Enterprise Softproducts - Mellemmenneskelige IT sikkerhed.

//WHOAMI

Mit navn er Mark Steenberg.

Jeg har arbejdet med IT sikkerhed gennem en del år efterhånden. Jeg har gennem min karrierer arbejdet med alt fra IR og SOC til pentesting og purple teaming. De sidste år har jeg specialiseret mig inden for den offensive del af faget. Hvis jeg skulle beskrive hvad jeg er bedst til, så er det nok at perspektivere teknisk risiko til hvordan den vil påvirke virksomhedens drift.

[CERTIFICERINGER]

Gennem min karrierer har jeg efterhånden en del certificeringer inden for cyber sikkerhed. De spænder fra red teaming til ncident response og hardening af netværk og infrastruktur.

[Hover for more details on each]

OFFENSIVE SECURITY

  • HTB Pro Labs:Various simulated enterprise environments with focus on initial access and post exploitation in multi-domain environments, containing defensive measures like network segmentation, AV, PowerShell Just Enough Administration (JEA), etc.
    • APTLabs
    • Cybernetics
    • RastaLabs
    • Offshore
    • Dante
    • Zephyr
  • eLearnSecurity Certified Penetration Tester eXtreme (eCPTXv2)Exploitation of multi-domain AD forest including ACL abuse, cross-domain lateral movement, MSSQL abuse, relay attacks, etc.
  • eLearnSecurity Certified eXploit Developer (eCXD)Exploitation of buffer overflows via traditional buffer overflows, ROP and SROP chains, on both Linux and Windows.
  • eLearnSecurity Certified Professional Penetration Tester (eCPPTv2)Intermediate pentest certification focusing on exploitation of vulnerabilities and cross-network lateral movement.
  • eLearnSecurity Mobile Application Penetration Tester (eMAPT)Cert focusing on the assessment and exploitation of Android applications.
  • eLearnSecurity Web Application Penetration Tester eXtreme (eWPTXv2)Advanced web app pentest cert. focusing on advanced techniques and exploitation.
  • eLearnSecurity Web Application Penetration Tester (eWPT)Web app pentest cert. focusing on OWASP top 10
  • eLearnSecurity Junior Penetration Tester (eJPT)Entry level offensive security certification
  • Certified Red Team Professional (CRTP)AD exploitaiton and lateral movement
  • Certified Azure Red Team Professional (CARTP) Exploitation of Azure cloud environment and lateral movement between cloud and on-prem.

DFIR

  • GIAC Certified Forensic Analyst (GCFA)Perform incident response investigations and analysis on a compromised network.
  • eLearnSecurity Certified Threat Hunting Professional (eCTHPv2)Conduct threat hunting activities, including SOC analysis, network investigations, and in-memory forensics, also use tools to create IOCs and detection rules for the identified IOCs.
  • eLearnSecurity Certified Incident Responder (eCIR)Certification showing capabilities for analyzing network and host-based incidents using Splunk and network traffic (.pcap).
  • eLearnSecurity Certified Digital Forensics Professional (eCDFP)Perform digital forensics on windows laptop.

DEFENSIVE SECURITY AND INFRA.

  • eLearnSecurity Certified Reverse Engineer (eCRE)Reverse engineer compiled binaries (unmanaged) and analyze ASM using Immunity Debugger.
  • eLearnSecurity Certified Malware Analysis Professional (eCMAPv1)Use IDA and other modern reverse engineering tools to analyze and understand complex malware.
  • eLearnSecurity Web Defence Professional (eWDP)Perform a penetration test of an PHP app, then harden the applicaiton using a custom MOD firewall to deny previous attacks, and then remediate all vulnerabilities in the code itself such as implementing RBAC and input/output sanitization.
  • eLearnSecurity Network Defense Professional (eNDP)Harden a modern network and servers, including configuration and setup of site-to-site VPN, creation and provisioning of GPOs, and AD hardening.
  • Azure Fundamentals (AZ-900)General introduction to the azure ecosystem.
[SECURITY RESEARCH]
  • CVE-2021-44151 - Session hijacking via brute forcing (Reprise RLM 14.2)
  • CVE-2021-44152 - Arbitrary unauthenticated password change (Reprise RLM 14.2)
  • CVE-2021-44153 - Authenticated RCE (Reprise RLM 14.2)
  • CVE-2021-44154 - Buffer Overflow (Reprise RLM 14.2)
  • CVE-2021-44155 - User enumeration (Reprise RLM 14.2)
[SECURITY RESEARCH]
[PRESENTATIONS]