<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Gregor Debus on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/gregor-debus/</link>
    <description>Recent content in Gregor Debus on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 19 Mar 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/gregor-debus/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Assessing Endpoint Protection: Our Approach to EDR/XDR and Supplements Evaluation</title>
      <link>https://insinuator.net/2026/03/assessing-endpoint-protection-our-approach-to-edr/xdr-and-supplements-evaluation/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/assessing-endpoint-protection-our-approach-to-edr/xdr-and-supplements-evaluation/</guid>
      <description>&lt;p&gt;There is a growing landscape of security products promising to protect an&#xA;organization’s IT infrastructure from attacks. Solutions referred to as EDR, and&#xA;sometimes also as XDR, are designed to protect endpoints from all malicious&#xA;activity. The ever-increasing cases of breaches and the associated costs,&#xA;especially in the realm of&#xA;&lt;a href=&#34;https://www.totalassure.com/blog/ransomware-statistics-by-year-2025-comprehensive-report&#34;&gt;ransomware attacks&lt;/a&gt;,&#xA;raise the question of whether there is more that can be done to add an&#xA;additional layer to traditional endpoint protection concepts. That is why a&#xA;customer of ours commissioned us to evaluate whether EDR supplementing solutions&#xA;provide extended protection against ever-evolving threats, as well as to shine a&#xA;light on the performance overheads those solutions might introduce.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2024-11035: Minor Security Issues in VMware Carbon Black Cloud</title>
      <link>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</link>
      <pubDate>Mon, 31 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</guid>
      <description>&lt;p&gt;We recently conducted a security assessment of VMware Carbon Black Cloud, a&#xA;unified SaaS solution that integrates endpoint detection and response (EDR),&#xA;anti-virus, and vulnerability management capabilities. As part of our&#xA;evaluation, we tested the solution’s ability to detect and prevent malicious&#xA;activity on Windows and Linux systems. Our analysis focused on the Carbon Black&#xA;agents for these platforms, and although we did not identify any critical&#xA;vulnerabilities, we want to share some of the findings in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Select * from OpenStack - A Steampipe Plugin for OpenStack</title>
      <link>https://insinuator.net/2023/08/select-from-openstack-a-steampipe-plugin-for-openstack/</link>
      <pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/08/select-from-openstack-a-steampipe-plugin-for-openstack/</guid>
      <description>&lt;p&gt;Although, more and more companies start to move their IT-Infrastructure from&#xA;on-premise to public cloud solutions like Amazon Web Services (AWS) and&#xA;Microsoft Azure, public cloud providers are not an option for every&#xA;organization. This is where private cloud platforms come into play as they give&#xA;organizations direct control over their information, can be more energy&#xA;efficient than other on-premise hosting solutions, and offer companies the&#xA;possibility to manage their data centers efficiently.&#xA;&lt;a href=&#34;https://www.openstack.org/&#34;&gt;OpenStack&lt;/a&gt; is a widely deployed, open-source&#xA;private cloud platform many companies and universities use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pentesting the ELK Stack</title>
      <link>https://insinuator.net/2021/01/pentesting-the-elk-stack/</link>
      <pubDate>Wed, 13 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/pentesting-the-elk-stack/</guid>
      <description>&lt;p&gt;With this blog post, I will provide information on how to proceed when testing&#xA;ELK Stack landscapes. Information regarding the exploitation of the ELK Stack is&#xA;very rare on the internet. Therefore, following article aims to provide you with&#xA;some approaches that can be useful during a penetration test.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;All information below were collected during a research project and there is no&#xA;claim for completeness. The guide focuses on ELK Stack deployments for Linux&#xA;machines. Further, this article does not include information for identifying&#xA;misconfigurations in a white-box configuration audit.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
