SECURITY RESOURCES

Offensive minded security exploit development
What is Threat Modeling?

Threat Modeling

What is Threat Modeling?

A common question asked by people new to the specifics of cybersecurity. Threat modeling is a practical measure used to protect your business’ data and networks from cyber threats and attacks.

Read About Threat Modeling
A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

A Pasta Threat Modeling Solution for Complex Cybersecurity Tasks

PASTA is not a complicated static framework. It’s an agile methodology that breaks down and solves complex cybersecurity tasks, allows scaling, and evolves with the cybersecurity landscape and business goals.

Read About PASTA
The Process for Attack Simulation and Threat Analysis

Cybersecurity Library, Ebooks & Guides, Threat Modeling, VerSprite Security Resources

The Process for Attack Simulation and Threat Analysis

PASTA is the Process for Attack Simulation & Threat Analysis and is a risk-centric threat modeling methodology aimed at identifying viable threat patterns against an application or system environment.

Download eBook
Threat Modeling: A Comprehensive Guide

Threat Modeling: A Comprehensive Guide

In this model, you will see engineers, network professionals, developers, architects, business analysts, project managers, security champions, pentesters, and quality assurance engineers. Because they all have some level of involvement and collaboration at different stages of application, as well as organizational, threat modeling ensures effective results.

Learn About Threat Modeling
Using Risk-Based Threat Modeling to Protect Your Supply Chain

Cybersecurity Library, Ebooks & Guides, Supply Chains, VerSprite Security Resources

Using Risk-Based Threat Modeling to Protect Your Supply Chain

Why are supply chains a popular target for cybercriminals? VerSprite CEO, Tony UcedaVélez, introduces our risk-based threat modeling approach, PASTA, and how it allows organizations to better protect their supply chain software from threat actors.

Read About Risk-Based Threat Modeling
Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

In this article, VerSprite’s Offensive Security team explore the difference between common security risk assessments (vulnerability assessment, penetration testing, and red teaming) as we walk you through real exploits we have used to test organizations’ security protocols.

Read About Criminal Tactics

Category

View All
HIPAA with the Security Experts
Regulatory Compliance

HIPAA with the Security Experts

XXE – OWASP
Slides & Presentations, VerSprite Security Resources

XXE – OWASP

Cyber Criminals Target Employees with W-2 Phishing Scam
Application Security, Digital Forensics & Incident Response, Governance Risk & Compliance

Cyber Criminals Target Employees with W-2 Phishing Scam

Exploiting VyprVPN for MacOS
Security Research

Exploiting VyprVPN for MacOS

[Video] Abusing Insecure WCF Endpoints
VerSprite Security Resources, Videos

[Video] Abusing Insecure WCF Endpoints

Exploiting the Dolphin Browser for Android’s Backup & Restore Feature
Application Security, Mobile Security Testing, Security Research

Exploiting the Dolphin Browser for Android’s Backup & Restore Feature

Shellcoding an Arm64 In-Memory Reverse TCP Shell with Frida
Application Security, Mobile Security Testing, Security Research

Shellcoding an Arm64 In-Memory Reverse TCP Shell with Frida

Fixing Threat Models with OWASP Efforts
VerSprite Security Resources, Videos

Fixing Threat Models with OWASP Efforts

Swimming in the Deep End: Taking a Deeper Look at the Use Cases of JEA
Application Security, Governance Risk & Compliance

Swimming in the Deep End: Taking a Deeper Look at the Use Cases of JEA

Frida Engage Part One | Building an ELF Parser with Frida
Application Security, Mobile Security Testing, Security Research

Frida Engage Part One | Building an ELF Parser with Frida

Role of Zero Trust in Future Enterprise Security
VerSprite Security Resources, Webinars

Role of Zero Trust in Future Enterprise Security

Risk Centric Threat Models for Internet of Things (IoT) & Medical Devices
Application Security, Threat Modeling

Risk Centric Threat Models for Internet of Things (IoT) & Medical Devices

Why Threat Hunting Should Be Included in Your Mergers & Acquisitions Playbook
Digital Forensics & Incident Response

Why Threat Hunting Should Be Included in Your Mergers & Acquisitions Playbook

Adding and Using JEA in Your Windows Environment
Data Privacy & Development of Security Policies, Security Operations

Adding and Using JEA in Your Windows Environment

AppSec EU 2017: Modeling Threats for Applications
Threat Modeling, VerSprite Security Resources, Videos

AppSec EU 2017: Modeling Threats for Applications

ci cd security, devsecops ci/cd, web app pen testing

Subscribe for Our
Updates

Please enter your email address and receive the latest updates