14
OWASP Mantra-OS Because the world is cruel

OWASP Mantra-OS

  • Upload
    ikia

  • View
    51

  • Download
    0

Embed Size (px)

DESCRIPTION

OWASP Mantra-OS. Because the world is cruel. About Me. Attended United Stated Air Force Institute of Technology Defense Acquisition University Platform Security Engineer at. What is Mantra-OS?. - PowerPoint PPT Presentation

Citation preview

Page 1: OWASP Mantra-OS

OWASP Mantra-OSBecause the world is cruel

Page 2: OWASP Mantra-OS

About Me

• Attended United Stated Air Force Institute of Technology

• Defense Acquisition University

• Platform Security Engineer at

Page 3: OWASP Mantra-OS

What is Mantra-OS?

• Mantra-OS is a virtualized attack platform designed around Mantra Security toolkit and OWASP WTE repository.

Page 4: OWASP Mantra-OS

What was Mantra-OS developed for?

• SCAP testing and professional pen-testing environment optimized for virtual environments. Such as vSphere, XenDesketop, OpenStack, oVirt.

• Installation media iso and deployable ovf/ova.

Page 5: OWASP Mantra-OS

Mantra-OS & HyTrust

• Mantra-OS was implemented into HyTrust QA cycle

• It is used for SCAP testing and Vulnerability verification testing.

• Is deployed through vCenter.

Page 6: OWASP Mantra-OS

Mantra-OS Virtualization and Security Kernel

• GrSecurity Kernel patch and OpenVZ Kernel patch.

• Ganeti for Virtual Cluster

• KVM implementation as secondary layer of virtualization.

Page 7: OWASP Mantra-OS

Mantra-OSContainers and

Sandboxing

• OpenVZ is used as container controller and lxc with arkose d-bus hook to sandbox desktop.

• Libvirtd is used as a job handler for virtualization with glib hook.

Page 8: OWASP Mantra-OS

Mantra-OSVirtual Core

Page 9: OWASP Mantra-OS

Mantra-OSEnhanced Security

• IDS protection with suricata

• Artillery and honeyd for IPS protection

• Container based sandboxing

• AppArmor, SElinux

Page 10: OWASP Mantra-OS

Mantra-OSSecurity Audit Tools

• OWASP Zap

• Burp

• Maltego

• Metasploit & Armitage

• Zenmap

Page 11: OWASP Mantra-OS

Mantra-OSPacket Capture

• Ettercap

• Wireshark

Page 12: OWASP Mantra-OS

Mantra-OSWeb Application

Scanners

• Skipfish

• Nikto

• Gruyere

Page 13: OWASP Mantra-OS

Mantra-OSSQL Injection

• Sqlbrute

• Sqlmap

• Sqlmap intergration with Zap

Page 14: OWASP Mantra-OS

Mantra-OSIntel Collection

• Maltego