OSINT Funnel Methodology by @0SINTr
STAGE 1: Search Engines
STAGE 2: Specialized Tools
STAGE 3: Social Avenues
STAGE 4: Data Breaches
STAGE 5: Dark Web
Github repo with tips and tools for each stage:
https://t.co/HWHihiIXXe
#osint#socmint
What is DevSecOps?
DevSecOps emerged as a natural evolution of DevOps practices with a focus on integrating security into the software development and deployment process. The term "DevSecOps" represents the convergence of Development (Dev), Security (Sec), and Operations (Ops) practices, emphasizing the importance of security throughout the software development lifecycle.
The diagram below shows the important concepts in DevSecOps.
1 . Automated Security Checks
2 . Continuous Monitoring
3 . CI/CD Automation
4 . Infrastructure as Code (IaC)
5 . Container Security
6 . Secret Management
7 . Threat Modeling
8. Quality Assurance (QA) Integration
9 . Collaboration and Communication
10 . Vulnerability Management
–
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/FIzCeaWsZV
New section in APIs for #OSINT Github Repo - Reverse Image Search. There are various APIs out there that will help automate image search, uniqueness and copyright checks, etc.
https://t.co/3LZWDWm17D
#osint#socmint
The DFIR Report describes a threat actor toolkit from an open directory filled with batch scripts for defence evasion, executing command-and-control payloads, Ngrok for proxy services, SystemBC and two command-and-control frameworks: Sliver and PoshC2. https://t.co/8aLTNaieB3
OSINT without APIs
Article by @Intel471Inc about different #osint automation techniques:
Brute-Forcing
Port Scanning and Banner Grabbing
Web Spidering
Web Scraping
Working with DNS Zone Transfers/TXT records/WHOIS data
and more.
https://t.co/MgSmBefA6Y
Tip by @hakluke