Saturday, July 6, 2024

Vulnerability Management - Scream Test

What will you do when you went through CMDB and did not find any ownership info. of a server ? You initiated a thread as well but no one is claiming/accepting ownership of the server.


You run a scream test 😁 .

It is a simple – remove it and wait for the screams test. If someone screams, put it back. The Scream Test can be applied to any product, service or capability – particularly when there is poor ownership or understanding of it’s importance.

Typically it consists of the following steps:

  1. Display the message “Hey, is this your server, contact us?” on the sign-in splash page for two weeks.
  2. Restart the server once each day for two weeks to see whether someone opens a ticket (in other words, screams).
  3. Shut down the server for two weeks and see whether someone opens a ticket. (Again, whether they scream.)
  4. Retire the server, retaining the storage for a period, just in case.

From vulnerability management standpoint, there are two benefits:
  1. If such servers/applications are removed, a lot of vulnerabilities are removed.
  2. If someone screams, well, you know the owner now 😛 .

Happy Learning
hashtagvulnerabilitymanagement hashtagcybersecurity

Vulnerability Management - On a lighter note 😅

If one truly wants to learn vulnerability prioritization and risk assessment, he/she should work in OT Vulnerability Management. Unlike IT Vulnerability Management where patching is frequent, here it is very rare 🤣.

If your reasoning (to patch) is not strong enough then support teams will just ignore your request. The only option left for you is to be very strong in your vulnerability analysis.

Message - IT focuses on Confidentiality and Integrity while OT focuses on Availability.

OT environment be like - Kuch din to gujaro OT network me 😁

OR

"Patching" - We don't do that here !!

Vulnerability Management - Huge dataset

Vulnerability data is huge. I realized this yesterday when my VBA script gave this error ("You can't paste this here because the Copy area and paste area aren't the same size. Select just one cell in the paste area or an area that's the same size, and try pasting again.")

I was a bit shocked as till now the script worked fine and hadn't given any error.

So after googling and a bit of testing, I found out that the maximum rows a worksheet can have is 1048576. If you want to work with a dataset in MS Excel crossing this limit then you will need to switch to Excel's power query.

This is one of the usecase which tells why integration between vulnerability management solution and data analytics solution is needed.

Please note: There are other reasons as well because of which you can get this error.

Please refer the below URL for more details:
https://support.microsoft.com/en-us/office/excel-specifications-and-limits-1672b34d-7043-467e-8e27-269d656771c3

Happy Learning !!

hashtagvulnerabilitymanagement hashtagcybersecurity

Data Analytics - Excel Vs PowerBI

Microsoft Excel already had features like power query and power pivot, but these were not well known 10-12 years ago.


Then data analytics market started growing and solutions such as Tableau became popular.

Microsoft saw an opportunity to enter in data analytics market (they already were in a way because of Excel) and introduced a new tool named as PowerBI (Repackaged Microsoft Excel 😅). Table and model view constitutes the brain of PowerBI where all the processing happens.

Today, Power query is a key component of PowerBI. Microsoft's PowerBI has emerged as a competitor to existing data analytics solutions.

My learning - Adaptability is the key to survival.

These days most job roles related to data analytics require hands-on on PowerBI.

Happy Learning !!
hashtagmicrosoft hashtagmsexcel hashtagpowerBI

Vulnerability Management - (Rapid7) SQL Queries

Rapid 7 InsightVM does not allow few filters to access directly. One of such filters is solution ID. A typical solution ID for a Microsoft patch would look like 'msft-kbXXXXXXX-alphanumeric text'. As we all are aware, patch Tuesday for June month was on 11th. Now, if I want to know the assets missing May month Microsoft patches then I have no option to get this list using standard filters (Why would I want to know this? Because I want to improve my patch compliance).


In such scenarios, SQL queries come to our rescue. There is a specific report template in InsightVM which is based on SQL queries. I can write a SQL query to fetch the list of assets missing a specific KB.

You might be wondering, why can't we just apply filter on 'Vulnerability Solution' column (in report) and get the list? No, we cannot, because for one particular OS, the solution contains all the recently released KBs for all versions of Microsoft OSes. Does not make sense right? Neither to me, I am trying to find out the rationale though.

Please note: You should know the basic concepts of DBMS like fact and dimension table, variety of joins, primary and foreign keys etc. This is where Vulnerability Management overlaps with SQL. Surprised? Remember, we live in a small world :)

Please find the below URL:
https://discuss.rapid7.com/t/sql-query-listing-systems-that-require-specific-kb/27579/2

Happy Learning !!
hashtagvulnerabilitymanagement hashtagcybersecurity hashtagRapid7

Vulnerability Management - Understanding vulnerability posture

Understanding the vulnerability posture of an organisation at a basic level helps you drive remediation efforts. So, I don't know what t...