shellsharks, to blogging
@shellsharks@shellsharks.social avatar

Some (silly) stuff I posted over the weekend for

shellsharks,
@shellsharks@shellsharks.social avatar

@adamsdesk I just updated the note 😄. Though it doesn't seem like Bowser makes an appearance in either of those games. I'm sure i'm still missing some though…

adamsdesk,
@adamsdesk@fosstodon.org avatar

@shellsharks Fair point, I just meant a few were missing. 🙂

shellsharks, to infosec

A quick-look at a not-so-talked-about type of security assessment, the "Secure Configuration Review”. Here I introduce a quick methodology for conducting this sort of review and provide examples of configs/settings you might typically evaluate during the assessment. Consider using this assessment type in the context of triaging OWASP Top 10 "Security Misconfiguration" or CWE-16-type flaws.

https://shellsharks.com/secure-config-review

#mondayblogs #infosec #cybersecurity #owasp

shellsharks, to SmallWeb

In 2019 I started my blog but knew nothing of the or . Thanks in large part to the awesome community I was introduced to these concepts and have been diving in ever since, adding IndieWeb capabilities to my site and exploring the Indie World in its entirety. To help introduce others to the IndieWeb as well as catalog useful/interesting things I encounter I decided to write a post about it.

https://shellsharks.com/indieweb

That piece features a few cool lists like a list of webrings, blogrolls, IndieWeb search engines, indie site hosting providers and more!

To further help “score” my site on its “IndieWeb-ness”, I also wrote the following post about which includes my site’s score.

https://shellsharks.com/indiemark-score

shellsharks, to infosec
shellsharks, to lemmy

Wrote a “guide” to / last year after Reddit went full enshittify.

https://shellsharks.com/threadiversal-travel

If you’re interested in checking out a -based alternative to Reddit, come check out infosec.pub! It hosts a number of communities including one I’ve stood up for / !

https://infosec.pub/c/cybersecurity

shellsharks,

@AssaultPepper @ed209 Yeah I loved Reddit back when and honestly would still get a lot of use out of it if I were to drag myself back there. I’m attempting a principled stand and trying to build something useful on the Fediverse. So as Ty said, I’m attempting to dedicate myself to this side and turn it into something more. Some communities (e.g. cybersecurity) are better poised to achieve this in shorter order. Smaller, more niche communities def have a harder grind to do it.

ed209,

@shellsharks @AssaultPepper I 100% agree with the 'be the change'. But also that some of us still have to fall back to the Red Site to fill in the gaps. If it wasn't for r/Narcolepsy I would probably just delete my account.

shellsharks, to mastodon

I wrote this “guide” / thoughts on after re-joining the Fediverse in November 2022 (soon after some sort of Twitter-related crisis). This coincided with one of the larger migrations of folks to Mastodon.

https://shellsharks.com/mastodon

I have kept this post semi-updated with a lot of interesting Mastodon/Fediverse-related resources as well as information for the infosec community here.

shellsharks, to infosec

My compendium on the multitude of threat modeling methodologies out there. https://shellsharks.com/threat-modeling

It features quite a few frameworks currently! (With more planned for the future)

  • Microsoft Threat Modeling
  • PASTA
  • OCTAVE
  • Trike
  • LINDDUN
  • VAST
  • NIST SP 800-154
  • OWASP TMP
  • TARA
  • IDDIL/ATC
  • hTMM
  • QTMM

simontsui,

@shellsharks forgive my ignorance, but is MITRE ATT&CK considered threat modeling?

Edit: upon reading your compendium further, I think I didn't ask the right question.

shellsharks,

@simontsui It’s definitely something that could be helpful when performing threat modeling, especially when doing threat generation. I consider it one (of the many) “Attack Libraries” out there (https://shellsharks.com/threat-modeling#attack-libraries)

shellsharks, to blogging

I’ve really loved writing for and building my blog over the years, making it uniquely mine. I highly encourage everyone to have an Internet “home” of their own and even better, to publish their own writing/thoughts there! A few years ago I wrote about why I blog and why you should too!

https://shellsharks.com/you-should-blog

shellsharks, to infosec

If any (or prospective ) folks out there are looking to get into Vulnerability Management (), take a look at this “Bootcamp” I whipped up a few years ago. Cheers!

https://shellsharks.com/vm-bootcamp

shellsharks, to blogging

I’m a big #inboxzero fan, both as a means to generally declutter but also as a mechanism to fuel a productive to-do driven life. Check out the two-part series on Inbox Zero below if you’re interested!

Part I (the Art): https://shellsharks.com/inbox-zero

Part II (the Science): https://shellsharks.com/inbox-zero-part-2

#mondayblogs #blogging #indieweb #productivity #email

shellsharks, to random

My strategy and philosophy for syndicating content from my site.

https://shellsharks.com/syndication-strategy

lydiaschoch, to Fitness
@lydiaschoch@mastodon.social avatar
shellsharks, to infosec

For folks out there, what’s your routine/strategy for “staying current” in the field? I’ve written about my daily reading routine here for anyone interested.

https://shellsharks.com/notes/2023/11/06/keeping-current-in-infosec

mttaggart,

@shellsharks To help address this, I created a curated RSS feed of high-quality sources at https://intel.taggartinstitute.org. You can either read it straight, or subscribe to the main feed, or any of the sub categories!

I've heard from a lot of folks it becomes their first stop during their routine.

shellsharks,

@mttaggart I love what you’ve done with it. Even considered trying to do something similar since I’ve put so much effort in over the years compiling this list - https://shellsharks.com/infosec-blogs. Would definitely recommend this to others looking to pump up their regular infosec news-intake routine though.

shellsharks, to infosec

My latest post is on the subject of "Secure Configuration Review". It's my take on a very specific style of security assessment. Check it out!

https://shellsharks.com/secure-config-review

nolantium,

Ahoy @shellsharks
I’m a fan of your secure config review note.

shellsharks, to infosec

My ever-growing, gigantic list of blogs, with sections for indie, commercial, aggro and more!

https://shellsharks.com/infosec-blogs

The post currently features 3300+ unique infosec-related blogs/sites and has a downloadable, importable .opml file for use in your RSS aggregator of choice.

If you have a blog or site you want included in the list or know of one that is missing, feel free to let me know!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • cubers
  • magazineikmin
  • InstantRegret
  • thenastyranch
  • Durango
  • Youngstown
  • ngwrru68w68
  • slotface
  • everett
  • rosin
  • osvaldo12
  • kavyap
  • DreamBathrooms
  • megavids
  • mdbf
  • khanakhh
  • cisconetworking
  • GTA5RPClips
  • modclub
  • tacticalgear
  • ethstaker
  • tester
  • normalnudes
  • anitta
  • Leos
  • provamag3
  • lostlight
  • All magazines