Skip to content
Cyberside

Blog

Notatki operatorskie

Assessment · OSINT · Hardening · AEGIS

RSS

Assessment

How to prepare for an offensive assessment — CTO checklist

RoE, attestation, scope and deliverables — before anyone goes active.

2026-07-20

OSINT

OSINT in practice — what can be found about your company in 15 minutes

Passive first: DNS, CT, archives, lookalikes. Active only after.

2026-07-18

Hardening

Hardening nginx in 2026 — 12 steps to SSL Labs A+

TLS 1.2/1.3, HSTS, CSP, server_tokens, COOP/CORP — operator checklist.

2026-07-12

AEGIS

Dependency confusion — why your npm install can be dangerous

Private package names vs public registry. Detection without exploit theatre.

2026-07-08

Assessment

RoE and attestation — the minimum before going active

Without written scope and a system owner there is no engagement — only risk.

2026-07-05

Hardening

TLS and security headers — operator checklist

HSTS, CSP, COOP/CORP, server_tokens — what to check in 10 minutes.

2026-07-01

OSINT

Lookalike domains — catching brand impersonation

Homoglyphs, typos, CT monitoring — before a client clicks phishing.

2026-06-24

AEGIS

Evidence, not theatre — how to report an assessment

Finding = reproduction + impact + remediation. A screenshot without context is noise.

2026-06-18

OSINT

Passive first — recon order under RoE

CT, DNS, archives, lookalikes — before anyone starts an active probe.

2026-06-12

Hardening

CSP with nonce in 2026 — no unsafe-inline on script

strict-dynamic + nonce is the new baseline. Inline style is a separate decision.

2026-06-08

AEGIS

STS missions — queue discipline and evidence

Every mission: owner, RoE, status, artifacts. No orphan jobs.

2026-06-02

Assessment

Brand presence and security — one contract

A site without TLS and CSP is not “design done”. Assessment and delivery under one bar.

2026-05-28

Porozmawiajmy o Twoim projekcie