SECURITY RESOURCES

Black Hat minded security exploit development
What is Threat Modeling?

Threat Modeling

What is Threat Modeling?

A common question asked by people new to the specifics of cybersecurity. Threat modeling is a practical measure used to protect your business’ data and networks from cyber threats and attacks.

Read About Threat Modeling
What Is PASTA Threat Modeling? 7 Stages Explained for Modern Security

What Is PASTA Threat Modeling? 7 Stages Explained for Modern Security

PASTA is not a complicated static framework. It’s an agile methodology that breaks down and solves complex cybersecurity tasks, allows scaling, and evolves with the cybersecurity landscape and business goals.

Read About PASTA Threat Modeling
PASTA Threat Modeling for Integrated Risk Management

Cybersecurity Library, VerSprite Security Resources, Threat Modeling, Ebooks & Guides

PASTA Threat Modeling for Integrated Risk Management

PASTA is the Process for Attack Simulation & Threat Analysis and is a risk-centric threat modeling methodology aimed at identifying viable threat patterns against an application or system environment.

Download PASTA Threat Modeling eBook
Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

Attacking Your Assumptions: How Criminal Tactics Can Save Your Organization

In this article, VerSprite’s Offensive Security team explore the difference between common security risk assessments (vulnerability assessment, penetration testing, and red teaming) as we walk you through real exploits we have used to test organizations’ security protocols.

Read About Criminal Tactics

Category

View All
WD My Cloud Command Injection – Access All Private Folders
Cloud Security, VerSprite Security Resources, Videos

WD My Cloud Command Injection – Access All Private Folders

Command Injection in the WD My Cloud NAS
Application Security, Cloud Security, Information Security Management System (ISMS)

Command Injection in the WD My Cloud NAS

WD My Cloud Command Injection – Remote Root with WebRTC
Cloud Security, VerSprite Security Resources, Videos

WD My Cloud Command Injection – Remote Root with WebRTC

Anti-Nausea Medicine for LastPass, Password Management FUD
Application Security, Information Security Management System (ISMS), Regulatory Compliance, Security Governance

Anti-Nausea Medicine for LastPass, Password Management FUD

Why Threat-Free Threat Modeling Doesn’t Work
Application Security, Threat Modeling

Why Threat-Free Threat Modeling Doesn’t Work

Into the Jar | JSON Pickle Exploitation
Application Security, Security Research

Into the Jar | JSON Pickle Exploitation

Assessing Emerging JavaScript Platforms with Express.js and Node.js – What to Look For
Application Security, Information Security Management System (ISMS)

Assessing Emerging JavaScript Platforms with Express.js and Node.js – What to Look For

Android Titan SMS Trojan Analysis | Part One
Application Security, Mobile Security Testing, Security Research

Android Titan SMS Trojan Analysis | Part One

Security Metrics Rehab – Part One
Information Security Management System (ISMS), Security Governance

Security Metrics Rehab – Part One

Multiple Vulnerabilities in Mercury Browser for Android Version 2.2.2 & 3.0.0
Application Security, Mobile Security Testing, Security Research

Multiple Vulnerabilities in Mercury Browser for Android Version 2.2.2 & 3.0.0

Android InfoStealer – Godwon – Analysis
Application Security, Mobile Security Testing, Security Research

Android InfoStealer – Godwon – Analysis

Android Emulator Detection
Application Security, Mobile Security Testing, Security Research

Android Emulator Detection

Baidu Browser for Android Insecurely Handles the Intent Url Scheme
Application Security, Mobile Security Testing, Security Research

Baidu Browser for Android Insecurely Handles the Intent Url Scheme

PASTA Threat Modeling – One Day Training
Slides & Presentations, VerSprite Security Resources

PASTA Threat Modeling – One Day Training

The Truth About Chinese Hardware Implants
Threat & Vulnerability Management

The Truth About Chinese Hardware Implants

ci cd security, devsecops ci/cd, web app pen testing

Subscribe for Our
Updates

Please enter your email address and receive the latest updates