Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
internal-security-detect — 기업 내부 보안 통제 탐지 | Kitploit
도구/GitHubGitHub/rxerium/internal-security-detect
Defensive ToolsOSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersConfiguration AuditingInformation GatheringWeb SecurityRed Teaming
GitHubrxerium/internal-security-detect

internal-security-detect

기업 내부 보안 통제 탐지

저장소 보기
27개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

내부 보안 탐지 (SafeBase 활용)

노출된 SafeBase 포털은 동시에 두 부류의 사용자를 대상으로 합니다: 보안 태세에 대한 증명이 필요한 잠재 고객과 보안 연구자(블루 팀 및 레드 팀)입니다. 각 녹색 체크 표시는 (아마도) 현재 존재하는 통제 항목을 나타내며, 누락된 체크 표시는 존재하지 않는 항목에 대한 똑같이 명확한 힌트가 됩니다.

이 데이터를 수집하는 이유는?

ISO 27001, SOC 2, PCI-DSS와 같은 규정 준수 프레임워크와 각 지역에서 증가하는 개인정보 보호 규정은 보안 통제가 마련되어 제대로 작동하고 있다는 "증거"를 요구합니다. SafeBase는 증명이나 문서를 위한 끝없는 이메일 교환 없이 이를 제공할 수 있는 편리한 방법을 제공합니다.

직접 만든 공개 트러스트 센터를 스크래핑하는 것은 불필요해 보일 수 있지만, 그렇게 해야 할 충분한 다른 이유가 있습니다:

  1. 지속적 보증(Continuous assurance) – 감사자들은 점점 더 지속적인 증거를 선호합니다.
  2. 변경 탐지 – 플랫폼 업데이트나 인수·합병 이후 정책 제목, 그룹, 통제 항목 이름까지 변경될 수 있습니다. 자동화된 스크래핑은 고객이 알아차리기 전에 이러한 변경 사항을 감지할 수 있습니다.
  3. 타사 매핑 – 목록을 JSON으로 변환하면 통제 라이브러리(예: NIST 800-53)와 상호 참조하여 적용 범위를 자동으로 증명할 수 있습니다.
  4. 보안 평가 – 블루 팀의 경우 공개된 주장이 정확하게 유지되도록 보장하며, 레드 팀의 경우 자체 통제 라이브러리와의 빠른 비교를 통해 "약점"을 식별할 수 있게 해줍니다.

이 스크립트를 어떻게 실행하나요?

  1. 여기에서 Nuclei를 다운로드하세요.
  2. 템플릿을 로컬 시스템에 복사하세요.
  3. 다음 명령어를 실행하세요: nuclei -u https://yourHost.com -headless -t template.yaml

출력은 다음과 같아야 합니다: 대체 텍스트

심층 가이드는 여기에서 확인할 수 있습니다: Internal Security Detection

SafeBase 사이트 찾기

이 Google dork를 사용하여 SafeBase 트러스트 센터를 발견하세요:

root@kitploit:~
inurl:(security|trust|compliance) "Powered by SafeBase"

탐지된 보안 통제 (검증된 통제 163개)

아래의 모든 통제 항목은 실제 SafeBase 트러스트 센터에서 검증되었습니다.

접근 및 인증

  • Access Control
  • Access Control Policy
  • Access Log Management
  • Access Monitoring
  • Access Monitoring Policy
  • Authentication
  • Collected Data Access
  • Credential Management
  • Data Access
  • Data Roles: Controller and Processor
  • Multi-Factor Authentication
  • Password Security
  • SSO Support
  • Sub-processors
  • Subprocessors
  • Voluntary Product Accessibility Template® (VPAT®)

AI 및 머신러닝

  • AI Governance
  • AI Risk Statement
  • AI Security
  • AI Training Data
  • AI Training Data and Bias
  • Alignment with EU AI Act Principles
  • Decision-Making and Human Oversight
  • EU AI Act
  • Model Evaluations, Fairness & Bias
  • Ongoing Third-Party Bias Audits
  • TRUSTe Responsible AI Certification

애플리케이션 보안

  • Application Penetration Testing
  • Bug Bounty Program
  • Code Analysis
  • Responsible Disclosure
  • Responsible Disclosure & Bug Bounty
  • Secure Development Training
  • Secure Software Development Lifecycle
  • Software Development Lifecycle

자산 및 인프라

  • Asset Management
  • Asset Management Policy
  • Asset Management Practices
  • Audit Logging
  • Capacity Management
  • Data Exfiltration Monitoring
  • Infrastructure Logging
  • Logging
  • Status Monitoring
  • Status Monitoring of SLA

비즈니스 연속성

  • BC/DR
  • Business Continuity and Disaster Recovery
  • Business Continuity/Disaster Recovery (BC/DR) Policy
  • Data Backups
  • Disaster Recovery & Backups
  • Operational Resilience and Redundancy Policy
  • Overarching Operational Resilience and Redundancy Plan

규정 준수 및 인증

  • CCPA
  • CSA STAR
  • CSA STAR Certification
  • CSA STAR Level 1
  • CSA STAR Level 2
  • CSA STAR Level 2 Certification
  • CSA STAR for AI
  • CSA Trusted Cloud Provider
  • Cyber Essentials Plus
  • DORA
  • DoD IL4
  • EU-US DPF
  • FIPS 140-2
  • FedRAMP High
  • FedRAMP Moderate
  • GDPR
  • GDPR Compliance and AI
  • GovRAMP
  • HECVAT
  • HECVAT Full
  • HECVAT Lite
  • HIPAA
  • IRAP
  • IRAP Protected Documentation
  • ISO 27001 / 27017 / 27018
  • ISO/IEC 20243:2024
  • ISO/IEC 27001
  • ISO/IEC 27001 SoA
  • ISO/IEC 27001:2022
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • ISO/IEC 27701:2019
  • ISO/IEC 42001:2023
  • NIST
  • NIST 800-53 Rev. 5
  • OPTIV ISO27001
  • PCI DSS
  • PCI DSS v4.0.0
  • Privacy Mark
  • SOC 1
  • SOC 2
  • SOC 2 Type 2
  • SOC 3
  • Swiss-US DPF
  • TISAX
  • TX-RAMP
  • UK Extension to EU-US DPF
  • US Employment Law Compliance
  • VPAT

데이터 보호 및 개인정보 보호

  • Cookies
  • Data Breach Notifications
  • Data De-Identification
  • Data Deletion / Data Retention
  • Data Erasure
  • Data Flow Diagram
  • Data Loss Prevention
  • Data Privacy Officer
  • Data Processing Agreement
  • Data Residency
  • Data Retention
  • Data Retention & Disposal
  • Data Security
  • Disk Encryption
  • Employee Privacy Training
  • Encryption-at-rest
  • Health Data Hosting (HDS) France
  • Network / Data Flow Diagrams
  • Privacy Officer
  • Privacy Policy

엔드포인트 및 디바이스

  • Bring Your Own Device (BYOD)
  • Endpoint Detection & Response
  • Mobile Device Management

침해 대응

  • Incident Response
  • Incident Response Plan

네트워크 보안

  • Allow List Restrictions
  • Anti-DDoS
  • DNS Filtering
  • Firewall
  • IDS/IPS
  • Network Diagram

인력 및 교육

  • Acceptable Use Policy
  • Anti-Bribery and Corruption
  • Anti-Modern Slavery
  • Code of Conduct
  • Employee Training
  • HR Security
  • Model Pretraining
  • Modern Slavery
  • Phishing Training
  • Role-Based Training
  • Supplier Code of Conduct

위험 및 취약점

  • Risk Assessments
  • Supply Chain Risk Management
  • Vulnerability & Patch Management

제3자 및 공급업체

  • Customer Audit Rights
  • Third Party Dependence
  • Vendor Management

기타

  • Alternate Work Sites
  • Approach to AI
  • Certificate of Insurance
  • Change Enablement Policy
  • Continual Improvement Policy
  • Critical Dependence
  • Cyber Insurance
  • Email Protection
  • Employers Liability Insurance
  • Environment Social and Governance
  • Security Information and Event Management
  • Security Operations Center (SOC)
  • Technical and Organisational Measures

테스트된 사이트

이 템플릿은 다음에 대해 테스트 및 검증되었습니다:

  • security.projectdiscovery.io
  • security.okta.com
  • trust.openai.com
  • secureandtrusted.gbgplc.com
  • trust.treasuredata.com
  • trust.hipeople.io

참고 자료

  • https://safebase.io
  • https://blog.rxerium.com/internal-security-detection

연락처

Signal로 언제든지 저에게 연락해 주세요.

도구 다운로드