Poking Holes in the Firewall: Egress Testing With AllPorts.Exposed
ID: 826883f3-1b49-5a78-9a1e-e5431b592a19
STIX ID: report--826883f3-1b49-5a78-9a1e-e5431b592a19
Feed Name: Black Hills Infosec Blog
The post explains the importance of egress filtering and demonstrates how to quickly assess which outbound TCP ports are permitted from a network by scanning the allports.exposed host using simple PowerShell scripts. It shows examples for common port sets and recommends minimizing outbound exposure by allowing only necessary ports, implementing a web proxy, and forcing client web traffic through it to reduce command-and-control risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
