Skip to main content

Concetti

Appunti teorici, architetture, protocolli e meccanismi di difesa in ambito Cybersecurity.

β–Ά πŸ“ OS & Linux Internals (46)
β”œβ”€ alternative a man (cheatsheet) [system]
β”œβ”€ architettura di wazuh siem/xdr [observability], [system]
β”œβ”€ bash reverse shell - anatomia del comando [dfir], [system]
β”œβ”€ blockchain - ledger immutabile e applicazioni security [system], [network-defense]
β”œβ”€ certificate formats - pem, der, pfx/p12, cer, crt, key [system], [network-defense]
β”œβ”€ command chaining e grouping [system]
β”œβ”€ compressione vs archiviazione [system]
β”œβ”€ etc directory purpose [system], [iam]
β”œβ”€ faq - diagnostica di rete e servizi [network-defense], [system]
β”œβ”€ file-descriptor [system]
β”œβ”€ filesystem architecture inodes [system]
β”œβ”€ hypervisor - type 1 vs type 2, vm escape e container [system], [cloud-security]
β”œβ”€ i confini della visibilitΓ : pubblico vs privato [system], [cloud-security]
β”œβ”€ inode anatomy [system]
β”œβ”€ iptables - netfilter firewall linux [network-defense], [system]
β”œβ”€ journald - systemd-journald [system], [observability]
β”œβ”€ link hard vs symbolic [system]
β”œβ”€ link orfani (broken links) [system], [persistence]
β”œβ”€ linux filesystem hierarchy [system]
β”œβ”€ linux processes - processi [system]
β”œβ”€ network configuration linux [network-defense], [system]
β”œβ”€ network interfaces (interfacce di rete) [network-defense], [system]
β”œβ”€ pam - pluggable authentication modules [iam], [system]
β”œβ”€ persistenza degli alias [system]
β”œβ”€ rm mechanism [system]
β”œβ”€ s/mime - email signing e encryption [network-defense], [system]
β”œβ”€ servizi linux (daemon) [system], [persistence]
β”œβ”€ shebang - #! [system]
β”œβ”€ shell - confronto e differenze [system]
β”œβ”€ standard streams [system]
β”œβ”€ steganography vs tokenization vs data masking [network-defense], [system]
β–Ά πŸ“ Network Defense (91)
β”œβ”€ anycast - resilienza architetturale e anti-ddos [network-defense], [cloud-security]
β”œβ”€ arp - address resolution protocol [network-defense]
β”œβ”€ blockchain - ledger immutabile e applicazioni security [system], [network-defense]
β”œβ”€ botnet e c2 - master-slave vs p2p, domain flux [malware-analysis], [network-defense]
β”œβ”€ casb - cloud access security broker [cloud-security], [network-defense]
β”œβ”€ certificate formats - pem, der, pfx/p12, cer, crt, key [system], [network-defense]
β”œβ”€ cloud shared responsibility model: iaas, paas, saas [cloud-security], [network-defense]
β”œβ”€ command injection [network-defense]
β”œβ”€ crittografia asimmetrica - rsa, ecc, firma digitale e code signing [network-defense], [cloud-security]
β”œβ”€ cryptography [network-defense]
β”œβ”€ csrf - cross-site request forgery e samesite cookies [network-defense], [cloud-security]
β”œβ”€ cvss - common vulnerability scoring system [threat-intel], [network-defense]
β”œβ”€ ddos reflected e amplification attack [network-defense], [threat-intel]
β”œβ”€ dhcp - dynamic host configuration protocol [network-defense]
β”œβ”€ dmz e screened subnet: dual-firewall, bastion host, jump server [network-defense], [cloud-security]
β”œβ”€ dns e http in una lan con switch [network-defense], [dfir]
β”œβ”€ dns poisoning, pharming e dns sinkhole [network-defense], [threat-intel]
β”œβ”€ dns records [network-defense]
β”œβ”€ dns resolution flow [network-defense], [threat-intel]
β”œβ”€ dns tunneling [network-defense], [dfir], [threat-intel]
β”œβ”€ faq - diagnostica di rete e servizi [network-defense], [system]
β”œβ”€ fim - file integrity monitoring [network-defense]
β”œβ”€ firewall types: packet filtering, stateful, ngfw, waf, proxy [network-defense], [cloud-security]
β”œβ”€ frame, pacchetto, segmento - osi e stream [network-defense], [dfir]
β”œβ”€ fuzzing - coverage-guided, mutation-based [network-defense]
β”œβ”€ hashing, hmac e password storage - integrita' e autenticazione [network-defense], [cloud-security]
β”œβ”€ honeypot, honeynet, honeyfile, honeytoken - deception technologies [network-defense], [threat-hunting]
β”œβ”€ how web works [network-defense]
β”œβ”€ http in detail [network-defense]
β”œβ”€ http in wireshark - tcp segmentation e packet analysis [network-defense], [dfir]
β”œβ”€ ids e ips - detection e prevention, host e rete [network-defense], [observability]
β”œβ”€ ip addressing & subnetting [network-defense]
β”œβ”€ ip header e ipv4 [network-defense]
β”œβ”€ ip subnetting - matematica e routing [network-defense]
β”œβ”€ iptables - netfilter firewall linux [network-defense], [system]
β”œβ”€ ipv6 - internet protocol version 6 [network-defense]
β”œβ”€ kms - key management system e key rotation [cloud-security], [network-defense]
β”œβ”€ lan topologies - topologie di rete [network-defense]
β”œβ”€ load balancer - active-active, active-passive e session affinity [network-defense], [cloud-security]
β”œβ”€ mdm - mobile device management e byod [cloud-security], [network-defense]
β”œβ”€ mtu - maximum transmission unit [network-defense]
β”œβ”€ nac - network access control e posture assessment [network-defense], [cloud-security]
β”œβ”€ nat concept [network-defense]
β”œβ”€ ndp - neighbor discovery protocol [network-defense]
β”œβ”€ network configuration linux [network-defense], [system]
β”œβ”€ network interfaces (interfacce di rete) [network-defense], [system]
β”œβ”€ osi model - il modello a layer [network-defense]
β”œβ”€ osint tools - shodan, censys, virustotal, hibp, exploit-db, cyberchef, navigator, dett&ct [threat-intel], [network-defense], [observability]
β”œβ”€ owasp top 10 [network-defense], [threat-intel]
β”œβ”€ passive reconnaissance - ricognizione passiva [network-defense], [threat-intel]
β”œβ”€ pki - public key infrastructure e chain of trust [network-defense], [cloud-security]
β”œβ”€ proxy [network-defense]
β”œβ”€ replay attack - timestamp, nonce e kerberos [network-defense], [cloud-security]
β”œβ”€ reverse shell [network-defense], [persistence]
β”œβ”€ routing statico e topologia lan-internet [network-defense]
β”œβ”€ routing, hop e ttl [network-defense]
β”œβ”€ s/mime - email signing e encryption [network-defense], [system]
β”œβ”€ sast vs dast vs iast vs sca - application security testing [network-defense], [automation]
β”œβ”€ scada e ics - ot security e purdue model [network-defense], [threat-intel]
β”œβ”€ session hijacking - cookie theft, httponly e token regeneration [network-defense], [cloud-security]
β”œβ”€ smtp - simple mail transfer protocol [network-defense]
β”œβ”€ sql injection (sqli) [network-defense]
β”œβ”€ ssh key authentication [network-defense], [iam]
β”œβ”€ ssl stripping, hsts e cryptographic downgrade attacks [network-defense], [cloud-security]
β”œβ”€ steganography vs tokenization vs data masking [network-defense], [system]
β”œβ”€ symmetric encryption [network-defense]
β”œβ”€ syn flood e syn cookies - connection table exhaustion [network-defense], [threat-intel]
β”œβ”€ tcp handshake [network-defense]
β”œβ”€ tls - transport layer security - handshake e crittografia ibrida [network-defense], [cloud-security]
β”œβ”€ tpm e hsm - hardware security module e trusted platform module [network-defense], [cloud-security]
β”œβ”€ unicast, broadcast, multicast [network-defense]
β”œβ”€ vlan - segmentazione logica e vlan hopping [network-defense], [cloud-security]
β”œβ”€ vpn e ipsec - ike, esp, ah, tunnel e split tunnel [network-defense], [cloud-security]
β”œβ”€ vulnerability assessment - credentialed vs non-credentialed [network-defense], [threat-intel]
β”œβ”€ well-known ports - security+ [network-defense]
β”œβ”€ wireshark [network-defense], [dfir]
β”œβ”€ xss - cross-site scripting reflected, stored, dom e csp [network-defense], [cloud-security]
β”œβ”€ xxe - xml external entity injection [network-defense]
└─ zero trust architecture - never trust always verify [network-defense], [cloud-security]
β–Ά πŸ“ Cloud & Container (38)
β”œβ”€ /var/run/docker.sock - il socket di docker [cloud-security], [iam]
β”œβ”€ anycast - resilienza architetturale e anti-ddos [network-defense], [cloud-security]
β”œβ”€ casb - cloud access security broker [cloud-security], [network-defense]
β”œβ”€ cloud shared responsibility model: iaas, paas, saas [cloud-security], [network-defense]
β”œβ”€ crittografia asimmetrica - rsa, ecc, firma digitale e code signing [network-defense], [cloud-security]
β”œβ”€ csrf - cross-site request forgery e samesite cookies [network-defense], [cloud-security]
β”œβ”€ dlp - data loss prevention [cloud-security], [dfir]
β”œβ”€ dmz e screened subnet: dual-firewall, bastion host, jump server [network-defense], [cloud-security]
β”œβ”€ docker - modello mentale [cloud-security]
β”œβ”€ docker - uid, permessi e volumi bind mount [cloud-security], [iam]
β”œβ”€ docker compose [cloud-security]
β”œβ”€ docker image [cloud-security]
β”œβ”€ docker network [cloud-security]
β”œβ”€ docker security [cloud-security], [iam], [persistence]
β”œβ”€ docker volumes [cloud-security]
β”œβ”€ dockerfile [cloud-security]
β”œβ”€ edr vs antivirus - behavioral analysis e response [threat-hunting], [cloud-security]
β”œβ”€ firewall types: packet filtering, stateful, ngfw, waf, proxy [network-defense], [cloud-security]
β”œβ”€ hashing, hmac e password storage - integrita' e autenticazione [network-defense], [cloud-security]
β”œβ”€ hypervisor - type 1 vs type 2, vm escape e container [system], [cloud-security]
β”œβ”€ i confini della visibilitΓ : pubblico vs privato [system], [cloud-security]
β”œβ”€ kms - key management system e key rotation [cloud-security], [network-defense]
β”œβ”€ load balancer - active-active, active-passive e session affinity [network-defense], [cloud-security]
β”œβ”€ mdm - mobile device management e byod [cloud-security], [network-defense]
β”œβ”€ nac - network access control e posture assessment [network-defense], [cloud-security]
β”œβ”€ pki - public key infrastructure e chain of trust [network-defense], [cloud-security]
β”œβ”€ replay attack - timestamp, nonce e kerberos [network-defense], [cloud-security]
β”œβ”€ session hijacking - cookie theft, httponly e token regeneration [network-defense], [cloud-security]
β”œβ”€ ssl stripping, hsts e cryptographic downgrade attacks [network-defense], [cloud-security]
β”œβ”€ sso, kerberos e saml - enterprise identity federation [iam], [cloud-security]
β”œβ”€ tls - transport layer security - handshake e crittografia ibrida [network-defense], [cloud-security]
β”œβ”€ tpm e hsm - hardware security module e trusted platform module [network-defense], [cloud-security]
β”œβ”€ vlan - segmentazione logica e vlan hopping [network-defense], [cloud-security]
β”œβ”€ vpn e ipsec - ike, esp, ah, tunnel e split tunnel [network-defense], [cloud-security]
β”œβ”€ xss - cross-site scripting reflected, stored, dom e csp [network-defense], [cloud-security]
└─ zero trust architecture - never trust always verify [network-defense], [cloud-security]
β–Ά πŸ“ Observability (19)
β”œβ”€ architettura di wazuh siem/xdr [observability], [system]
β”œβ”€ auth.log - log di autenticazione [iam], [observability]
β”œβ”€ ids e ips - detection e prevention, host e rete [network-defense], [observability]
β”œβ”€ incident response - framework e lifecycle [observability], [dfir]
β”œβ”€ journalctl vs var log [observability]
β”œβ”€ journald - systemd-journald [system], [observability]
β”œβ”€ mitre att&ck framework [observability]
β”œβ”€ osint tools - shodan, censys, virustotal, hibp, exploit-db, cyberchef, navigator, dett&ct [threat-intel], [network-defense], [observability]
β”œβ”€ reverse proxy [observability]
β”œβ”€ ruoli aziendali - c-suite e figure security [dfir], [observability]
β”œβ”€ security controls - tipi e funzioni [dfir], [observability]
β”œβ”€ soc - struttura e organizzazione [dfir], [observability], [threat-intel]
β”œβ”€ soc tiers - ruoli e responsabilitΓ  [observability]
β–Ά πŸ“ DFIR (25)
β”œβ”€ bash reverse shell - anatomia del comando [dfir], [system]
β”œβ”€ cia triad [dfir], [threat-intel]
β”œβ”€ dlp - data loss prevention [cloud-security], [dfir]
β”œβ”€ dns e http in una lan con switch [network-defense], [dfir]
β”œβ”€ dns tunneling [network-defense], [dfir], [threat-intel]
β”œβ”€ frame, pacchetto, segmento - osi e stream [network-defense], [dfir]
β”œβ”€ git objects - struttura interna di git [dfir], [automation]
β”œβ”€ http in wireshark - tcp segmentation e packet analysis [network-defense], [dfir]
β”œβ”€ incident response - framework e lifecycle [observability], [dfir]
β”œβ”€ path traversal, lfi e rfi [dfir]
β”œβ”€ ruoli aziendali - c-suite e figure security [dfir], [observability]
β”œβ”€ secret scanning - trovare segreti esposti [dfir], [threat-intel]
β”œβ”€ security controls - tipi e funzioni [dfir], [observability]
β”œβ”€ soc - struttura e organizzazione [dfir], [observability], [threat-intel]
└─ wireshark [network-defense], [dfir]
β–Ά πŸ“ Threat Intel (27)
β”œβ”€ attacker-in-the-browser - form grabbing e zeus case study [malware-analysis], [threat-intel]
β”œβ”€ cia triad [dfir], [threat-intel]
β”œβ”€ cve e nvd - database vulnerabilitΓ  [threat-intel]
β”œβ”€ cvss - common vulnerability scoring system [threat-intel], [network-defense]
β”œβ”€ ddos reflected e amplification attack [network-defense], [threat-intel]
β”œβ”€ dns poisoning, pharming e dns sinkhole [network-defense], [threat-intel]
β”œβ”€ dns resolution flow [network-defense], [threat-intel]
β”œβ”€ dns tunneling [network-defense], [dfir], [threat-intel]
β”œβ”€ malware classification - virus, worm, trojan, rat, rootkit [malware-analysis], [threat-intel]
β”œβ”€ osint tools - shodan, censys, virustotal, hibp, exploit-db, cyberchef, navigator, dett&ct [threat-intel], [network-defense], [observability]
β”œβ”€ owasp top 10 [network-defense], [threat-intel]
β”œβ”€ passive reconnaissance - ricognizione passiva [network-defense], [threat-intel]
β”œβ”€ ransomware - crypto vs locker, wannacry, notpetya [malware-analysis], [threat-intel]
β”œβ”€ scada e ics - ot security e purdue model [network-defense], [threat-intel]
β”œβ”€ secret scanning - trovare segreti esposti [dfir], [threat-intel]
β”œβ”€ soc - struttura e organizzazione [dfir], [observability], [threat-intel]
β”œβ”€ syn flood e syn cookies - connection table exhaustion [network-defense], [threat-intel]
└─ vulnerability assessment - credentialed vs non-credentialed [network-defense], [threat-intel]
β–Ά πŸ“ Malware Analysis (7)
β”œβ”€ attacker-in-the-browser - form grabbing e zeus case study [malware-analysis], [threat-intel]
β”œβ”€ botnet e c2 - master-slave vs p2p, domain flux [malware-analysis], [network-defense]
β”œβ”€ fileless malware - living off the land, powershell [malware-analysis], [threat-hunting]
β”œβ”€ logic bomb e easter egg [malware-analysis], [persistence]
β”œβ”€ magic bytes [malware-analysis]
β”œβ”€ malware classification - virus, worm, trojan, rat, rootkit [malware-analysis], [threat-intel]
└─ ransomware - crypto vs locker, wannacry, notpetya [malware-analysis], [threat-intel]
β–Ά πŸ“ Threat Hunting (4)
β”œβ”€ edr vs antivirus - behavioral analysis e response [threat-hunting], [cloud-security]
β”œβ”€ fileless malware - living off the land, powershell [malware-analysis], [threat-hunting]
β”œβ”€ honeypot, honeynet, honeyfile, honeytoken - deception technologies [network-defense], [threat-hunting]
β–Ά πŸ“ Persistence (8)
β”œβ”€ docker security [cloud-security], [iam], [persistence]
β”œβ”€ link orfani (broken links) [system], [persistence]
β”œβ”€ logic bomb e easter egg [malware-analysis], [persistence]
β”œβ”€ reverse shell [network-defense], [persistence]
β”œβ”€ servizi linux (daemon) [system], [persistence]
β”œβ”€ shell interattiva vs non interattiva [persistence]
β”œβ”€ suid, sgid e sticky bit [iam], [persistence]
└─ systemd [persistence]
β–Ά πŸ“ IAM (22)
β”œβ”€ /var/run/docker.sock - il socket di docker [cloud-security], [iam]
β”œβ”€ auth.log - log di autenticazione [iam], [observability]
β”œβ”€ docker - uid, permessi e volumi bind mount [cloud-security], [iam]
β”œβ”€ docker security [cloud-security], [iam], [persistence]
β”œβ”€ etc directory purpose [system], [iam]
β”œβ”€ etc passwd anatomy [iam]
β”œβ”€ linux groups [iam]
β”œβ”€ linux permissions ugo [iam]
β”œβ”€ orphaned files security [iam]
β”œβ”€ pam - pluggable authentication modules [iam], [system]
β”œβ”€ ssh key authentication [network-defense], [iam]
β”œβ”€ sso, kerberos e saml - enterprise identity federation [iam], [cloud-security]
β”œβ”€ sudoers and privileges [iam]
β”œβ”€ suid, sgid e sticky bit [iam], [persistence]
└─ uid gid identifiers [iam]
β–Ά πŸ“ Automation (4)
β”œβ”€ command grouping - {} [automation]
β”œβ”€ git objects - struttura interna di git [dfir], [automation]
β”œβ”€ heredoc - blocco di testo come stdin [automation]
└─ sast vs dast vs iast vs sca - application security testing [network-defense], [automation]