Skip to content
Alfredo Pardo

a10o.net – Alfredo Pardo

Information Security, Software Engineering, and more…

Bluehost

python-for-infosec 

Analyzing Linux Authentication Files

September 9, 2020September 9, 2020 Supervisor authentication, infosec, jupyter, linux, matplotlib, python

When auditing Unix-based systems, particularly some Linux flavors, some requirements arise regarding the authentication files.These systems have two main files:

Read more
Docker Image Static Analysis Tools Comparison
devsecops 

Docker Image Security: Static Analysis Tool Comparison – Anchore Engine vs Clair vs Trivy

April 22, 2020September 17, 2022 Supervisor Anchore-Engine, CD, CI, Clair, DevSecOps, Docker, security, Tool, Trivy

In the Software Development Lifecycle (SDLC) and the DevSecOps world, there are different stages of security analysis. One of them

Read more
aws-security 

How to use Multifactor Authentication (MFA) in AWS from the command line

February 11, 2020September 9, 2020 Supervisor aws, cli, command line, linux, mfa, security

Nowadays, relying on password-only authentication for AWS accounts managing production-related workload is extremely dangerours. Multi-factor authentication (MFA) is a must

Read more
AWS Security Specialty
aws-security 

How I successfully passed the AWS Certified Security Specialty exam?

January 28, 2020September 9, 2020 Supervisor aws, certification, cloud, security, specialty

Last December (2019) I had the chance to successfully pass the AWS Certified Security Specialty exam. It took me between 2 and

Read more
Shifting Security Left
devsecops 

What does “Shifting Security Left” mean?

December 28, 2019September 9, 2020 Supervisor

Today, up to 90% of security breaches are caused by software vulnerabilities, additionally penetration testing activities commonly occur near the last

Read more
NIST Cybersecurity Framework
devsecops 

How to align your AWS Strategy with the NIST Cybersecurity Framework

December 28, 2019September 9, 2020 Supervisor

The NIST Cybersecurity Framework (CSF) is a non-profit endeavor based on best practices and using existing standards, originally intended for

Read more
DevSecOps
devsecops 

How to Successfully Onboard DevSecOps into your Business

December 28, 2019September 9, 2020 Supervisor

Security requirements are foundational for every business project and should be prioritized with the same importance than Software Development (Dev)

Read more
Application Security Program
devsecops 

Starting a solid Application Security Program

December 28, 2019September 9, 2020 Supervisor

Establishing a robust Application Security Program is not something that occurs overnight. It is a process that inevitably requires incorporating

Read more
Application Container Security
devsecops 

Application Container Security – Being Compliant from the Beginning

December 28, 2019September 9, 2020 Supervisor

In order to manage application infrastructure administrators rely on containers and tools that empower the DevOps team to package, deliver,

Read more
OVAL Results General Information
devsecops 

Getting Started with OpenSCAP

December 28, 2019September 9, 2020 Supervisor

The Security Content Automation Protocol, generally recognized as SCAP, enables automated vulnerability management, measurement and policy compliance evaluation of systems based on

Read more
  • ← Previous

Let's Get Social!

Recent Posts

  • Analyzing Linux Authentication Files
  • Docker Image Security: Static Analysis Tool Comparison – Anchore Engine vs Clair vs Trivy
  • How to use Multifactor Authentication (MFA) in AWS from the command line
  • How I successfully passed the AWS Certified Security Specialty exam?
  • What does “Shifting Security Left” mean?
Bluehost
Copyright © 2022 a10o.net – Alfredo Pardo. All rights reserved.
Theme: ColorMag by ThemeGrill. Powered by WordPress.