프로젝트 소개
이 프로젝트는 Red Team의 다음 측면들을 수집하고 정리하는 데 사용됩니다.
-
Red Team 공격 사고방식
-
Red Team 공격 도구
-
Red Team 공격 방법
핵심 콘텐츠
공격·방어 테스트
시리즈 콘텐츠
기초 보안
- https://book.yunzhan365.com/umta/rtnp/mobile/index.html 사이버 보안 대중화 소책자
- http://sec.cuc.edu.cn/huangwei/textbook/ns/ 사이버 보안 전자 교재. CUC(중국전매대학) 정보보안 강좌 웹사이트
- https://mitre.github.io/attack-navigator/enterprise/ mitre 기관 att&ck 침입 탐지 항목
- https://github.com/danielmiessler/SecLists 테이블 유형에는 사용자 이름, 비밀번호, URL, 민감 데이터 패턴, 퍼징 페이로드, Web shell 등이 포함됨
- https://github.com/GitGuardian/APISecurityBestPractices api 인터페이스 테스트 checklist
- https://github.com/ym2011/SecurityManagement 보안 관리 체계 구축, ISO27001, 등급 보호(等级保护), 보안 심사 과정의 세세한 경험을 공유
- https://mp.weixin.qq.com/s/O36e0gl4cs0ErQPsb5L68Q 블록체인, 이더리움 스마트 컨트랙트 감사 CheckList
- https://github.com/slowmist/eos-bp-nodes-security-checklist 블록체인, EOS bp nodes security checklist(EOS 슈퍼노드 보안 실행 가이드)
- https://xz.aliyun.com/t/2089 핀테크 SDL 보안 설계 checklist
- https://github.com/juliocesarfort/public-pentesting-reports 여러 컨설팅 회사와 학술 보안 기관이 발표한 공개 침투 테스트 보고서 목록.
- http://www.freebuf.com/articles/network/169632.html 오픈소스 소프트웨어로 SOC를 구축하기 위한 체크리스트
- https://github.com/0xRadi/OWASP-Web-Checklist owasp 웹사이트 점검 항목
- https://www.securitypaper.org/ SDL 개발 보안 수명주기 관리
- https://github.com/Jsitech/JShielder linux 서버 원클릭 보안 강화 스크립트
- https://github.com/wstart/DB_BaseLine 데이터베이스 베이스라인 점검 도구
학습 매뉴얼
학습 랩