DumpsterFire
Notes
DumpsterFire | Notes | |
---|---|---|
3 | 12 | |
970 | 1,539 | |
- | - | |
0.0 | 2.3 | |
almost 4 years ago | 4 months ago | |
Python | ||
MIT License | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
DumpsterFire
-
If you could name 5 tools/software worth learning for a cybersecurity analyst to become more employable, what would they be?
https://github.com/TryCatchHCF/DumpsterFire The DumpsterFire Toolset is a modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events. Easily create custom event chains for Blue Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Turn paper tabletop exercises into controlled "live fire" range events. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
- How to keep a SOC on their toes
- How do you improve your blue team skills?
Notes
-
SWE vs. Cybersecurity
https://github.com/gracenolan/Notes/blob/master/interview-study-notes-for-security-engineering.md i think this is a good general list of topics - there are many subfields within it but for appsec or product security dm me i got tons of links. The other fields idk but they are always a lot of people hired for Cloud Infra/IAM/PKI type roles
-
Finally made it(Google) - now people will know what my job is
Basically this https://www.youtube.com/watch?v=GM9yGj5tdHc but way longer and with a slightly more complex coding question similar to something you would need to solve irl. This guide is a little more detailed for intern but accurate for what to expect for full time interviews https://github.com/gracenolan/Notes/blob/master/interview-study-notes-for-security-engineering.md
-
Landing a job in California, moving from Italy
I suppose it depends on the role as some might be more code oriented than other roles. Check this out by Nolan, interview notes on Google Security Engineering. It could have something valuable for you.
- Security Engineer interview - google
-
Technical Interview pointers
Ps: some technical questions to test if you are ready or not - github
- Advice on new career path (Cyber security professionals' opinion would be welcome) and a Cyber security training package being offered to me
- Security Engineer Interview Prep for FAANG?
-
If you could name 5 tools/software worth learning for a cybersecurity analyst to become more employable, what would they be?
For government: Python, Splunk, Nessus, McAfee, know your current events in the cyber landscape.For modern world: https://github.com/gracenolan/Notes/blob/master/interview-study-notes-for-security-engineering.md
- PSA you don't need to do leetcode to work at FAANG. if you learn specialized skills specialized swe roles still pay the same but without requiring leetcode(i.e. security, sre, some OS teams)
- Security Engineering at Google: Interview Study Notes
What are some alternatives?
hacktricks - Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
APTSimulator - A toolset to make a system look as if it was the victim of an APT attack
CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera - 🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337
atomic-red-team - Small and highly portable detection tests based on MITRE's ATT&CK.
evillimiter-windows - Tool that limits bandwidth of devices on the same network without access.
reconmap - Vulnerability assessment and penetration testing automation and reporting platform for teams.
Kali-Linux-Tools-Interface - Graphical Web interface developed to facilitate the use of security information tools.
AlanFramework - A C2 post-exploitation framework
JSshell - JSshell - JavaScript reverse/remote shell
MIXON - Next generation cyber security research and testing software.
cpanel-pass-reset - An easy tool to reset cpanel password when you can't upload backdoor to server. This tool will be useful only if the password reset feature on cpanel is activated.