Latest release

SAFETAG: Advanced Threats

@joncamfield joncamfield released this May 4, 2018 · 68 commits to master since this release

This release includes the following large changes:

  • Responding to Advanced Threats -- a new method and activities to detect and response to malware and for working with high-risk organizations, as well as improved guidance on conducting technical threat research. See https://safetag.org/2018/05/04/Advanced_Threats.html for details.

  • Remote SAFETAG Audits -- improvements and guidance in conducting remote assessments when travel to the site is impractical, unsafe, or there are multiple offices to audit with limited travel availability. This includes technical and facilitated activity modifications and options for the auditor to direct depending on organizational capacity, as well as completely new activities. See https://safetag.org/2017/08/31/Remote_Audits.html for details.

  • New SAFETAG Playlist: Minimal Viable Audit -- a SAFETAG "playlist" focused on essential activities when facing a constrained timeline, and to use as a core to add custom activities on to. Build this playlist using index.mva.md , or view the attached MVA PDF.

  • Network and Vulnerability Scanning Improvements Better guidance and tool recommendations for website footprinting/auditing, and improved documentation for scanning for vulnerabilities.

  • OSINT / Recon Improvements -- Additional exercises to conduct research and identify the online footprint and potential points of vulnerability for an organization.

  • Core and Structural Improvements -- Creation of a Code of Conduct and a Contribution guide (see #299). Normalization of files/structure and removal of symlinks to better support Content as Code inclusion. Activities with multiple, parallel/duplicative options are now presented as variants within the activity's instructions.

Updated SAFETAG Guide

@joncamfield joncamfield released this Sep 5, 2017 · 433 commits to master since this release

This release is a roll-up of edits to the SAFETAG English guide, incorporating both stylistic/editorial changes as well as new and updated activities.

SAFETAG-FullGuide_Sep2017.pdf

SAFETAG (June 2015)

@joncamfield joncamfield released this Jun 30, 2015 · 538 commits to master since this release

This release fixes a number of content and formatting issues, as well as includes a translation of the core SAFETAG materials into Spanish. The document creation scripts have been separated into a new repository, making this focused on the content of SAFETAG.

SAFETAG (June 2015a)

@joncamfield joncamfield released this Jun 25, 2015 · 578 commits to master since this release

This release is in preparation for SAFETAG translation work and is for reference.

Pre-release

SAFETAG April 2015

@joncamfield joncamfield released this Apr 29, 2015 · 634 commits to master since this release

This release is a first step towards larger changes to the SAFETAG framework towards a much more abstracted process. The "guides" are now "methods" and the "examples" have been moved to a separate directory, "exercises", enabling them to be cross-linked and more easily referenced from the methods and curricula content.

Pre-release

SAFETAG (Jan 2015)

@joncamfield joncamfield released this Apr 29, 2015 · 737 commits to master since this release

This is the slightly updated SAFETAG content and curricula based on the first trainings and independent review inputs

Pre-release

SAFETAG 2014

@joncamfield joncamfield released this Apr 29, 2015 · 634 commits to master since this release

The rebooted SAFETAG content used as the core of the SAFETAG training in 2014 and early 2015.