Alexander V. Leonov
AVLEONOV Podcast
Vulnerability assessment, IT compliance management, security automation and other beautiful stuff.
Author
Alexander V. Leonov
Category
Podcast website
Latest episode
Mar 5, 2024
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Ep.19 - Microsoft Defender for Endpoint: Why You May Need It and How to Export Hosts via API in Python 19.02.2021 5:26
I recently tried Microsoft Defender for Endpoint. Not that free antivirus built into Windows, but an enterprise product. The thing is very promising. Even from the Vulnerability Management side. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.18 - Vulners Linux Audit API for Host Vulnerability Detection: Manual Auditing, Python Scripting and Licensing 11.02.2021 5:34
This episode will be about Vulners Linux Audit API, which allows you to detect vulnerabilities on a Linux host knowing only the OS version and installed packages. I had a similar post about this 4 years ago, but some details have changed, so I came back to this topic. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com bl...
Ep.17 - Vulristics Vulnerability Score, Automated Data Collection and Microsoft Patch Tuesdays Q4 2020 11.01.2021 9:49
In this episode I would like to make a status update of my Vulristics project. For those who don’t know, in this project I retrieve publicly available vulnerability data and analyze it to better understand the severity of these vulnerabilities and better prioritize them. Currently, it is mainly about Microsoft Patch Tuesday vulnerabilities, but I have plans to go further. Also in this episode I wa...
Ep.16 - MaxPatrol VM: An Ambitious Vision for Vulnerability Management Transformation 05.12.2020 12:51
In this episode, I would like to share my thoughts about the new Vulnerability Management product by Positive Technologies – MaxPatrol VM. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.15 - Nessus Essentials with offline registration and plugin updates 25.10.2020 3:07
In this episode, I would like to talk about Nessus Essentials and, in particular, how to register and update it without direct internet access. Nothing complicated, but there are a couple of pitfalls that I would like to share. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.14 - Microsoft Patch Tuesday September 2020: Zerologon and other exploits, RCEs in SharePoint and Exchange 30.09.2020 5:59
I would like to start this episode by talking about Microsoft vulnerabilities, which recently turned out to be much more serious than it seemed at first glance. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.13 - Microsoft Patch Tuesday August 2020: vulnerabilities with Detected Exploitation, useful for phishing and others 30.08.2020 4:01
This time I would like to review not only the vulnerabilities that were published in the last August Microsoft Patch Tuesday, but also the CVEs that were published on other, not Patch Tuesday, days. Of course, if there are any. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.12 - Microsoft Patch Tuesday July 2020: my new open source project Vulristics, DNS SIGRed, RDP Client and SharePoint 02.08.2020 8:39
I am doing this episode about July vulnerabilities already in August. Sorry for delay. I talk here about my new open source project Vulristics and review the PatchTruesday report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.11 - Barapass, Tsunami scanner, vulnerabilities in Windows DNS Server and SAP products, weird attack on Twitter 18.07.2020 7:20
This episode is based on posts from my Telegram channel avleonovcom, published in the last 2 weeks. So, if you use Telegram, please subscribe. I update it frequently. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.10 - Microsoft Patch Tuesday June 2020: The Bleeding Ghost of SMB 23.06.2020 5:31
This time, Microsoft addressed 129 vulnerabilities: 11 critical and 118 important. It's rather interesting month, but the focus is still mainly on SMB RCE vulnerabilities and the possible use of these vulnerabilities in malware attacks. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.
Ep.9 - How to list, create, update and delete Grafana dashboards via API 10.06.2020 4:12
I have been a Splunk guy for quite some time, 4 years or so. I have made several blog posts describing how to work with Splunk in automated manner. But after their decision to stop their business in Russia last year, including customer support and selling software and services, it was just a matter of time for me to start working with other dashboarding tools. For me, Grafana has become such a too...
Ep.8 - Add new features to Notepad++ using Python scripts: keyboard shortcut to insert current time 04.06.2020 2:23
It will be an off-topic, but I really wanted to share this with you. Adding your own tools in Notepad++ makes it much more fun!😊 I have to say, I spend a lot of time daily in Notepad++ text editor for Windows. I keep my “logbook” there. I record what I am doing now and what needs to be done. This allows me not to keep everything in my head and switch the context more efficiently. I can recommend...
Ep.7 - Microsoft Patch Tuesday May 2020: comments from VM vendors, promising stuff for phishing, troubles with SharePoint and lulz with Visual Studio 26.05.2020 5:30
Last time I complained that different VM vendors release completely different reports for Microsoft Patch Tuesday. This time I decided that it’s not a bug, but a feature. I upgraded my script to not only show vulnerabilities, but also show how these vulnerabilities were mentioned in the reports of various VM vendors (Tenable, Qualys, Rapid7 and ZDI). In my opinion, it seems pretty useful. Watch th...
Ep.6 - Anti-Phishing process with advanced phishing attacks simulation 05.05.2020 5:19
This time I want to write about the service of my friends from Antiphish. They call it “security awareness and employee behaviour management platform”. Simply put, they teach company employees how to detect and avoid phishing attacks. How can you protect your organization from phishing attacks? Educate people and constantly provoke them using emulated phishing attacks (some of these Antiphish atta...
Ep.5 - Microsoft Patch Tuesday April 2020: my classification script, confusing RCE in Adobe Type Manager and updates for older vulnerabilities 26.04.2020 7:32
Making the reviews of Microsoft Patch Tuesday vulnerabilities should be an easy task. All vulnerability data is publicly available. Even better, dozens of reviews have already been written. Just read them, combine and post. Right? Not really. In fact it is quite boring and annoying. That's why I created a script that takes Patch Tuesday CVE data from microsoft.com and visualizes it giving me helic...
Ep.4 - Microsoft Patch Tuesday March 2020: a new record was set, SMBv3 “Wormable” RCE and updates for February goldies 22.03.2020 5:47
Without a doubt, the hottest Microsoft vulnerability in March 2020 is the "Wormable" Remote Code Execution in SMB v3 CVE-2020-0796. The most commonly used names for this vulnerability are EternalDarkness, SMBGhost and CoronaBlue. There was a strange story of how it was disclosed. It seems like Microsoft accidentally mentioned it in their blog. Than they somehow found out that the patch for this vu...
Ep.3 - Parsing Nessus v2 XML reports with python 09.03.2020 2:21
This will be an update to my post from 2017. In that post, I presented a small python script that parses Nessus XML reports and returns a dictionary with all the data. It worked pretty well for me until the most recent moment when I needed to get compliance data from Nessus scan reports, and it failed. So I researched how this information is stored in a file, changed my script a bit, and now I wan...
Ep.2 - Forrester report for Rapid7: number juggling and an excellent overview of Vulnerability Management problems 24.02.2020 7:34
I recently read Forrester's 20-page report "The Total Economic Impact™ Of Rapid7 InsightVM". It is about the Cost Savings And Business Benefits that Vulnerability Management solution can bring to the organizations. In short, I didn't like everything related to money. It seems like juggling with numbers, useless and boring. But I really liked the quotes from customers who criticized existing Vulner...
Ep.1 - Is Vulnerability Management more about Vulnerabilities or Management? 11.02.2020 1:55
I’ve just read a nice article about Vulnerability Management in the Acribia blog (in Russian). Here is an extract with my comments. In the most cases Vulnerability Management is not about Vulnerabilities, but about Management. Just filtering the most critical vulnerabilities is not enough. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all li...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.