SCFI.pdf
734 KB
#Research
#hardening
"SCFI: State Machine Control-Flow Hardening Against Fault Attacks", 2022.
Fault injection (FI) is a powerful attack methodology allowing an adversary to entirely break the security of a target device. As finite state machines (FSMs) are fundamental hardware building blocks responsible for controlling systems, inducing faults into these con trollers enables an adversary to hijack the execution of the inte grated circuit. A common defense strategy mitigating these attacks is to manually instantiate FSMs multiple times and detect faults using a majority voting logic.
📚
#hardening
"SCFI: State Machine Control-Flow Hardening Against Fault Attacks", 2022.
Fault injection (FI) is a powerful attack methodology allowing an adversary to entirely break the security of a target device. As finite state machines (FSMs) are fundamental hardware building blocks responsible for controlling systems, inducing faults into these con trollers enables an adversary to hijack the execution of the inte grated circuit. A common defense strategy mitigating these attacks is to manually instantiate FSMs multiple times and detect faults using a majority voting logic.
📚
8_ways_compromise_ADFS.pdf
1.8 MB
#hardening
#Cloud_Security
"Eight ways to compromise AD FS certificates", 2022.
]-> Best practices for securing Active Directory Federation Services:
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs#enable-protection-to-prevent-by-passing-of-cloud-azure-ad-multi-factor-authentication-when-federated-with-azure-ad
📰
📚
#Cloud_Security
"Eight ways to compromise AD FS certificates", 2022.
]-> Best practices for securing Active Directory Federation Services:
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs#enable-protection-to-prevent-by-passing-of-cloud-azure-ad-multi-factor-authentication-when-federated-with-azure-ad
📰
📚
10_Ways_to_Improve_AD_Security.pdf
3.1 MB
#hardening
#Blue_Team
"Top 10 Ways to Improve Active Directory Security Quickly", 2022.
]-> https://www.hub.trimarcsecurity.com/post/webcast-top-10-ways-to-improve-active-directory-security-quickly
📰
📚
#Blue_Team
"Top 10 Ways to Improve Active Directory Security Quickly", 2022.
]-> https://www.hub.trimarcsecurity.com/post/webcast-top-10-ways-to-improve-active-directory-security-quickly
📰
📚
email_auth_best_practices.pdf
284.7 KB
#hardening
#exploit
Email Authentication Recommended Best Practices (.pdf) + The Gmail SMTP Relay Service Exploit:
https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit
📚
#exploit
Email Authentication Recommended Best Practices (.pdf) + The Gmail SMTP Relay Service Exploit:
https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit
📚
junos_ddos_guide.pdf
1.8 MB
#hardening
#Whitepaper
"Junos OS Attack Detection and Prevention User Guide for Security Devices", 2021.
#Whitepaper
"Junos OS Attack Detection and Prevention User Guide for Security Devices", 2021.
Win10_Hardening_Guide.pdf
505.8 KB
#hardening
"Configuration Recommendations for Hardening of Windows 10 Using Built-in Functionalities", 2021.
]-> https://www.bsi.bund.de/EN/Topics/Cyber-Security/Recommendations/SiSyPHuS_Win10/AP11/SiSyPHuS_AP11_node.html
t.iss.one/Library_Sec
"Configuration Recommendations for Hardening of Windows 10 Using Built-in Functionalities", 2021.
]-> https://www.bsi.bund.de/EN/Topics/Cyber-Security/Recommendations/SiSyPHuS_Win10/AP11/SiSyPHuS_AP11_node.html
t.iss.one/Library_Sec