Recommend what to read. Part 1

Recommend what to read. Part 1

It's always nice to share useful information with the community. We asked our employees to recommend resources they personally visit to stay updated on developments in the world of cybersecurity. The selection turned out to be extensive, so we had to split it into two parts. Here is the first part.

Twitter

  • NCC Group Infosec β€” a technical blog of a large cybersecurity company that regularly publishes its research, tools/plugins for Burp.
  • Gynvael Coldwind β€” a security researcher and founder of the top CTF team Dragon Sector.
  • Null Byte β€” tweets about hacking and hardware.
  • HackSmith β€” an SDR developer and RF and IoT security researcher, tweets/retweets about hardware hacking.
  • DirectoryRanger β€” about Active Directory and Windows security.
  • Binni Shah β€” mainly writes about hardware, retweets posts on various cybersecurity topics.

Telegram

  • [MIS]ter & [MIS]sis Team β€” cybersecurity from the perspective of RedTeam. A lot of quality material dedicated to attacks on Active Directory.
  • Kavichka β€” a typical channel about web bugs for web bug enthusiasts. It often emphasizes dissecting exploitation methods of common vulnerabilities and advice on effective software use, along with lesser-known but useful features.
  • CyberP*eet β€” a channel about technology and cybersecurity.
  • Data Leaks β€” a digest of data leaks.
  • Admin with a Letter β€” a channel about system administration. Not strictly cybersecurity, but useful.
  • linkmeup β€” the linkmeup podcast channel, where enthusiasts have discussed networks, technology, and cybersecurity since 2011. We also recommend checking out website.
  • Life-Hack [Life-Hacking] / Hacking β€” posts about hacking and security in an accessible language (perfect for beginners).
  • r0 Crew (Channel) β€” a digest of useful materials mainly on RE, exploit development, and malware analysis.

Github repository

Blogs

  • Project Zero β€” usually does not need an introduction, but if you haven't heard of them: it's a team of cool specialists who search for vulnerabilities like "remote jailbreak for top iOS without user interaction", not for money, but for the sake of public safety.
  • PortSwigger Blog β€” the blog of the developers of the Burp Suite tool, which has become the de facto standard for web security. It is dedicated, of course, to web application security.
  • Firmware Security
  • Active Directory Security
  • Black Hills Information Security β€” has written many useful tools/scripts for auditing, besides the blog, they actively share knowledge in their podcasts.
  • Sjoerd Langkemper. Web application security
  • Pentester Land β€” a digest of videos and articles on pentesting is published here every week.

Youtube

Bloggers

  • GynvaelEN β€” video walkthroughs, including from the well-known Gynvael Coldwind of the Google security team and founder of the top CTF team Dragon Sector, where he shares many interesting insights about reverse engineering, programming, solving CTF tasks, and code auditing.
  • LiveOverflow β€” a channel with very high-quality content β€” explaining cool exploitation methods in simple terms. There are also analyses of interesting Bug Bounty reports.
  • STΓ–K β€” a channel focused on Bug Bounty, valuable advice and interviews with top bug hunters from HackerOne.
  • IppSec β€” walkthroughs of machines on Hack the Box.
  • CQURE Academy β€” a company specializing in auditing Windows infrastructure. There are many useful videos on various aspects of Windows systems.

Conferences

Academic Conferences

Industry Conferences

Systematization of Knowledge (SoK)

This type of academic work can be very useful at the very beginning of delving into a new topic or when systematizing information. It's not hard to find such works, here are a few examples:

Original Source

We hope you found something new. In the next part, we will suggest what to read if you are interested in topics like formula satisfiability in theories and machine learning in security, and we will also recommend whose talks on iOS jailbreaking would be useful.

We would be glad if you share your findings or personal blog in the comments.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers πŸ”₯ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster