sábado, 15 de octubre de 2022

Security Operation Center Trainings

Splunk Courses (FREE)
https://lnkd.in/d_dZNduf
Fortinet Courses (FREE)
https://lnkd.in/dmmkZ-tH

AttackIQ Mitre Att&ck Courses (FREE)
https://lnkd.in/dcfmSPEJ
Microsoft SC-200 Course (FREE)
https://lnkd.in/dbCn3k4n
Awesome OSINT Courses (FREE)
https://lnkd.in/dTCaCf-u

CSILinux Forensic Trainings (FREE)
https://lnkd.in/dhjwx_5h

Cybrary Trainings (FREE)
https://cybrary.it

Introduccion a ThreatHunting Parte 1

 Threat Hunting Introduction PT 1.pdf - Google Drive - Joas Antonio

The best talks about PenTest and Red Team

Kevin Mitnick + Dave Kennedy -- Adaptive Penetration Testing

DEF CON 23 - Social Engineering Village - Dave Kennedy - Understanding End-User Attacks

DEF CON 18 - Barnaby Jack - Jackpotting Automated Teller Machines Redux

DEF CON 23 - Charlie Miller & Chris Valasek - Remote Exploitation of an Unaltered Passenger Vehicle

AVPASS: Leaking and Bypassing Antivirus Detection Model Automatically

DEF CON Safe Mode Red Team Village - Jorge Orchilles - Deep Dive into Adversary Emulation Ransomware

Discovering C&C in Malicious PDFs with obfuscation, encoding, and other techniques by Filipi Pires

DEF CON 26 - Rob Joyce - NSA Talks Cybersecurity

Evading Microsoft ATA for Active Directory Domination

Black Hat 2013 - Exploiting Network Surveillance Cameras Like a Hollywood Hacker

DEF CON 23 - Marc Rogers and Kevin Mahaffey - How to Hack a Tesla Model S

Daniel Bohannon – Invoke-Obfuscation: PowerShell obFUsk8tion

DEF CON 23 - Chris Domas - Repsych: Psychological Warfare in Reverse Engineering

OSCP 2021 to 2022 (Offensive Security Certified Professional) Pass and Preparation - Active Directory

Links:

Recursos para practicar PenTesting

No todos los sitios son gratuitos!!

HackTheBox

TryHackMe

Hack This Site

Cybrary

EchoCTF

Ethical Hacking in 12 Hours - Full Course - Learn to Hack!

Hack Yourself First

OWASP Juice Shop

PortSwigger Web Security Academy

Game Of Hacks

VulnHub

INE

HackerTest

Beginner Web Application Hacking (Full Course)

PentesterLab

Defend The Web

Hackxor

Full Ethical Hacking Course - Network Penetration Testing for Beginners (2019)

Google Gruyere

Linux for Ethical Hackers (2022 - Full Kali Linux Course)

OverTheWire

Que es un ataque de diccionario?

 What is a Dictionary Attack? How the Attack works and How to Prevent the Dictionary Attack

miércoles, 12 de octubre de 2022

Algunos recursos para aprender Wireshark

Wireshark es un software gratuito para capturar y analizar tráfico, esta es una habilidad invaluable en el ambiente de redes y cibersegurdiad! 

CompTIA Guide to Wireshark:
https://lnkd.in/eT2sfxjB

LetsDefend “Malware Traffic Analysis with Wireshark”:
https://lnkd.in/esNfk24X

Deep Dive Into Wireshark (YouTube Playlist)
https://lnkd.in/eFjW8pvH

Wireshark Tutorial - David Bombal (YouTube Video)
https://lnkd.in/eP-xMsSt

domingo, 9 de octubre de 2022

Recursos gratuitos para aprender seguridad de APIs

1. Traceable AI, API Hacking 101

2. Video: Katie Paxton-Fear, API Hacking

3. Video: Bugcrowd, Bad API, hAPI Hackers

4. Video: OWASP API Security Top 10 Webinar

5. Blog: Detectify, How To Hack API's in 2021

6. Blog: HackXpert, Let's build an API to hack

7. Video: Bugcrowd, API Security 101 by Sadako

8. Video: David Bombal, Free API Hacking Course

9. Blog: Wallarm, How To Hack API In 60 Minutes

10. Website: APIsecurity IO, API Security Articles

11. Blog: Curity, The API Security Maturity Model

12. Blog: Expedited Security, API Security MegaGuide

13. Video: Grant Ongers, API Security Testing Workshop

14. Blog: APIsec OWASP API Security Top 10: A Deep Dive

15. Podcast: We Hack Purple, API Security Best Practices

16. Blog: Kontra Application Security, Owasp Top 10 for API

17. Blog: Secure Delivery, OWASP API Top 10 CTF Walk-through

18. Blog: SmartBear, How To Hack An API And Get Away With It

19. Blog: Ping Identity, API Security: The Complete Guide 2022

20. Blog: Bend Theory, Finding and Exploiting Unintended Functionality in Main Web App APIs

21. Blog: Bright Security, Complete Guide to Threats, Methods & Tools

sábado, 8 de octubre de 2022

Lista de Websites para escanear dominios o IPs

1. GreyNoise https://www.greynoise.io/

2. VirusTotal https://www.virustotal.com/gui/home/search

3. Whois https://www.whois.com/whois

4. AbuseIPDB https://www.abuseipdb.com/

5. IpAddress https://www.ipaddress.com/search/

6. ARIN https://search.arin.net/

7. Censys https://search.censys.io/

8. Intelligence X https://intelx.io/

9. Shodan https://www.shodan.io/

10. ZoomEye https://www.zoomeye.org/discover

11. ONYPHYE https://www.onyphe.io/

12. What is My IP https://whatismyip.live/ip-lookup

13. BinaryEdge https://docs.binaryedge.io/search/

14. URL Scan https://urlscan.io/search/#*

15. Abuse CH https://abuse.ch/#platforms

Nuevos Cursos Gratuitos

 Aqui les dejo unos cuantos recursos gratuitos:

1. SANS Cyberaces Training

2. COMPTIA (networking, cloud and cyber)

3. Cybrary IT

4. Cybersecurity Basics

5. Fortinet Information Security Awareness

Recursos para aprender Python

 Aqui les dejo algunos recursos para aprender Python:

1. Google Python Course

2. Microsoft's Introduction to Python Course

3. Introduction to Python Programming on Udemy

4. Python 13 YouTube Videos

5. NetworkChuck YouTube Python Course

6. Learn Python 3 for Total Beginners on Udemy

7. Learn Python - Full Course for Beginners by freeCodeCamp

8. LearnPython free course

9. Learn Python with Programming with Mosh

Aqui pueden ver 2 clases completas de TCM Security Academy

1. Ethical Hacking in 12 Hours - Full Course - Learn to Hack!

2. Open-Source Intelligence (OSINT) in 5 Hours - Full Course - Learn OSINT!

Bienvenidos!

Hola a todos! Gracias por tomarse el tiempo de visitar mi Blog. Aqui tratare de publicar cosas relevantes del tema de Ciberseguridad.

CISSP FREE Full Courses with Certificates

 CISSP: Introduction to Information Security https://www.simplilearn.com/introduction-to-information-security-basics-skillup?tag=CISSP Intro...