Planing the security for a public web application, any feedback?

I’ve been working long time on a web application, consisting of a large amount of data and many services and also communicating with external services.
Now that I’m very happy with the functionality and reliability, before moving from an … Continue reading Planing the security for a public web application, any feedback?

How to secure a SQL Server database (windows auth) against a network windows user (penetration test)

I need to prepare my web app for a penetration test. The scenario is: If one of our windows users is hacked, what can the hacker do to my app and my database?
I have a virtual machine on our server, which holds a SQL Server Express and a d… Continue reading How to secure a SQL Server database (windows auth) against a network windows user (penetration test)

How to find the process that is running PowerShell commands that appear in Windows Defender

On one of our Windows Datacenter 2016, there’s an alert that a trojan is trying to install :

The following PowerShell commands are trying to execute at seemingly random hours of the day (always during working hours, one to two times a day… Continue reading How to find the process that is running PowerShell commands that appear in Windows Defender