TGViewer
Channel Public Channel
SGAP (Cyber Security Leadership)

SGAP (Cyber Security Leadership)

@sgapsec

SGAP cyber security leadership
مرکز امنیت سایبری SGAP
ارائه خدمات فنی شبکه و امنیت سایبری
آموزش دوره های تخصصی هک و امنیت
آخرین اخبار شبکه و امنیت و دانلود منابع آموزشی
ارتباط با ما :
@sgapsec
www.sgap.co
09158000468
05136029870
Subscribers
811
Photos
1.6K
Videos
180
Links
921
Recent Posts 20 shown
Post #2706
Channel photo updated
Post #2696 515
SGAP (Cyber Security Leadership) Malware Development, Analysis and DFIR Series PART I Introduction This will be a series focussed on developing Malwares for ethical purposes only, The author is not liable for any damages caused. before we begin, let’s know about a few things what is a malware?…
Post #2694 454
Malware Development, Analysis and DFIR Series
PART I
Introduction

This will be a series focussed on developing Malwares for ethical purposes only, The author is not liable for any damages caused.

before we begin, let’s know about a few things
what is a malware?

Malwares are malicious softwares, that are a nefarious class of software meticulously engineered to compromise the integrity, confidentiality, or availability of computer systems. These pernicious programs are often cloaked in deceit, masquerading as legitimate software to trick unsuspecting users into granting them access. A malware can perform harmful actions such as stealing sensitive data, causing system disruptions, or even taking control of the system.

Malwares can also be used by red/purple teamers and pentesters for ethical and authorized purposes like Assessment of Defenses, Simulation of Threat Actors, Testing Incident Response Plans, Validation of Security

گروه امنیت سایبری SGAP
www.sgap.co
@sgapsec
azr43lkn1ght.github.io Malware Development, Analysis and DFIR Series - Part I 1st post of Malware Development, Analysis and DFIR Series. This post will be focussed on developing Malwares for ethical purposes only, The author is not liable for any damages caused.
Post #2691 492
🖥درس آموخته ای از حادثه‌ی اخیر Crowdstrike و استفاده از تجربه آن در امنیت سایبری شبکه های OT

1️⃣ اهمیت آزمایش هرگونه به‌روزرسانی در محیط آزمایشی قبل از استقرار در محیط اجرایی مطابق با گزارش فنی استاندارد ISA/IEC 62443-2-3. آزمایش Patchها در حوزه OT بسیار حیاتیست چون عدم دسترسی به ایستگاه های کاری اپراتورها یا سرورهای کنترلی می‌تواند به پیامدهای نامطلوبی منجر شود.
2️⃣ اهمیت مفهوم Secure Product Development Lifecycle هست که در استاندارد ISA/IEC 62443-4-1 به آن پرداخته شده است تا اطمینان حاصل شود که تأمین‌کننده محصول امنیت را در طول توسعه محصول در نظر می‌گیرد.

گروه امنیت سایبری SGAP
www.sgap.co
@sgapsec
Post #2687 649
🔖Top 2️⃣5️⃣ Recon tools and their purpose

01. Amass (Attack Surface)
02. Subfinder (Subdomains Enumeration)
03. Assetfinder (Subdomains Enumeration)
04. Dnsx (DNS Resolution)
05. Puredns (DNS resolution)
06. Dnsvalidator (Active DNS Servers)
07. Naabu (Port Scanner)
08. Nmap (Port Scanner)
09. Masscan (Port Scanner at scale)
10. Httpx (Web server detection)
11. Aquatone (Screenshot)
12. Gowitness (Screenshot)
13. Waybackurls (Urls)
14. Gau (Urls)
15. Waymore (Urls)
16. Gospider (Web Crawler)
17. Ffuf (File&Dir Enumeration)
18. Dirsearch (File&Dir Enumeration)
19. Gobuster (File&Dir Enumeration)
20. Feroxbuster (File&Dir Enumeration)
21. Whatweb (Technology Detection)
22. Trufflehog (Credentials)
23. Gotator (Subdomain Permutation)
24. Altdns (Subdomain Permutation)
25. Nuclei (Vulnerability Detection)

گروه امنیت سایبری SGAP
www.sgap.co
@sgapsec
سدید گستران امن پارس SGAP Home طراحی و پیاده‌سازی مرکز عملیات امنیت سایبری SOC ادازی و صنعتی OT با قابلیت شناسایی تهدیدات APT و نسل جدید با بهره‌گیری از هوش مصنوعی و DPI
Post #2686 435
SGAP (Cyber Security Leadership) 🔖Misconfig Mapper A fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets! 😴Github: 🔗Link
Post #2685 445
Post #2682 441
🤖 AutoAppDomainHijack 🤖

💬
Tools to automate finding AppDomain hijacks and generating payloads from shellcode.

👤 HijackHunt:
Run this tool on the target. It will search recursively in the C:\ directory for .NET managed `.exe`s and test if the folder is writeable - indicating that the PE is AppDomainHijack-able.

💡 AutoDomainHijack:
💻 Usage:
  AutoDomainHijack.exe (--version | -h | --help)

📊 Options:
-t, --target-name=<target-name>  Name of the target managed .exe to hijack.
-n, --hijack-name=<hijack-name> Name of the hijacker .dll.
-u, --url=<url> URL of the remote shellcode to run.
-f, --file=<file> File containing the shellcode to embed.
-o, --output=<output> Full directory to write files to.
-e, --etw=<etw> Disable ETW. [default: true]
--version Prints version
-h, --help Show help message


📂 Build:
nimble build


😸 Github

گروه امنیت سایبری SGAP
www.sgap.co
@sgapsec
GitHub GitHub - nbaertsch/AutoAppDomainHijack: Automated .NET AppDomain hijack payload generation Automated .NET AppDomain hijack payload generation - nbaertsch/AutoAppDomainHijack
Older posts →

About this channel

How can I read @sgapsec without a Telegram account?
TGViewer shows the public web preview Telegram publishes for SGAP (Cyber Security Leadership): recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does SGAP (Cyber Security Leadership) have?
SGAP (Cyber Security Leadership) (@sgapsec) has 811 subscribers on Telegram, refreshed roughly every 30 minutes.
Does SGAP (Cyber Security Leadership) know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →