
Explains the pitfall of security operation, "I take logs but don't notice the attack". From the perspective of an infrastructure engineer, we will introduce five steps to transform logs from mere storage objects into "defensive weapons" using correlation analysis and automatic detection. |Colorkrew Security

Based on the vulnerabilities and botnet risks hidden in IoT devices, we will explain the IoT security measures that organizations should implement. Easy-to-understand practical steps such as network isolation, access control, vulnerability management, and monitoring system|Colorkrew Security

Systematically explains ransomware attack methods, damage risks, and multi-layered defense practices. Introducing a realistic defense model that includes EDR, SIEM, and backup strategies|Colorkrew Security

With the ever-increasing number of vulnerabilities, it's impossible to keep up with everything. In this article, we will explain how to efficiently manage vulnerabilities with limited resources by utilizing EPSS (Exploit Prediction Scoring System), which predicts the likelihood of exploitation. We also introduce the differences from CVSS and tips for using it together. |Colorkrew Security

Should all dependent library vulnerabilities be addressed? Learn how GitHub Dependabot and risk-based management can help you focus on critical vulnerabilities. |Colorkrew Security

In response to the new ISMS standard, we will introduce practical examples for building threat intelligence. Detailed explanation of effective security measures such as IPA and security news auto-posting, dark web monitoring, vulnerability management, etc. This article is full of tips to help companies strengthen their information security. Colorkrew Security Blog

Based on the 2022 revisions of the ISO27001, we will explain in detail how to respond to the new ISMS standard. It provides a step-by-step introduction to the changes to Annex A and the steps to introduce new management measures, covering important points that certified companies should be aware of. A practical guide to strengthening your security strategy. Colorkrew Security Blog