It explains in an easy-to-understand manner from the basics of MITRE ATT&CK to its structure, how to view the matrix, and how to use it in the field. This is a practical guide to help you analyze gaps and strengthen countermeasures|Colorkrew Security
SOC engineers explain what MITRE is and how CVEs and MITRE ATT&CK are used in security operations in an easy-to-understand manner. Basic knowledge for beginners to help you understand the overall picture of attacks and strengthen defenses|Colorkrew Security
Is Multi-Factor Authentication (MFA) Really Secure? A thorough explanation of the limitations of SMS authentication and authentication apps, as well as the vulnerabilities targeted by attackers. We will introduce the advancements and challenges of next-generation authentication technologies such as Passkey, as well as the security measures that companies should take now. |Colorkrew Security
During the summer vacation, shadow IT increased rapidly due to remote work and reduced support systems. We will explain measures to prevent the risk of data leakage and malware infection in specific scenarios and practical methods. |Colorkrew Security
Orca Security is the next generation of CNAPPS that protect the entire cloud without agents. From attack path analysis, AI-based rapid response, and compliance response, we will explain cloud security operations that solve traditional challenges. |Colorkrew Security
Explain the basic concepts and mechanisms of IDS (Intrusion Detection System) and IPS (Intrusion Prevention System), and the differences between Firewall and WAF. We will also introduce the reasons why companies should introduce it and operational points. Colorkrew Security Blog
What is a CNAPP (Cloud-Native Application Protection Platform)? We will explain in detail the full scope of integrated security solutions that protect complex cloud environments, including key functions, implementation benefits, and selection points. Colorkrew Security Blog
Utilize Azure WAF's Bot Protection feature to protect your website from malicious bots and explain specific setup steps and practical measures. This is a must-see for businesses considering implementing or reviewing a WAF. |Colorkrew Security
Explain basic security measures for building robust web applications that do not rely on WAF. We will introduce in detail how to deal with major vulnerabilities such as SQL injection, XSS, and CSRF, as well as points for session management, input validation, and authentication enhancement. |Colorkrew Security
Explain in detail the typical examples and causes of false positives that occur in web application firewalls (WAFs). Learn about false positive patterns that occur in input forms, search queries, and contact forms, effective tuning methods, and operational improvements using SOC services. Colorkrew Security Blog
To combat modern cyber threats, a defense-in-depth strategy that combines WAF and Firewall is essential for combating modern cyber threats. In this article, we'll take a closer look at the best security architectures for comprehensive protection of a company's digital assets and how to implement them. Strengthen your network and improve your defenses against cyberattacks with practical advice from security experts. |Colorkrew Security
This section provides a detailed explanation of the basic concepts and roles of WAF (Web Application Firewall). Introduce a defense-in-depth approach to protecting web applications, best practices for deployment and operation, and effective management methods using SOC services. We provide practical advice for companies considering the use of WAF in cloud environments. |Colorkrew Security