A Penetration Testing Findings Repository

Опубликовано: 21 Октябрь 2024
на канале: Software Engineering Institute | Carnegie Mellon University
430
13

In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI) Marisa Midler and Samantha Chaves, penetration testers with the SEI’s CERT Division, talk with Suzanne Miller about a penetration-testing repository, available at https://github.com/cisagov/pen-testin..., that they helped to build. The repository is a source of information for active directory, phishing, mobile technology, systems and services, web applications, and mobile- and wireless-technology weaknesses that could be discovered during a penetration test. The repository is intended to help assessors provide reports to organizations using standardized language and standardized names for findings, and to save assessors time on report generation by having descriptions, standard remediations, and other resources available in the repository for their use. The repository is currently an open-source document hosted on the Cybersecurity andInfrastructure Agency (CISA) Github website.

#pentesting, #software, #vulnerabilities, ‪@TheSEICMU‬

The SEI Podcast Series is available sei.cmu.edu/podcasts and on the following channels:
Apple Podcasts: https://podcasts.apple.com/us/podcast...
Google Podcasts: https://podcasts.google.com/?feed=aHR...
TuneIn: https://tunein.com/podcasts/Technolog...
SoundCloud:   / cmu-sei-podcasts  
Stitcher: https://www.stitcher.com/podcast/soft...
Spotify: https://open.spotify.com/show/1CAKTiV...