To be honest it feels like vested interests are keeping it that way: professionals want to keep the tools manual so they can charge by the hour; and tool vendors obviously have no interest in open source tools
To be honest it feels like vested interests are keeping it that way: professionals want to keep the tools manual so they can charge by the hour; and tool vendors obviously have no interest in open source tools
And the community of practitioners are giving back to the community in all dimensions, code, knowledge, talks, support, heck even governments and institutions five free insights; mitre, nist, cis for instance.
With a few exceptions such as Nessus and Qualys.
CIS audit, https://www.auditscripts.com
Mitre Attack, https://attack.mitre.org/
NIST, https://www.nist.gov/cyberframework
CISA, https://www.cisa.gov/cybersecurity
OWASP top 10, https://owasp.org/www-project-top-ten/
Cloud security alliance, https://cloudsecurityalliance.org/
Higher level standards: Iso27001
IEC62443
Tools:
AD: Bloodhound / Sharphound
PingCastle
Web:
Owasp ZAP
Burpsuite
Basically download the Kali linux distro
+++++++++++++++
Conferences:
Blackhat
Defcon
Hope
I gave up on trying to do an authenticated scan. Docs/ Forum answers always say "First get it to work in the GUI, then try running on command line." Well that's not helping me very much, because "getting it to work in the GUI" is not reproducible and shareable in the same way as a code/script showing clear steps. Secondly, getting authenticated scans to work when your login form is protected by a CSRF token is very much not trivial (don't think I got this to work in any tools). But if your forms are not protected, you have a vulnerability.
My feeling is that the right kind of tool is really a library, so that one can script the login process which may be quite complex with 2FA.
For CSRF you'll want browser automation, like Chrome Headless. Alternatively, you can load a page and extract a token from the DOM in a normal scraper.
>To be honest it feels like vested interests are keeping it that way: professionals want to keep the tools manual so they can charge by the hour;
As a security professional, get out of here with that non-sense. You've run into a challenging problem and still think there is some conspiracy. What we do is highly technical and often customer specific (e.g. automate 2fa due to some weird requirement rather than the customer disabling it for the test account). There is no market in automating a lot of this work, packaging it in a nodejs library for you to use, and writing docs.
Zap is pretty scriptable as well, so there are likely solutions for it also. What have you tried?
Oh, and it also crashes with null pointer errors.
That piece of software is some of the worst, verbose, bug-ridden garbage I've been required to work with.
That’s the only way to break the consultancy chain - stop paying the wolves to guard the henhouse.