTA, and how it allows organizations to better protect their supply chain software from threat actors.

Read More
Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

In this article, VerSprite’s Offensive Security team explore the difference between common security risk assessments (vulnerability assessment, penetration testing, and red teaming) as we walk you through real exploits we have used to test organizations’ security protocols.

Read More

Category

View All
10 Data Privacy Tips: Wellness Industry & Growing Data Concerns
Governance Risk & Compliance, Integrated Risk Management (IRM)

10 Data Privacy Tips: Wellness Industry & Growing Data Concerns

5 Fundamental Data Privacy Rights
Data Privacy & Development of Security Policies, Governance Risk & Compliance

5 Fundamental Data Privacy Rights

ATL Channel 2 News Interviews VerSprite CEO on Security Gaps Found in DeKalb Data Center
In The News, VerSprite Security Resources, Videos

ATL Channel 2 News Interviews VerSprite CEO on Security Gaps Found in DeKalb Data Center

Why an Increasing Number of Clients Are Migrating to Microsoft Azure
Cloud Security, Security Operations

Why an Increasing Number of Clients Are Migrating to Microsoft Azure

Threat Models – Offensive Security & Defensive
VerSprite Security Resources

Threat Models – Offensive Security & Defensive

Waves Maxx Audio DLL Side-Loading LPE via Windows Registry
Application Security, Security Research

Waves Maxx Audio DLL Side-Loading LPE via Windows Registry

Microsoft Windows Remote Code Execution (RCE) Vulnerability: BlueKeep
Threat & Vulnerability Management

Microsoft Windows Remote Code Execution (RCE) Vulnerability: BlueKeep

Microsoft Outlook for Android Vulnerable to Cross-Site Scripting
Threat & Vulnerability Management

Microsoft Outlook for Android Vulnerable to Cross-Site Scripting

Mozilla Firefox Patches Multiple Zero Days
Application Security, Threat & Vulnerability Management

Mozilla Firefox Patches Multiple Zero Days

OH The POSsibilities: Point of Sale System Security
Application Security, Security Research

OH The POSsibilities: Point of Sale System Security

The General Data Protection Regulation (GDPR): A Quick Guide for Organizations
Data Privacy & Development of Security Policies, Governance Risk & Compliance, Regulatory Compliance

The General Data Protection Regulation (GDPR): A Quick Guide for Organizations

Digging up the Past: OS X File Versioning
Digital Forensics & Incident Response, Security Research

Digging up the Past: OS X File Versioning

Why Healthcare is an Attractive Target for Malicious Actors
Data Privacy & Development of Security Policies, Integrated Risk Management (IRM), Regulatory Compliance

Why Healthcare is an Attractive Target for Malicious Actors

Attacking Weakly-Configured EAP-TLS Wireless Infrastructures
Application Security, Information Security Management System (ISMS)

Attacking Weakly-Configured EAP-TLS Wireless Infrastructures

Growing Intersection of Geopolitics and Cybersecurity
Integrated Risk Management (IRM)

Growing Intersection of Geopolitics and Cybersecurity

ci cd security, devsecops ci/cd, web app penetration testing

Subscribe for Our
Updates

Please enter your email address and receive the latest updates