@krutikvirani Or implement sector-wise VDPs not covered under nciipc if not bug bounty programs, handled by a proper security team or do internal vapt at regular intervals or check the third party service provider's security state, their vapt reports, who performed it and their patch history
Giving away 2x full access packages:
Linux Attack, Detection & Forensics v2.0 - Hands-on Purple Teaming Playbook + 90 days PurpleLabs VPN access
To enter:
✅ Follow me
❤️ Like this post
💬 Comment
🔁 Repost
Winners announced March 22nd 🎯
First time doing this, let's see how it goes 😄
https://t.co/SUktIBXgHt
#linux #redteam #blueteam #dfir
Giveaway - Our instructor-led advanced bootcamps for sharpening your Red Team skills start this weekend.
Attacking and Defending Active Directory - Advanced Edition (CRTE) starts this Friday.
Advanced Windows Tradecraft - Evasion Techniques for Red Teams (CETP) starts this Saturday.
I am giving away one seat for each of the bootcamps. To participate, please Follow @nikhil_mitt and @AlteredSecurity, Like, Comment and Repost.
We will announce the random winners on Wednesday.
https://t.co/Kd0RNoINWc
#RedTeam #Evasion
@Officialwhyte22 B is most likely. But most organisations consider it as a normal behaviour due to no or low real world impact, to the extent that it is not vulnerable to other attacks like sqli etc. For example wordpress username enumeration.
@coffinxp7@legen_eth@Snowden@NahoXSS Does it mean that one can know whether an account is being used or loggedin by looking at region info. even though there is no post/tweet interactions?