This post has been de-listed
It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.
I hope this is the right sub, i was wondering if someone could please point me in the right direction.
I'm familiar with:
- https://cve.mitre.org/cve/search_cve_list.html
- https://www.cvedetails.com/ and;
- https://gtfobins.github.io/
The goal is to scope for vulnerabilities and reduce the attack surface. Additionally, patch holes in security.
Ultimately, I'm trying to aggregate from rigorously up-to-date sources. On the side of configuration, with regards to common tooling such as DBs, web servers, tunneling via SSH, firewall configuration, system config, kernels, etc, keeping up-to-date in this regard too - specifically "hardening" and "best practices."
Does anyone know of some decent guides/resources for aggregation that are frequently updated? Maybe we can compile a list in this thread. Perhaps discuss existing IDS/IPS methods and alternatives as well.
Thanks!!
Subreddit
Post Details
- Posted
- 7 months ago
- Reddit URL
- View post on reddit.com
- External URL
- reddit.com/r/AskNetsec/c...