Register and share your invite link to earn from video plays and referrals.

Zoë
@zoecyber001
Red teamer working in the GRC world
438 Following    3.8K Followers
> be me > first time going onsite for a high-assurance financial & physical security audit > logical side is heavy: HSMs, cryptographic keys, air-gapped zones, Zero Trust > time to walk the floor for the physical compliance checklist > "Are badge readers installed?" [x] Yes > "Are secure doors locked?" [x] Yes > "Are visitor logs kept?" [x] Yes > Everything checked out. 100% compliant on paper. > but my IoT/hardware hacker brain couldn't rest > walking the floor, I'm not seeing checkboxes, I'm seeing attack surface > standard compliance will only asks if a lock exists or a badge is issued > it never asks how that hardware behaves under 45 seconds of someone actually trying to get past it > a facility can pass every line on the checklist and still fold to a ₦15,000 RF cloner or a door left a few mm out of true > compliance would only measures whether the hardware exists on paper > so I've been spending my evenings building APCAF - Adversarial Physical Control Assessment Framework > MITRE ATT&CK for physical & hardware-layer security > quick, non-invasive site checks. Check out what I'm building: 🔗
Show more
How does process hollowing work?