Search titles only
By:
Home
Members
Moderators
Current visitors
Escrow
Deposit
Account Upgrades
ADS
Help
WMIX.TO
Komplexes Bot
Log in
Register
What's new
Search
Search titles only
By:
Menu
Log in
Register
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Depov's latest activity
Depov
posted the thread
Responding to incidents in industrial networks: PLC, TTPs attackers and stop recovery
in
Programming
.
How the response to incidents of ICS SCADA differs from IT Responding to incidents in industrial networks is based on another model of...
Jun 29, 2026
Depov
posted the thread
Penttest of browser extensions: a methodology for analysis, vulnerability and detection for SOC
in
Web
.
Business logic: why are the expansions attacked and what does it threaten the company A browser extension is a JavaScript code with...
Jun 29, 2026
Depov
posted the thread
Protection against DDoS attacks: awax, scrupbing-center, rate limiting and automation of response
in
Web
.
DDoS-attack business logic: TTPs on MITRE AT&CK and what SOC should see Before building a DDoS-resistant infrastructure, let’s see how...
Jun 29, 2026
Depov
posted the thread
CSRF attack: operation mechanics, defense and PoC construction
in
Web
.
On the fintech pedest, the developers swore that the CSRF attack is impossible - "we have a set-off of CORS." After 40 minutes, a...
Jun 29, 2026
Depov
posted the thread
Detection of mobile spyware in the corporate environment: from blind MDM zones to network-based detection
in
Programming
.
On the audit of the mobile arsenal of fintech companies from the top 30, we found the iPhone of the CFO, who for three weeks leaked the...
Jun 29, 2026
Depov
posted the thread
WAPT: web application pentest as a methodology and practice
in
Web
.
What is WAPT / WAPT Web Application Penetration Testing (WATT or WAPT) is a systemic method of analyzing the security of web...
Jun 25, 2026
Depov
posted the thread
macOS Red Team Tools: Mythic, Sliver, Poseidon and custom implants for offensive operations
in
Programming
.
Kill chain macOS operations: where C2 stands Corporate Mac is Keychain with OAuth tokens, VPN configurations, active Slack and Teams...
Jun 25, 2026
Depov
posted the thread
Corporate Wi-Fi Network Security: WIDS/WIPS, hardening 802.1X and detection rogue AP
in
Programming
.
Threat model: how an attacker breaks the protection of the wireless network of the enterprise A wireless network is the only segment of...
Jun 24, 2026
Depov
posted the thread
WebSocket Security: testing real-time applications
in
Web
.
яIntroduction: WebSocket in a modern web WebSocket is a communication protocol that provides a two-way data transmission channel over a...
Jun 24, 2026
Depov
posted the thread
UEBA to detect insiders: setting up behavioral analytics and integration with SIEM
in
Programming
.
Why DLP System Without Behavioral Analytics Is Blind to Slices DLP sees content and transmission channel. It works when a document with...
Jun 23, 2026
Depov
posted the thread
Attacks on endpoint management of the system: analysis of TTP 2026 and detection for SOC
in
Web
.
On February 13, 2026, CISA gave the organizations three days to eliminate CVE-2026-1731 - pre-authentiction RCE in BeyondTrust Remote...
Jun 23, 2026
Depov
posted the thread
Mapping the external attacked surface of the organization: Passive DNS, CT-logs and hunt for Shadow IT
in
Web
.
At the pre-engagement phase of the pentest industrial company, I uploaded the root domain to cl.sh and received 47 subdomains. The IT...
Jun 22, 2026
Depov
posted the thread
Smartphone protection from surveillance: GrapheneOS, Lockdown Mode and mobile hardening for high-risk users
in
Programming
.
When we disassembled a similar case on the protection side for a media organization, the picture was painfully familiar: the corporate...
Jun 22, 2026
Depov
posted the thread
CI/CD for Beginners: Docker, GitLab CI and the first safe pypaline
in
Programming
.
CI/CD-pipeline as an attack surface CI/CD (Continuous Integration / Continuous Delivery) - a conveyor that automatically collects, tests...
Jun 21, 2026
Depov
posted the thread
Vulnerability Monitoring for Blue Team: a conveyor from KEV CISA to patching prioritization
in
Programming
.
Why CVSS is not enough to prioritize patches by risk CVSS has long been the only language of vulnerability management with business and...
Jun 21, 2026
Top
Bottom