Cody has been working on setting up the SVN environment using SourceForge and Google Code
Darryl has been deep in the data analysis and data modeling
Adrien has modified the python scripts and is improving the performance of the scripts.
Cody has been working on setting up the SVN environment using SourceForge and Google Code
Darryl has been deep in the data analysis and data modeling
Adrien has modified the python scripts and is improving the performance of the scripts.
Cody and Adrien discussed the content for the Wiki, and discussed the plans to move to SourceForge.
Cody submitted the rough draft for the GVWN Gold paper.
Adrien is teaching the SANS Sec560 next week in Toronto.
Cody has completed the alpha code for the PowerShell AD ACL Parser for his GWCN Gold paper. He plans on putting the final touches on the script and completing the paper over the next week.
Darryl has:
Adrien has been working on fine tuning his python scripts.
Cody has made great headway with the powershell script framework and can now can control the XML data formatting.
Darryl has continued to make headway at data modeling from the initial data set Adrien has supplied.
Adrien has recently presented SecTor on the project.
OSSAMS founding member Adrien de Beaupré will be presenting on his work with OSSAMS project at SecTor 2011 today at 11:30 AM in Track 4 (104D). In celebration of SecTor OSSAMS is releasing Alpha code developed by Adrien. The code download can be found on the new Alpha Code page. Adrien’s presentation can also be downloaded from the Presentations page.
OSSAMS, Security Testing Automation and Reporting - Adrien de Beaupré
This presentation will discuss the options available to automate the conduct of vulnerability assessment and penetration testing engagements, and the reporting processes. The most important parts of running a security test are following a consistent methodology, utilizing the appropriate tools and their configuration, data management, getting accurate results, manual validation, and standardized reporting. The goal being to streamline and automate the parts of the process, where possible, and improved efficiency.
Aug 24 – Cody, Adrien, & Darryl
Updates
As information security professionals, we conduct security assessments for companies. One of the biggest problems we have is after all the data is collected, how can we correlate the data accurately. So we decided to start a project to solve this problem, and we are calling it Open Source Security Assessment Management System (OSSAMS). OSSAMS is a framework for putting configuration files, security scan data files (like Nessus), and other data collected, during a security assessment or penetration test, into a RDBMS.
The framework is going to be designed in a fashion similar to Metasploit, SNORT, or other systems that allow the security community to create plugins for new tasks as needed. The primary goal of OSSAMS is to normalize the data, there by allowing the security professional to better assess the current state of security for an organization.
The founding OSSAMS team is comprise of Cody Dumont, Adrien de Beaupre, and Darryl Williams. Cody is a Sr. Security Consultant for the NWN STAR team (www.nwnstar.com), Adrien is a Security Tester in Canada with Intru-Shun.Ca Inc., and Darryl Williams is an expert in database design and SDLC architecture.