I would urge most security teams to hit pause for an hour and take a moment to look at these three tools that may add leverage to the work you are doing.
1. Python LogTools – This is an excellent python library that makes parsing web logs, primarily Apache logs, easy and useful. The capability also can be trivially expanded to analyze other types of logs and system outputs with a little bit of text hacking. Seriously, we know you aren’t reading the logs – find a way to use programatic tools – even if that just means you are parsing for specific issues. I know, I know – you have the SEIM – but honestly, parse the logs. You’ll likely be amazed what you find…
2. Open Source Web Task Manager – Taskfreak – Nearly every team we talk to asks about coordinating task and resource management on other security teams. Here is a free tool set that you can you can use, apart from the more difficult enterprise tools and bloatware. Get a team server or instance and share tasks and resources. Done!
3. Nmap – yeah, we said it – NMAP! – Oh, I know – you’ve used it. It comes on Kali and nearly every distro – but forget using it for pen-testing and auditing. Now, with a clear mind – begin to think about how you can use nmap to know what’s out there. Inventory of systems and services, done. Ongoing runs to detect new devices, done. Ongoing runs to find new services on known network segments, done. Periodic runs to test network speeds and connectivity for routing issues, done. Gateway checks, done. Detection of new devices by parsing DHCP logs and launching runs – a poor man’s NAC tool, done. There are so many things you can do with nmap other than pen-testing that I am thinking of just becoming an nmap consultant. C’mon – learn the basics and then use the basic tool in new ways to solve problems you already have. Nmap and some simple scripting can up your security team’s game. Give it a shot…
Got other ideas? Let us know on Twitter (@microsolved). See you there!
New Blog Post: 3 Tools Security Teams Need to Look at Today https://t.co/FZ6cQLAm8k
3 Tools Security Teams Need to Look at Today – I would urge most security teams to hit pause for an hour and ta… https://t.co/X7gp7uetKp
3 Tools Security Teams Need to Look at Today | MSI :: State of Security https://t.co/MpvZ8BvHZp
3 Tools Security Teams Need to Look at Today #infosec https://t.co/c77oUJzuUO
RT @infosectony: 3 Tools Security Teams Need to Look at Today #infosec https://t.co/c77oUJzuUO
3 Tools Security Teams Need to Look at Today #infosec #cybersecurity #mustread https://t.co/c77oUJzuUO
RT @infosectony: 3 Tools Security Teams Need to Look at Today #infosec #cybersecurity #mustread https://t.co/c77oUJzuUO
RT @infosectony: 3 Tools Security Teams Need to Look at Today #infosec #cybersecurity #mustread https://t.co/c77oUJzuUO