Michael Koerfer

14 Followers
24 Following
65 Posts
Human, anti-fascist, craftsman, whitehat, team science...
Pronoun:Human or they/them
Location:Hidden Meadow
Language:GER|EN
@Viss Wonderful šŸ˜‚

In my free time over the coming weeks and months, I’ll be working on a new version of my pentest dropboxes for IT and OT, and I’ll be turning the projects ā€œLemonā€ and ā€œMotionā€, which are still on paper, into reality.

And since people keep asking, I don’t have a sponsor and pay for everything out of my own pocket because that’s the only way I can stay creative and independent.

#Cybersecurity #OT #IT #Network #Hardwarehacking #SCADA #ICS #Research #OpenSource #foss

I just realized that so many people in the company simply don’t understand, or don’t want to understand, the Purdue Model!

The Purdue Model is a functional model. Its origins have nothing to do with cybersecurity. It was adopted for cybersecurity, but not as a ā€œzoneā€ model. Its purpose is to define the functional layers at which different methods and tools are used. You don’t simply use typical IT tools at the lower levels!

The DMZ was added much later, as the model evolved into a cybersecurity model. ā€œAdditional segmentation can be performed using the concept of zones and conduits described in ISA 62443.ā€ The layers are not intended to define a zone per se. Anyone who does not divide the layers into discrete security zones based on an analysis should not even attempt to work in this (OT) area!

Furthermore, individuals have the flexibility to design their own separation, segmentation, and zone configuration within each architecture, taking into account specific functional and application-related requirements. This approach enables the creation of a robust defense in depth, with the Purdue model serving as a guide while allowing for customization as needed, without rigid requirements.

I will not show these guys how the ISA62443 and the Purde model match. Because I expect that experts can do it and those who can't do it have to learn.

#OTSecurity #Cybersecurity #ICS #Purdue

@SRDas Wow, awesome, love it.

Trump regime now requires press to sign a document agreeing not to obtain or possess "unauthorized" information.

https://archive.ph/3GGyU

Anyone who agrees to this is not qualified to call himself or herself a journalist.

But I'm betting most Big Journalism orgs will go ahead and sign.

Cyber uppsi #tenable
@jerry thank you for your service.
@RoganDawes Jupp radxa looks pretty nice, I like it! The GL.inet and TP-Links will be training kits, for certain reasons.
A preview. One will become the current generation of dropboxes again and the other three will become the next generation with other (additional features).
#ICS #OT #hardwarehacking #diytools
@Insanitree Thx, have forgotten the link!