An active security analyst thoroughly explains the difficulty of the personal information protection professional certification exam, learning points, and "real value" that will be useful in practice. Why is there a need for people who can make decisions not only in the field but also in the field? This is a must-see exam experience for PMS and ISMS management personnel. |Colorkrew Security
Introducing effective phishing email training and specific sample examples. Based on actual attack trends such as HR, accounting, and IT notifications, we will explain practical training methods using Microsoft 365 Defender. |Colorkrew Security
Practical explanation of how to create a minimum CSIRT configuration that can be realized even by small and medium-sized enterprises, starting from role division, external collaboration, and initial maintenance points|Colorkrew Security
We will explain the purpose, scenario design, implementation procedure, and output organization of the ransomware attack exercise led by the CSIRT with specific examples to help strengthen our response capabilities|Colorkrew Security
Why do companies need CSIRT now? Against the backdrop of increasing attack sophistication and limitations in person-to-person response, the role, necessity, and relationship between CSIRT and management risk are explained in an easy-to-understand manner|Colorkrew Security
Explain specific steps and practical points for successful CSIRT construction. We will introduce system design that does not become a formality, role definition, training, and improvement in accordance with practical work. |Colorkrew Security
Experts explain in detail why Sysmon is included as standard in Windows and its specific impact on attack detection, SIEM analysis, and forensics|Colorkrew Security
The risk of internal information leakage has skyrocketed. According to an IPA study, trade secret leaks have increased more than sixfold in the past five years. Not only technical defenses are essential, but also measures against employee "motivations" and "justifications". In this article, we will explain the specific internal fraud measures that companies should take. |Colorkrew Security
With the ever-increasing number of vulnerabilities, it's impossible to keep up with everything. In this article, we will explain how to efficiently manage vulnerabilities with limited resources by utilizing EPSS (Exploit Prediction Scoring System), which predicts the likelihood of exploitation. We also introduce the differences from CVSS and tips for using it together. |Colorkrew Security
Explains the basics, importance, typical tools, and implementation procedures of DAST (Dynamic Application Security Testing) in an easy-to-understand manner. This is a must-see for those who want to efficiently combat vulnerabilities in web applications. |Colorkrew Security
Phishing attacks exploiting Microsoft 365's Direct Send are on the rise. In this article, we will explain the modus operandi, the latest trends, and specific countermeasures (using SPF/DKIM/DMARC/Defender) in an easy-to-understand manner. |Colorkrew Security
What is OSINT (Open Source Intelligence)? In this article, we will explain how to use it in cyberattacks, the risks, and OSINT countermeasures that companies should take. This is a must-read guide to help prevent information leakage and strengthen security. Colorkrew Security