# Incognito Lab > Cybersecurity blog posts, articles, and insights from Incognito Lab — covering penetration testing, red teaming, OT security, and more. ## Documentation Sets - [Incognito Lab — Full Documentation](https://incognitolab.com/llms-full.txt): Complete cybersecurity content from Incognito Lab including blog posts, service descriptions, and product information. ## Blog Posts Cybersecurity articles, news, and ICL logbook entries - [007 Skyfall : the untold story](https://incognitolab.com/raw/blogs/007-skyfall-the-untold-story.md): สวัสดีปีใหม่ สำหรับในปี 2012 ที่ผ่านมาทางทีมงาน Incognito Lab ของเรา ขอขอบคุณทุก ๆ ท่านที่คอยติดตามเรา และ ส่งเมล์เข้ามาให้กำลังใจทีมงานอย่างมากครับ - [Introduction to Active Directory Certificate Services (AD CS)](https://incognitolab.com/raw/blogs/2026-01-05-introduction-to-adcs.md): ไม่ว่ากาลเวลาจะผันเปลี่ยนไปสักเท่าไร การโจมตีองค์กรต่าง ๆ เหล่า attacker มักจะมีเป้าหมายในการโจมตีและยึดครองระบบ Active Directory (AD) โดยอาศัยเทคนิคมากมายในการขยายผลและยกระดับสิทธิของตัวเองให้สามารถควบคุมทั้งองค์กรให้ได้ - [Cyber Security Checklist on Digital House](https://incognitolab.com/raw/blogs/2026-01-20-cyber-security-checklist-ep1.md): คนเรามักจะเลือกล็อกประตูบ้านเพื่อความปลอดภัย.. แล้วบ้านของคุณในโลก 'ดิจิทัล' มีการล็อกที่แน่นหนาแล้วหรือยัง? - [Snowflake Breach 2024: เมื่อ Infostealer กลายเป็นภัยเงียบที่ EDR มองไม่เห็น](https://incognitolab.com/raw/blogs/2026-01-20-what-is-infostealer-log-redalert-snowflake-2024.md): เจาะลึกภัยร้าย Infostealer และ Stealer Log ผ่านกรณีศึกษา Snowflake Breach 2024 ทำไมเครื่อง 3rd Party ถึงเป็นจุดอ่อนสำคัญ? พร้อมแนะนำ RedAlert บริการเฝ้าระวังเชิงรุกจาก Incognito Lab เพื่อปิดช่องโหว่ที่ EDR มองไม่เห็น - [Why EDR Isn’t Enough: A Guide to Monitoring Infostealer Logs with RedAlert](https://incognitolab.com/raw/blogs/2026-03-09-stop-infostealer-leaks-with-redalert.md): Hackers no longer break in—they log in. Discover how RedAlert provides visibility into leaked credentials from unmanaged devices and the dark web, closing the security gaps that traditional EDR and Antivirus miss. - [จาก personal assistance (openclaw) สู่ backdoor เมื่อ telegram bot ที่ deploy ไว้ไม่ใช่มีแค่เราที่ใช้ได้](https://incognitolab.com/raw/blogs/2026-03-11-openclaw-personal-assistant-to-backdoor.md): รีวิวความเสี่ยงเมื่อ AI Agent อย่าง OpenClaw ถูกเชื่อมกับ Telegram โดยไม่จำกัดสิทธิ์ เปิดทางให้ใครก็เข้ามาสั่งรันสคริปต์ได้ - [SCADA ยังรันได้อยู่ ทำไมต้องต้องอัป OS? ความเสี่ยงที่มักถูกวางไว้ท้ายสุด](https://incognitolab.com/raw/blogs/2026-03-19-1-legacy-windows-risks-in-scada-ot.md): โรงงานจำนวนมากยังต้องใช้ Windows รุ่นเก่ากับระบบ SCADA และ HMI เพราะซอฟต์แวร์ไม่รองรับ OS ใหม่ แม้ระบบจะยังทำงานได้ แต่ช่องโหว่ที่ไม่ได้รับการแก้ไขและการติด malware จาก USB หรือ network กลายเป็นความเสี่ยงสำคัญ บทความนี้อธิบายเหตุผลที่โรงงานเลิกใช้ OS เก่าไม่ได้ และแนวทางลดความเสี่ยงด้วย compensating controls และการวาง roadmap ระยะยาว - [Privilege Escalation - Potatoes Part 1](https://incognitolab.com/raw/blogs/2026-03-19-privilege-escalation-potatoes-part-1.md): บทความนี้จะอธิบายขั้นตอนการทำงานของเหล่า Potatoes หนึ่งในเครื่องมือที่ใช้งานในการยกระดับสิทธิบน Windows ก็คือเหล่าตระกูล "Potatoes" ซึ่งเป็นกลุ่มเครื่องมือที่ใช้ช่องโหว่ทางเทคนิคร่วมกับ User ที่มีสิทธิ SeImpersonatePrivilege เพื่อเปลี่ยนจากสิทธิ์ User ทั่วไปให้กลายเป็นสิทธิ์ผู้ใช้งานระดับสูงของเครื่องได้ในทันที - [Security Hardening รากฐานความปลอดภัยของระบบ ที่ทุกคนควรใส่ใจ](https://incognitolab.com/raw/blogs/2026-06-26-security-hardening-for-everyone.md): ระบบปฏิบัติการ (OS) หรือ Server ที่ถูกติดตั้งมาในตอนแรก มักจะมีฟังก์ชันการทำงาน, Services หรือ Ports ต่าง ๆ เปิดทิ้งไว้เป็นค่าเริ่มต้นเพื่อความสะดวกในการใช้งาน กระบวนการทำ Security Hardening จึงเข้ามาจัดการอุดหรือแก้ไขปัญหาเหล่านี้ผ่านเทคนิคสำคัญ - [เมื่อ Scammer ไม่ได้หลอกแค่เหยื่อ !!!: เบื้องหลังเทคนิคที่ใช้หลอกคน หลอก Google และหลอกระบบตรวจจับ](https://incognitolab.com/raw/blogs/2026-06-28-scammer-technique-2026.md): ในอดีต การหลอกลวงออนไลน์มักอาศัยอีเมลปลอม SMS ปลอม หรือเว็บไซต์ที่ เลียนแบบองค์กรที่มีชื่อเสียง แต่ในปัจจุบัน… - [Kerberos Delegation Attacks (Part 1): Overview & Unconstrained Delegation Abuse](https://incognitolab.com/raw/blogs/2026-06-29-ker-delg-pt1.md): Kerberos Delegation เป็นกระบวนการหรือการทำงานที่ถูกสร้างขึ้นเพื่อช่วยในการแก้ปัญหาในระดับ Enterprise ซึ่งกระบวนการข้างต้นมักพบในการใช้งานที่ต้องมีการยืนยันตัวตนแบบหลายต่อ (Multi-tier applications) แต่ในมุมมองของด้านความปลอดภัย การทำงานของ kerberos delegation ได้มีการพูดถึงการใช้งาน trust relationship ที่ทรงพลังและให้สิทธิ์ที่ค่อนข้างมาก ซึ่งเป็นจุดที่ผู้ไม่ประสงค์ดีหรือ attacker จะให้ความสนใจเป็นพิเศษ โดยหากมีการตั้งค่าที่ไม่ถูกต้อง kerberos delegation จะทำให้ attacker สามารถทำ action ต่าง ๆ ได้เช่น ปลอมเป็นผู้ใช้งานที่มีการตั้งค่าให้ทำ Delegation หรือ ทำกระบวนการ lateral movement ไปยังส่วนต่าง ๆ ของระบบ - [VA/Pentest Service การลงทุนที่คุ้มค่าสำหรับธุรกิจในยุคดิจิทัล](https://incognitolab.com/raw/blogs/2026-07-06-va-pentest-service.md): ในทุกวันที่ยุคดิจิทัลเคลื่อนไปข้างหน้าอย่างไม่รีรอและการโจมตีทางไซเบอร์เพิ่มมากขึ้นในทุกวัน อย่าปล่อยให้แฮกเกอร์เป็นผู้พบช่องโหว่บนระบบของคุณก่อนมันจะสายเกินแก้! - [Wiper Attack Hospital](https://incognitolab.com/raw/blogs/2026-07-08-wiper-attack-hospital.md): เมื่อวันที่ 11 มีนาคม 2569 กลุ่มแฮกเกอร์ Handala ซึ่งเชื่อมโยงกับรัฐบาลอิหร่าน ได้โจมตี บริษัท Stryker ซึ่งเป็นบริษัทผลิตอุปกรณ์การแพทย์ระดับโลกสัญชาติสหรัฐฯ Wiper Attack - [Post-Quantum Cryptography คืออะไรและทำไมเราต้องเปลี่ยน](https://incognitolab.com/raw/blogs/2026-07-13-post-quantum-cryptography.md): Post-Quantum Cryptography คืออะไร ทำไมคอมพิวเตอร์ควอนตัมถึงเป็นภัยต่อการเข้ารหัส และองค์กรควรเริ่มเปลี่ยนเมื่อไหร่ - [Cybersecurity Compliance เรื่องพื้นฐานที่ควรรู้ไว้เพื่อนำไปประยุกต์ใช้ได้จริง](https://incognitolab.com/raw/blogs/2026-07-23-cybersecurity-compliance-foundation.md): Cybersecurity Compliance คือการสร้างกระบวนการและมาตรการด้าน Cybersecurity ที่สามารถนำไปปฏิบัติได้จริง และพิสูจน์ได้ว่าองค์กรมีการบริหารความเสี่ยงอย่างเหมาะสม - [CertiGhost CVE-2026-54121](https://incognitolab.com/raw/blogs/2026-07-30-certighost-cve-2026-54121.md): Add a short description. - [Incognito Trip 2025](https://incognitolab.com/raw/blogs/icl-trip-2025.md): ทริปนี้ไม่ใช่แค่การพักผ่อน แต่คือโอกาสให้ทุกคนได้เติมพลัง เสริมสร้างความสัมพันธ์ และกลับมาพร้อมแรงบันดาลใจใหม่ ๆ Incognito Lab - [Persistence with Active Directory Certificate Services (AD CS)](https://incognitolab.com/raw/blogs/adcs-persistence.md): Active Directory Certificate Services (AD CS) ไม่ได้เป็นเพียงระบบออกใบรับรองเท่านั้น แต่ยังสามารถถูกผู้โจมตีใช้เป็นจุดฝังตัวเพื่อคงอยู่ในระบบ (Persistence) ได้อย่างแนบเนียน บทความนี้จะพาไปทำความเข้าใจเทคนิคและแนวคิดในการใช้ AD CS เพื่อฝั่งตัวอยู่ใน Active Directory Environment - [Agentic AI Work Flow In Cybersecurity](https://incognitolab.com/raw/blogs/agentic-ai-work-flow-in-cybersecurity.md): ในบทความนี้เราจะมาพูดถึงการใช้งาน Agentic AI ในงาน cyber security กันนะครับ - [An untold story about web application vulnerability assessment](https://incognitolab.com/raw/blogs/an-untold-story-about-web-application-vulnerability-assessment.md): มาทำความรู้จักกับการทำ Web application VA ให้มากขึ้นกันนะครับ - [ทำความรู้จักกับ Application Sandboxing บน Mobile Platform](https://incognitolab.com/raw/blogs/application-sandboxing-mobile-platform.md): เมื่อพูดถึงกลไกการรักษาความปลอดภัยของ Smartphone ในปัจจุบัน ไม่ว่าจะ iOS, Android หรือ Windows Phone ล้วนมีกลไกการรักษาความปลอดภัยพื้นฐานมาอยู่แล้วซึ่งช่วยให้ผู้ใช้งานทั่วไปสามารถใช้งาน Smartphone ได้อย่างมั่นคงปลอดภัยในระดับหนึ่ง - [Application Signing model and Approval process (1/2)](https://incognitolab.com/raw/blogs/application-signing-model-and-approval-process-1-of-2.md): ในบทความนี้ จะขอนำทุกท่านไปรู้จักกับ Application Signing model และ Approval process พร้อมกับวิเคราะห์ถึงประโยชน์และข้อจำกัดในมุมมองด้านความมั่นคงปลอดภัย - [Application Signing model and Approval process (2/2)](https://incognitolab.com/raw/blogs/application-signing-model-and-approval-process-2-of-2.md): Application Signing model มีจุดประสงค์หลักเพื่อใช้ในการยืนยันความถูกต้อง (Integrity) ของแอปพลิเคชันว่าไม่ได้ถูกดัดแปลงหรือแก้ไขโดยผู้ที่ไม่ใช่เจ้าของ หรือเรียกง่าย ๆ ก็คือการทำ Digital Signature สำหรับแอปพลิเคชันที่ไม่ได้รับการ Sign จะไม่สามารถนำไปติดตั้งลงบนอุปกรณ์ได้ ทั้งนี้การ Sign แอปพลิเคชันไม่ได้หมายความว่าแอปพลิเคชันนั้นจะปลอดภัยต่อการใช้งาน - [ASREPRoast Attack](https://incognitolab.com/raw/blogs/asreproast-attack.md): ASREPRoast Attack เป็นวิธีการโจมตีโดยนำ message ที่ได้จาก step ของ TGT Reply หรือ AS_REP มาทำ offline attack เพื่อหา password ของ account ที่สนใจ - [Attacking Kerberos in Windows Domain Environment](https://incognitolab.com/raw/blogs/attacking-kerberos-in-windows-domain-environment.md): บทความชุดนี้ตั้งใจเขียนอธิบายเรื่อง Kerberos ใน Windows Domain Environment และวิธีการโจมตีเหมาะสำหรับนักทดสอบเจาะระบบ อาจเป็นประโยชน์กับผู้ดูแลระบบบ้างแต่ไม่ได้มากนักเพราะไม่ได้เน้นเนื้อหาส่วน detection และ prevention สักเท่าไรเมื่อเทียบกับการอธิบายที่มาที่ไปและวิธีการโจมตี - [สอบ AWS Certificate](https://incognitolab.com/raw/blogs/aws-certificate.md): AWS Certificate มีแบ่งเป็น 4 ระดับ ได้แก่ Foundation, Associate, Professional, Specialty ดูรายละเอียดตามรูปด้านล่างได้เลย - [AWS Security Specialty Note](https://incognitolab.com/raw/blogs/aws-security-specialty-note-1.md): เหมือนจะมีคนสนใจ AWS Security Certificate มากกว่าที่คิด บทความนี้ผมขอนำ note ผมมา share เผื่อจะเป็นประโยชน์กับท่านอื่นที่เตรียมตัวสอบนะครับ - [Bangkok Governor Election](https://incognitolab.com/raw/blogs/bangkok-governor-election.md): สิ่งที่อยากจะแชร์ในวันนี้คือ Security ในเขตเลือกตั้งครับ - [Banking Trojan](https://incognitolab.com/raw/blogs/banking-trojan.md): ช่วง 1-2 ปีที่ผ่านมามี virus/trojan หรือเรียกโดยรวมว่า malware ประเภทหนึ่งที่ผู้เชี่ยวชาญให้คำจำกัดความว่า highly sophisticated - [Banking Trojan Hunting — g01pack's fundamental analysis](https://incognitolab.com/raw/blogs/banking-trojan-hunting-g01packs-fundamental-analysis.md): 1-2 วันที่ผ่านมาผมคิดว่าหลาย ๆ คนที่เข้าไปดูข่าวออนไลน์บ่อย ๆ อาจจะตกใจเนื่องจาก Google และ Google Chrome มีการแจ้งเตือนภัยคุกคามว่า website ดังกล่าวอาจเป็นอันตรายต่อคอมพิวเตอร์ของผู้ใช้งาน - [Basic Covert Channel](https://incognitolab.com/raw/blogs/basic-covert-channel.md): คำว่า Covert Channel ในเรื่องของ Security หมายถึง การส่งข้อมูลโดยใช้ช่องทางที่ไม่ได้ถูกออกแบบมาให้ส่งข้อมูลนั้น ๆ - [Be Anonymous — Search Privately](https://incognitolab.com/raw/blogs/be-anonymous-search-privately.md): Be Anonymous — Search Privately - [Beating Cybersecurity Certificate](https://incognitolab.com/raw/blogs/beating-cybersecurity-certificate.md): เนื่องจากวันก่อนได้มีโอกาสไปคุยกับ Partner แล้วก็ได้มีคำถามในห้องว่ามีเทคนิคในการสอบ Cert หรือไม่? คำตอบเร็ว ๆ คือ ไม่มีครับ แต่บทความนี้ขอเล่า Journey การสอบ Cert ที่ผ่านมาของผมโดยแบ่งเป็นประเด็น ๆ ไป - [Black Kite ตอนที่ 1](https://incognitolab.com/raw/blogs/black-kite-1.md): วันนี้จะมาเล่าถึง Black Kite ซึ่ง Partner ที่ทาง Incognito Lab ด้วยตั้งแต่ปีที่แล้ว โดย Black Kite เป็น Solution ประเภท IT Vendor Risk Management (IT VRM) - [Black Kite ตอนที่ 2](https://incognitolab.com/raw/blogs/black-kite-2.md): จากโพสต์ก่อนเราเล่าถึงประโยชน์เบื้องต้นของ Solution ประเภท IT VRM ในโพสต์นี้จะขอลงรายละเอียดมากขึ้นเกี่ยวกับการทำงาน - [Black Kite ตอนที่ 3](https://incognitolab.com/raw/blogs/black-kite-3.md): คราวก่อนเราเล่าถึงภาพรวมของ IT VRM Solution และอธิบายการทำงานโดยภาพรวมแล้ว คราวนี้เดี๋ยวเราจะมาเจาะลึก Black Kite เพิ่มในส่วนของ Technical - [Black Kite คืออะไร? ทำไมองค์กรต้องใช้แพลตฟอร์ม Cyber Risk Rating ในการบริหาร Third-Party Risk](https://incognitolab.com/raw/blogs/black-kite-cyber-third-party-risk-management-and-cyber-rating.md): ในยุคที่การโจมตีทางไซเบอร์ไม่ได้จำกัดเพียงแค่อุปกรณ์หรือระบบขององค์กร แต่ยังลุกลามไปสู่เครือข่ายคู่ค้า (Supply Chain) การบริหารความเสี่ยงด้านไซเบอร์ที่เกิดจาก Third Party จึงเป็นเรื่องสำคัญที่ทุกองค์กรไม่ควรมองข้าม - [Black Kite กับการประเมินความเสี่ยงจาก Ransomware](https://incognitolab.com/raw/blogs/black-kite-ransomware-indicator.md): Black Kite หนึ่งใน Solution ที่มาแรงในกลุ่ม IT Vendor Risk Management Solutions และเป็น Solution ที่ทาง Incognito Lab เป็น Official Partner - [Bypass Authentication against Guest OS on VMWare Workstation](https://incognitolab.com/raw/blogs/bypass-authentication-against-guest-os-on-vmware-workstation.md): หลาย ๆ คนที่ทำงานด้าน System Administrator หรือ Security Administrator คงจะเคยใช้งาน VMWare Workstation มากันบ้างแล้ว ผมเชื่อว่าหลาย ๆ ท่านน่าจะมี Guest OS อยู่มากกว่า 1 ตัวอย่างแน่นอนอย่างน้อยก็เพื่อ การ backup หรือจำลองการทำงานเป็น Network - [ลดความเสี่ยง เพิ่มความปลอดภัย ไม่ต้องต่ออายุ SSL เองอีกต่อไป](https://incognitolab.com/raw/blogs/byteplus-auto-renew-ssl-certificate.md): SSL Certificate ที่หมดอายุโดยไม่รู้ตัว อาจทำให้ผู้ใช้เข้าถึงเว็บไม่ได้ สูญเสียความน่าเชื่อถือ หรือโดน Google เตือนว่า "Not Secure" - [CANS Communication ISO27001](https://incognitolab.com/raw/blogs/cans-communication-iso27001.md): เมื่อวันอังคารที่ 6 เมษายน 2564 ตัวแทนบริษัท อินค็อกนิโตแล็บ จำกัด เข้าร่วมแสดงความยินดีกับ บริษัท แคนส์คอมมิวนิเคชั่น จำกัด ในโอกาสที่ได้รับรองมาตรฐาน ISO/IEC 27001:2013 เพื่อเน้นย้ำถึงการให้ความสำคัญด้านความปลอดภัยไซเบอร์ - [เคยเจอไหม? หน้าเว็บ Cloudflare ปลอมที่หลอกให้คุณคัดลอกคำสั่งแปลก ๆ](https://incognitolab.com/raw/blogs/clickfix-filefix.md): พาไปรู้จักเทคนิคยอดฮิตที่ชื่อว่า ClickFix และ FileFix ที่เน้นหลอก "พฤติกรรม" ของท่านให้ “เผลอทำตาม” บทความนี้จะพาไปดูว่าเทคนิคดังกล่าวคืออะไร มีที่มาอย่างไร พร้อมวิธีรับมือ ใครใช้คอมพิวเตอร์ ใช้งานอินเทอร์เน็ตเป็นประจำ หรือทำงานเอกสารทุกวัน ขอแนะนำให้อ่านเลยครับผม - [Communication Plan and Security Breach Notification Law](https://incognitolab.com/raw/blogs/communication-plan-and-security-breach-notification-law.md): เรียกได้ว่า Post นี้เกิดจากความสงสัยของผมที่ว่าเวลาที่ผมต้องหาข่าวเกี่ยวกับหน่วยงานหรือบริษัทที่ถูก Hack ในกรณีที่เป็นบริษัทในต่างประเทศเปรียบเทียบกับบริษัทในประเทศไทยแล้วมันมีความแตกต่างกัน สิ่งที่แตกต่างชัดเจนที่สุดคือ - [Company secret with Lotus Notes](https://incognitolab.com/raw/blogs/company-secret-with-lotus-notes-1.md): Lotus Notes คือ software ของบริษัท IBM ซึ่งสามารถใช้งานได้หลากหลายไม่ว่าจะเป็นการรับ-ส่งเมล, ทำตารางนัดหมาย, address book, chat ก็ยังได้ สำหรับคนทำงานที่ใช้ notes คงพอจะเคยเล่นกัน ที่สำคัญสามารถพัฒนาโปรแกรมง่าย ๆ ใช้งานบน Lotus Notes ได้อีกด้วย ปัจจุบัน version ล่าสุดจะเป็น ver 8.5.x แล้ว - [Comparing Pentest Certificates](https://incognitolab.com/raw/blogs/comparing-penetationtest-certificates.md): บทความนี้ขอพูดถึง Certificate ยอดนิยมที่เกี่ยวข้องกับการทดสอบเจาะระบบ (Pentest) - [การเตรียมความพร้อม COVID-19 ผ่านมุมมอง Cybersecurity](https://incognitolab.com/raw/blogs/covid-19-cybersecurity.md): COVID-19 จัดเป็น Pandemic หรือโรคระบาดที่เกิดการระบาดทั่วโลก ทำให้หลายบริษัทต้องออกมาตรการขั้นเด็ดขาดเพื่อรับมือการแพร่ระบาดไวรัส เช่นการเน้นย้ำบุคลากรพร้อมกับชี้แจงให้กับพาร์ทเนอร์ เพื่อดูแลสุขภาพและป้องกันการแพร่ระบาดสู่ส่วนรวม - [Crisis Communication](https://incognitolab.com/raw/blogs/crisis-communication.md): Crisis Communication หรือการสื่อสารในภาวะวิกฤต ความหมายโดยสรุปก็คือ "What you say when everything goes wrong" สิ่งที่สื่อสารต้องชัดเจน หากสื่อสารแล้วไม่เข้าใจ คนที่ได้รับผลกระทบก็ยังคงสงสัยและการวิจารณ์ต่าง ๆ ก็จะดำเนินต่อไป - [ฐานข้อมูล CVE อาจหยุดให้บริการหลังจากวันนี้](https://incognitolab.com/raw/blogs/cve-database-risk-of-shutdown-april-2025.md): วิกฤตนี้ไม่ใช่แค่เรื่อง "ช่องโหว่" แต่เป็นเรื่อง "โครงสร้างพื้นฐานของความมั่นคงไซเบอร์" ที่ทุกธุรกิจพึ่งพา หากไม่มี CVE ที่เป็นกลางและเชื่อถือได้ จะกระทบทั้งด้านเทคนิค การปฏิบัติตามข้อกำหนด และความน่าเชื่อถือขององค์กร - [Cyber Defense Initiative Conference 2020](https://incognitolab.com/raw/blogs/cyber-defense-initiative-conference-2020.md): Cyber Defense Initiative Conference 2020 - [ฝึกซ้อม Cyber Drill ด้วย CYBER RANGES](https://incognitolab.com/raw/blogs/cyber-ranges.md): CYBER RANGES แพลตฟอร์มที่ช่วยเพิ่มขีดความสามารถทางด้าน cybersecurity แบบ all-in-one แน่นอนว่ามีโมดูลมากมายที่ช่วยพัฒนาขีดความสามารถด้าน cybersecurity มากมาย - [Cyber Skills Unleashed: Recommended Cybersecurity Learning](https://incognitolab.com/raw/blogs/cyber-skills-unleashed-recommended-cybersecurity-learning.md): บทความนี้สำหรับผู้เริ่มต้นในสาย Cybersecurity เรามักได้รับคำถามว่าควรจะไปอ่านหรือเรียนรู้ด้าน Cybersecurity จากไหนดี - [Cybersecurity for Startup/SME Business ตอนที่ 1/3](https://incognitolab.com/raw/blogs/cybersecurity-for-startup-sme-business-1-3.md): รู้หรือยัง ? ว่ากำลังตกอยู่ในความเสี่ยง - [Cybersecurity for Startup/SME Business ตอนที่ 2/3](https://incognitolab.com/raw/blogs/cybersecurity-for-startup-sme-business-2-3.md): ก่อนจะจัดการกับความเสี่ยงด้าน Cybersecurity ยิ่งถ้าเราไม่ค่อยรู้อะไร เรายิ่งต้องเริ่มจากวางแผนอย่างมีหลักการ หากเริ่มต้นโดยแก้ปัญหาเป็นจุด ๆ จะการทำแบบนั้นก็เหมือนกับเราเดินหลงในป่าตอนกลางคืน ไม่มีไฟฉาย ดูทิศทางไม่เป็น เดินไปเดินมาก็อาจทำให้หลงกว่าเดิม บทความใน Series นี้เราแบ่งเป็น 5 ขั้นตอน - [Cybersecurity for Startup/SME Business ตอนที่ 3/3](https://incognitolab.com/raw/blogs/cybersecurity-for-startup-sme-business-3-3.md): นี่เป็นตอนสุดท้ายของ Series นี้ วัตถุประสงค์ของบทความนี้เราอยากให้องค์กร Startup และ SME เห็นความเสี่ยงและแนวทางในการจัดการด้าน Cybersecurity เพื่อไม่ให้เกิดการสิ้นเปลืองทั้งในด้านของเวลา และ ทรัพยากร (บุคลากร และ เงินที่ใช้) - [Cybersecurity training course](https://incognitolab.com/raw/blogs/cybersecurity-training-course.md): เชื่อว่าหลาย ๆ คนรู้จักคอร์สดัง ๆ จากค่ายต่าง ๆ ทั้ง SANS, Offensive Security, eLearnSecurity อยู่แล้ว บทความนี้อยากพูดถึงคอร์สที่เชื่อว่าหลายคนอาจไม่เคยรู้ว่ามันมีด้วยเหรอ - [Data Leakage and Data Privacy Part1](https://incognitolab.com/raw/blogs/data-leakage-and-data-privacy-part1.md): ปีนี้ผมเห็นเรื่องราวของ Data Leakage นี่น่าสนใจมากครับ ซึ่งแน่นอนข้อมูลที่รั่วออกมานี้มีประเด็นเรื่องของ Data Privacy แน่ ๆ - [DEF CON 31: Vishing Competition Review](https://incognitolab.com/raw/blogs/def-con-31-vishing-competition-review.md): ทางทีม Incognito Lab ได้ไปร่วมงาน DEF CON 31 ที่ Las Vegas ประเทศสหรัฐอเมริกา โดยปกติแล้วในงาน DEF CON จะมีกลุ่ม community แยกย่อยไปอีกหลายกลุ่ม - [DEF CON China 1.0 Badge Hacking](https://incognitolab.com/raw/blogs/def-con-china-1-0-badge-hacking.md): เมื่อวันที่ 31 พฤษภาคม 2562 ทางทีมงานได้มีโอกาสไปร่วมงาน DEF CON China 1.0 งาน DEF CON China 1.0 เป็นงานที่ถูกจัดขึ้นที่ประเทศจีนเป็นครั้งที่สอง - [Difference between Single-stage Ransomware and Multi-stage Ransomware](https://incognitolab.com/raw/blogs/difference-between-single-stage-ransomware-and-multi-stage-ransomware.md): องค์กรที่มีแผนรับมือ(Incident Response) กรณีการโจมตีของ Ransomware Attack ต้องเริ่มมาทบทวนแผนกันใหม่นะครับเนื่องจากรูปแบบการโจมตีของ attackers มีชั้นเชิงที่จะบีบบริษัทหรือองค์กรที่ตกเป็นเหยื่อมากยิ่งขึ้น - [Digital ID from the Penetration Tester eye view](https://incognitolab.com/raw/blogs/digital-id-from-the-penetration-tester-eye-view.md): Digital Identity หรือ Digital ID คือ ตัวตนของแต่ละคนบนโลกดิจิทัล ซึ่งสามารถนำไปใช้เพื่อสมัครบริการต่าง ๆ หรือทำธุรกรรมไม่ว่าจะเป็นด้านการเงิน การศึกษา สวัสดิการภาครัฐ และภาคเอกชนได้สะดวกยิ่งขึ้น - [Do you believe in mind reader?](https://incognitolab.com/raw/blogs/do-you-believe-in-mind-reader.md): เมื่อได้ดู Clip นี้จบ ผมนั่งยิ้มเลยครับ มีไอโม่งชุดดำนั่งกันเต็มเลยเพื่อที่จะช่วยกันหาข้อมูลให้กับ Dave - [Domain Controller Post-exploitation](https://incognitolab.com/raw/blogs/domain-controller-post-exploitation.md): หลังจากที่เราสามารถ compromise ผู้ใช้งานในกลุ่ม domain admins ได้สำเร็จ ในเชิงเทคนิคแล้ว domain นั้นย่อมถูก compromise ไปเรียบร้อยแล้ว - [Don’t get hooked with phishing fraud](https://incognitolab.com/raw/blogs/don-t-get-hooked-with-phishing-fraud.md): จากเรื่อง Phishing ที่หลอกเรื่องการโหลด Sticker ของ Line ฟรี นำไปสู่การขโมย Apple ID - [Easy technique to bypass web filtering](https://incognitolab.com/raw/blogs/easy-technique-to-bypass-web-filtering.md): อยู่ออฟฟิศ เข้า Web ไม่ได้อีกแล้ว จะบล็อคอะไรกันนักหนา Web ที่จะเข้าก็ใช้เกี่ยวกับงานทั้งนั้นแหละ ขอเข้าแค่ Web เดียว นี่จะต้องไป Process กันนานขนาดนี้เลยเหรอ เออเดี๋ยวเปิดดูผ่านจอเล็ก ๆ ในมือถือก็ได้ - [รีวิวการสอบ ECSA Practical + CPSA เส้นทางไปสู่ CRT](https://incognitolab.com/raw/blogs/ecsa-practical-cpsa.md): เส้นทางสู่การไปต่อ CREST CRT Certificate - [Extra: HTTPS Insecurity with SSLstrip](https://incognitolab.com/raw/blogs/extra-https-insecurity-with-sslstrip.md): SSLstrip เป็น 1 ในเทคนิคที่นิยมใช้กันในการทำ Man-in-the-middle เพื่อดักข้อมูล ซึ่งถูกคิดค้นโดย Moxie Marlinspike (คุณพี่ Deadlock นั่นเอง) และได้ถูกนำมา present ในงาน Black Hat DC 2009 - [Extract SMTP data from PCAP](https://incognitolab.com/raw/blogs/extract-smtp-data-from-pcap.md): ปกติแล้วชีวิตประจำวันสำหรับคนเล่น Internet นั้นคงหนีไม่พ้นการใช้งาน Web Site และ EMail ซึ่งทุกวันนี้ผมเองก็มักได้ยินแต่คนส่วนใหญ่แนะนำว่าเข้าใช้งาน Web ให้ระวังจะ Login ต้องมีดูที่ Address Bar ว่าต้องเป็น HTTPS ก่อนนะ แล้ว EMail ล่ะ ทำไมไม่ค่อยมีคนพูดถึงกันเลย ซึ่งผมคิดว่า EMail ก็ควรระมัดระวังในการใช้ด้วยเหมือนกัน - [Facebook Security Part 1: Privacy](https://incognitolab.com/raw/blogs/facebook-security-part-1-privacy.md): ปัจจุบัน Social Network เป็นสิ่งที่ผู้ใช้งาน Internet มักจะนิยมใช้งานมากที่สุด ผมยังไม่เคยเห็นคนที่พกพาอุปกรณ์ประเภท smart phones หรือ tablet ไม่ใช้ Social Network สักคน บทความชุดนี้จะกล่าวถึง Social Network ยอดนิยมอย่าง Facebook ว่าผู้ใช้งานอย่างเรา ๆ ท่าน ๆ ควรจะใช้งานหรือตั้งค่าอย่างไรให้ปลอดภัย - [Facebook Security Part 2: Protect our Photo Privacy](https://incognitolab.com/raw/blogs/facebook-security-part-2-protect-our-photo-privacy.md): การใช้งาน Facebook สิ่งหนึ่งที่มักจะหลีกเลี่ยงไม่ได้เลยก็คือการใช้งานรูปภาพโดยเฉพาะอย่างยิ่งการ Upload รูป Facebook ยุคแรกๆการ Upload ต้องทำผ่าน PC เท่านั้นแต่ปัจจุบันสามารถ Upload ผ่าน Mobile Platform ต่างๆได้ การตั้งค่าความปลอดภัยให้กับรูปที่ทำการ Upload นั้นจึงมีความสำคัญอย่างยิ่ง ผมขอให้พิจารณาเรื่องดังต่อไปนี้ - [Free HTTPS Is Real But Can You Trust That Website](https://incognitolab.com/raw/blogs/free-https-is-real-but-can-you-trust-that-website.md): ในโลกปัจจุบัน คุณสามารถเปิดใช้ HTTPS ได้ฟรี ภายในไม่กี่วินาที ด้วยบริการอย่าง Let's Encrypt - [ทำความรู้จัก หลักเกณฑ์การกำกับดูแลและบริหารจัดการความเสี่ยงด้านเทคโนโลยีสารสนเทศ ของบริษัทประกันชีวิตและประกันวินาศภัย พ.ศ. 2563 ตอนที่ 1](https://incognitolab.com/raw/blogs/general-insurance-1.md): ปัจจุบันถือเป็นเรื่องสำคัญอย่างยิ่งสำหรับองค์กรทุกองค์กร ในความพยายามที่จะปฏิบัติกฎหมาย กฎระเบียบ ประกาศ และข้อบังคับต่างๆ ที่ถูกประกาศออกมาและบังคับใช้จากหน่วยงานภาครัฐ - [Gift Card](https://incognitolab.com/raw/blogs/gift-card.md): สำหรับหลาย ๆ คนที่ได้ใช้บริการบัตรเครดิตในการซื้อของ Online เป็นประจำ หรือแม้แต่มีการใช้งานในต่างประเทศบ่อย ๆ นั้น อาจจะไม่ค่อยสบายใจนัก หากบัตรที่ใช้มีวงเงินสูง - [GPS Attack part 1](https://incognitolab.com/raw/blogs/gps-attack-part-1.md): ลองคิดดูว่าหากระบบนำทางที่เราเรียกกันติดปากว่าระบบ GPS เกิดปัญหาขัดข้องขึ้น ไม่ว่าจะเป็นการบ่งบอกพิกัดผิดจากตำแหน่งจริง หรือสถานีควบคุมเห็นวัตถุกำลังเคลื่อนที่จากจุดใดไปจุดหนึ่งแต่จริง ๆ - [GPS Attack part 2](https://incognitolab.com/raw/blogs/gps-attack-part-2.md): เราได้พูดถึงหลักการทำงานอย่างง่าย ๆ คร่าว ๆ ของระบบ GPS ไปเรียบร้อยแล้ว สำหรับ GPS ที่เราจะทำการโจมตีนั้น - [GPS Attack part 3](https://incognitolab.com/raw/blogs/gps-attack-part-3.md): มาถึงตอนที่ 3 ซึ่งจะเป็นตอนสุดท้ายของ series แล้วนะครับ วันนี้ผมจะมาทดลองการโจมตี AGPS ที่อยู่บน iPhone ดูว่าจะทำอะไรได้บ้าง หลังจากนั้นก็จะพูดถึงรูปแบบการโจมตี GPS ขั้นสูงในปัจจุบัน - [Incognito Lab เข้าร่วม GSB IT EXPO 2025](https://incognitolab.com/raw/blogs/gsb-it-expo.md): บริษัท Incognito Lab ได้มีโอกาสเข้าร่วมงาน GSB IT EXPO 2025 - [Hacker Hunting — How to trace the hackers](https://incognitolab.com/raw/blogs/hacker-hunting-how-to-trace-the-hackers.md): Hacker Hunting — How to trace the hackers - [Hermes React Native Reverse Engineering - Part 1: Understanding the Fundamentals (Thai Version)](https://incognitolab.com/raw/blogs/hermes-react-native-reverse-engineering-part1.md): ในปัจจุบันการพัฒนา mobile application ขึ้นมา มีแนวโน้มไปในทางที่มีการใช้งาน framework ที่เป็น cross-platform ทำให้เขียน code แค่ครั้งเดียว แต่สามารถ build เพื่อให้ใช้งานได้บนหลาย platform และเทคนิคการทำ reverse engineering, static analysis, dynamic analysis ในแต่ละ framework นั้นแทบจะแตกต่างกันโดยสิ้นเชิง ซึ่งการที่จะสามารถเข้าใจการทำงานของ application และหาจุดอ่อน/ช่องโหว่ทาง security ให้พบนั้น จำเป็นที่จะต้องรู้การทำงานภายในของแต่ละ framework และปัญหานี้ในปัจจุบัน (และอนาคต) เป็นความท้าทายพอสมควรสำหรับ security researcher เนื่องด้วยเทคโนโลยีมีการพัฒนาอย่างรวดเร็ว ทำให้เครื่องมือและความรู้เกี่ยวกับการวิเคราะห์ security ของ app นั้นตามไม่ทัน - [Hey CHAT !! อธิบาย Prompt Injection](https://incognitolab.com/raw/blogs/hey-chat-prompt-injection.md): Prompt Injection คือ การโจมตีที่ผู้ไม่ประสงค์ดีทำการควบคุมหรือเปลี่ยนแปลงการทำงานของ AI โดยการแทรกคำสั่ง (Prompt) เพื่อให้สามารถทำงานนอกเหนือจากการตั้งค่าที่ถูกกำหนดไว้ - [How many CISSPs in Thailand?](https://incognitolab.com/raw/blogs/how-many-cissps-in-thailand.md): เนื่องจากเห็น Keyword ที่ Search เข้ามาเจอ Incognitolab ของเรา บางท่านต้องการทราบข้อมูลของคนที่มี Certificate ของ ISC2 ซึ่งผมเห็นว่าก็มีประโยชน์ดีครับ - [How to get Free Internet at the airport](https://incognitolab.com/raw/blogs/how-to-get-free-internet-at-the-airport.md): I have to transit at Dubai International Airport and found that the Internet here was provided only 30 minutes for free. A question comes through my head. How can I survive for such a long transit??? - [HTTPS Insecurity Part 1](https://incognitolab.com/raw/blogs/https-insecurity-part-1.md): เรื่องน่าเบื่อที่ผู้ใช้งาน Internet คงได้ยินกันบ่อย ๆ คือ การเข้า Web ให้ปลอดภัยนั้นจะต้องดูว่าเป็น HTTPS หรือไม่ - [HTTPS Insecurity Part 2](https://incognitolab.com/raw/blogs/https-insecurity-part-2.md): หลังจาก Part 1 ได้มีการปูพื้นฐานของ PKI/Digital Certificate/HTTPS (SSL protocol) ไปแล้ว ใน Part 2 นี้จะขอพูดถึงความเสี่ยงของ HTTPS ที่สามารถเกิดขึ้นได้ครับ - [HTTPS Insecurity Part 3](https://incognitolab.com/raw/blogs/https-insecurity-part-3.md): ถึงตอนนี้แล้วทุกคนอาจมีคำถามว่า HTTPS ปลอดภัยหรือไม่? - [ICL LogBook 2020](https://incognitolab.com/raw/blogs/icl-logbook-2020.md): บันทึกเหตุการณ์ความปลอดภัยไซเบอร์เด่นตลอดปี 2020 ตั้งแต่ช่องโหว่ Zerologon การโจมตี ransomware ที่ Garmin และโรงพยาบาลสระบุรี เหตุแฮ็กบัญชี Twitter คนดัง ปัญหาความปลอดภัยของ Zoom ไปจนถึงฟิชชิงที่อ้างสถานการณ์ COVID-19 - [ICL LogBook 2021](https://incognitolab.com/raw/blogs/icl-logbook-2021.md): รวมเหตุข้อมูลรั่วและ ransomware ที่กระทบองค์กรไทยปี 2021 ทั้งโรงพยาบาลเพชรบูรณ์ ซีพี เฟรชมาร์ท กองบัญชาการกองทัพไทย จีเอเบิล และ Bangkok Airways รวมถึงการหลุดรหัสผ่านอุปกรณ์ Fortinet จากช่องโหว่ FortiOS - [Incognito Lab Certified ISO/IEC 27001:2013](https://incognitolab.com/raw/blogs/incognito-lab-certified-iso-iec27001.md): เมื่อไม่กี่วันที่ผ่านมานี้ทางเรา Incognito Lab ได้ผ่านการตรวจรับรองและได้รับใบประกาศนียบัตรมาตรฐาน ISO/IEC 27001:2013 - [Incognito Mode EP1](https://incognitolab.com/raw/blogs/incognito-mode-ep1.md): สำหรับใน EP 1 นี้ได้คุณพรสุข มาบรรยายในหัวข้อ Thailand's Cyber - [Incognito Trip 2026](https://incognitolab.com/raw/blogs/incognito-trip-2026.md): Incognito Trip 2026 ออกเดินทางสู่ตุรกีไปกับพวกเรา... - [IncognitoLab Case : Attack by advertisement](https://incognitolab.com/raw/blogs/incognitolab-case-attack-by-advertisement.md): สำหรับท่านที่มีปัญหาเรื่องการ redirect อัตโนมัติ ให้ลองตรวจสอบว่า Java ที่ติดตั้งอยู่ในเครื่องคือ version 1.7 ใช่หรือไม่ - [Industrial Control System (ICS)](https://incognitolab.com/raw/blogs/industrial-control-system-ics.md): ในช่วงปีหลัง ๆ ที่ผ่านมาถ้าใครติดตามเรื่อง Security คงจะเคยได้ยินเรื่องของ ICS มาบ้าง - [Industrial Control System (ICS) Part 2](https://incognitolab.com/raw/blogs/industrial-control-system-ics-part-2.md): ในตอนนี้มาทำความรู้จักกับ Protocol Modbus TCP ซึ่งเป็น Protocol ที่นิยมใช้กันในระบบ ICS หรือ SCADA นะครับ - [Information Security Training for Bhutan’s MOIC officers](https://incognitolab.com/raw/blogs/information-security-training-for-bhutans-moic-officers.md): สัปดาห์ที่ผ่านมาพวกเรารู้สึกเป็นเกียรติและยินดีเป็นอย่างยิ่งที่ทางกระทรวงเทคโนโลยีสารสนเทศและการสื่อสาร (ICT) ได้ให้โอกาสกับพวกเราไปบรรยายให้กับเจ้าที่ด้าน ICT - [Infosec Rock Star Review](https://incognitolab.com/raw/blogs/infosec-rock-star-review.md): Infosec Rock Star Review - [Instagram Insecurity](https://incognitolab.com/raw/blogs/instagram-insecurity.md): หลังจากที่เราได้เคยแนะนำขั้นตอนการ setup ค่าความเป็นส่วนตัวบน Facebook อย่างไรให้ปลอดภัยไปแล้ว โอกาสนี้ Incognito Lab จึงอยากแจ้งเตือนและบอกกล่าวถึงภัยและการป้องกัน Social Network อีกเจ้าหนึ่งที่ได้รับความนิยมไม่แพ้กันนั่นก็คือ Instagram - [Investment in Cybersecurity ETF](https://incognitolab.com/raw/blogs/investment-in-cybersecurity-etf.md): บทความนี้เป็นเรื่องการลงทุนในด้าน Cybersecurity นะครับ - [บทเรียนจากแผ่นดินไหว สู่แผนรับมือด้วย ISO 22301](https://incognitolab.com/raw/blogs/iso22301-bcm-bcp.md): เหตุการณ์แผ่นดินไหวที่เมียนมาเมื่อวันที่ 28 มีนาคม 2025 ส่งผลกระทบต่อประเทศไทยอย่างชัดเจน ไม่ว่าจะเป็นอาคารสำนักงาน คอนโดที่พักอาศัย รวมถึงพื้นที่ธุรกิจหลายแห่งที่ต้องหยุดชะงักชั่วคราว สะท้อนให้เห็นถึงความสำคัญของการเตรียมความพร้อมเพื่อรับมือกับเหตุการณ์ที่ไม่คาดคิด - [มหาวิทยาลัยทักษิณ มุ่งสู่มหาวิทยาลัยปลอดภัยด้านไซเบอร์ – อินค็อกนิโตแล็บร่วมผลักดันสู่มาตรฐาน ISO/IEC 27001:2022 พร้อมเสริมทัพด้วย Cyber Drill, Pentest และ PDPA](https://incognitolab.com/raw/blogs/iso27001-pdpa-cyber-drill-pentest-thaksin-university.md): บริษัท อินค็อกนิโตแล็บ จำกัด ขอแสดงความยินดีกับ มหาวิทยาลัยทักษิณ ที่เดินหน้าสู่การเป็นองค์กรต้นแบบด้านการบริหารจัดการความมั่นคงปลอดภัยสารสนเทศ ด้วยการขับเคลื่อนโครงการ พัฒนาระบบบริหารจัดการความมั่นคงปลอดภัยสารสนเทศตามมาตรฐาน ISO/IEC 27001:2022 สำหรับศูนย์เทคโนโลยีดิจิทัล - [Kerberoasting Attack](https://incognitolab.com/raw/blogs/kerberoasting-attack.md): Kerberoasting เป็นเทคนิคหนึ่งในการโจมตี Kerberos มีเป้าหมายเพื่อ crack หา Password ของ target service บน Windows Domain - [Kerberos in Windows Domain Environment](https://incognitolab.com/raw/blogs/kerberos-in-windows-domain-environment.md): Kerberos in Windows Domain Environment - [เรื่องราวของ “Kingpin” ผู้บุกเบิกโลกของ Hardware Hacking](https://incognitolab.com/raw/blogs/kingpin.md): ในยุคที่เทคโนโลยีและระบบอิเล็กทรอนิกส์เริ่มเข้ามามีบทบาทในชีวิตประจำวัน Joe Grand หรือที่รู้จักในชื่อ "Kingpin" ได้กลายเป็นผู้บุกเบิกสำคัญในโลกแห่งการแฮ็กและวิศวกรรมฮาร์ดแวร์ เริ่มตั้งแต่ช่วงปี 1980 เขาได้เดินทางบนเส้นทางที่เต็มไปด้วยความหลงใหลในการสำรวจและปรับแต่งระบบอิเล็กทรอนิกส์ จนนำไปสู่การสร้างผลงานที่มีอิทธิพลต่อวงการไซเบอร์ซีเคียวริตี้และเทคโนโลยีในปัจจุบัน - [KringleCon; HolidayHackChallenge 2018 ข้อ 9](https://incognitolab.com/raw/blogs/kringlecon-holidayhackchallenge-2018.md): จบไปแล้วกับการ submit คำตอบของ SANS Holiday Hack Challenge ประจำปี 2018 - [Lan Turtle – A cool gadget from Hak5](https://incognitolab.com/raw/blogs/lan-turtle-a-cool-gadget-from-hak5.md): หลังจากเคย Post เรื่องเกี่ยวกับเจ้าเป็ดน้อย USB Rubber Ducky ไปเมื่อนานมาแล้ว - [Break It Before It Breaks You: Performance Testing That Saves the Day](https://incognitolab.com/raw/blogs/loadtest.md): ในโลกธุรกิจดิจิทัลปัจจุบัน ความเร็วและความเสถียรของเว็บไซต์หรือแอปพลิเคชันไม่ใช่แค่เรื่อง "good to have" แต่เป็น "must" เพราะหากระบบไม่สามารถรองรับปริมาณการใช้งานจำนวนมากหรือตอบสนองต่อปริมาณผู้ใช้ที่พุ่งสูงได้ทันเวลา ผลลัพธ์ที่ตามมาคือระบบล่ม (downtime) สูญเสียรายได้ เสียโอกาส รวมถึงความเชื่อมั่นของลูกค้า - [Invisible Threat ภัยเงียบที่มองไม่เห็น](https://incognitolab.com/raw/blogs/lumma-malware.md): การจัดการ Malware บน Unmanaged device ขององค์กรถือว่าเป็นเรื่องที่ท้าทายมาก โดยเฉพาะ Malware ที่ขโมยข้อมูลออก ทำให้เราเหมือนเลือดออกตลอดเวลา จะหยุดเลือดนี้ได้อย่างไร? - [Malware Fighting Technique — DNS Sinkhole](https://incognitolab.com/raw/blogs/malware-fighting-technique-dns-sinkhole.md): 1 ในเทคนิคการป้องกัน malware ที่ implement ได้ง่ายและมีประสิทธิผลสูงสำหรับงาน Incident Handling ก็คือเทคนิคที่เรียกว่า DNS Sinkhole - [NTLM Authentication กำลังจะกลายเป็นอดีตจริงหรือ ?](https://incognitolab.com/raw/blogs/microsoft-officially-deprecates-ntlm-authentication-protocol-in-windows.md): Microsoft ออกมาประกาศว่า NTLM จะถูก deprecated อย่างเป็นทางการใน Windows 11 24H2 และ Windows Server 2025 - [Multiple Ways to Attack MetaMask](https://incognitolab.com/raw/blogs/multiple-ways-to-attack-metamask.md): MetaMask เป็น Crypto Wallet ประเภทหนึ่ง จัดเป็น hot wallet - [My Journey to GSE Certificate Part 1](https://incognitolab.com/raw/blogs/my-journey-to-gse-certificate-part-1.md): Top Certificate สาย Network เป็น CCIE แต่ถ้า Security ต้องเป็น GSE - [My Journey to GSE Certificate Part 2](https://incognitolab.com/raw/blogs/my-journey-to-gse-certificate-part-2.md): ตอนที่ 2 ขั้นตอนการเตรียมตัวและประสบการณ์การไปสอบ - [NTLMv2 Attack](https://incognitolab.com/raw/blogs/ntlmv2-attack.md): จากบทความก่อนหน้าที่กล่าวอธิบายว่าใน Windows Domain Environment เมื่อเครื่องที่อยู่ใน domain ต้องการสื่อสารกันจะใช้ Kerberos เป็น Protocol หลักในการทำ Authentication หากไม่สามารถใช้ได้จะหนีไปใช้ NTLMv2 แทน ซึ่งเงื่อนไขการไม่ใช้ Kerberos นั้นมีอยู่ 2 ข้อ - [Oracle Responds to Legacy Cloud Threat with Record April Patch Release](https://incognitolab.com/raw/blogs/oracle-critical-april-2025-patch-after-legacy-cloud-breach.md): ในเดือนนี้ Oracle ปล่อยอัปเดตความปลอดภัยครั้งใหญ่ที่สุดครั้งหนึ่งรวม 378 แพตช์ ครอบคลุมช่องโหว่จากผลิตภัณฑ์หลักเกือบทุกตัวทั้ง Oracle Database, MySQL, WebLogic ฯลฯ - [Pave the way to Domain Admins with BloodHound](https://incognitolab.com/raw/blogs/pave-the-way-to-domain-admins-with-bloodhound.md): ก่อนหน้าที่จะมี tools ชื่อ BloodHound การโจมตี Domain Controllers และ Escalate ตัวเองเป็นสิทธิ์ Domain Admins - [PCI DSS ตอนที่ 1 — Introduction](https://incognitolab.com/raw/blogs/pci-dss-introduction.md): Payment Card Industry Data Security Standard หรือ PCI DSS เป็นมาตรฐาน Payment Card Security Standard - [PDPA (Personal Data Protection Act)](https://incognitolab.com/raw/blogs/pdpa-personal-data-protection-act.md): PDPA (Personal Data Protection Act) - [Phishing domain](https://incognitolab.com/raw/blogs/phishing-domain.md): Phishing domain - [Regulation, Standard, และ Guideline ที่ควรรู้ของ OT Security](https://incognitolab.com/raw/blogs/regulation-standard-guideline-ot-security.md): OT Security ย่อมาจาก Operational Technology Security หมายถึงความมั่นคงปลอดภัยของระบบควบคุมจัดการโครงสร้างพื้นฐานสำคัญ (ICS/SCADA) - [Remote Access Security Assessment](https://incognitolab.com/raw/blogs/remote-access-security-assessment.md): Incognito Lab ร่วมต้านภัย COVID-19 ขอเต็มใจมอบบริการ "Remote Access Security Assessment" - [รอบรู้เรื่อง Remote Access ผ่าน VPN](https://incognitolab.com/raw/blogs/remote-access-vpn.md): VPN (Virtual Private Network) ถูกสร้างขึ้นเพื่อทำให้มั่นใจว่าการสื่อสารระหว่าง Source และ Destination นั้น secure เพียงพอ - [Review DEF CON China 1.0](https://incognitolab.com/raw/blogs/review-def-con-china-1-0.md): จบกันไปแล้ว สำหรับงานconference ขวัญใจ hacker ทั้งหลาย กับงาน DEF CON China 1.0เมื่อวันที่ 30 พฤษภาคม – 2 มิถุนายน 2562 โดยเป็นการจัดต่อเนื่องกันกับ DEF CON China beta ที่เป็นงาน DEF CON งานแรกที่จัดนอกสหรัฐอเมริกา ซึ่งเป็นการทดลองจัดไปก่อนหน้า - [Application Penetration Tester (eMAPT) 2023](https://incognitolab.com/raw/blogs/review-elearnsecurity-mobile-application-penetration-tester-emapt.md): วันนี้ผมจะมาเล่าถึงการไปสอบเอา Certificate ที่สายทำ Mobile Application Penetration Testing ต้องมีกัน คือ eLearnSecurity Mobile Application Penetration Tester (eMAPT) - [รีวิว GMOB 2025: เจาะลึกเนื้อหา Mobile Security พร้อมทริคเตรียมตัวสอบแบบม้วนเดียวจบ](https://incognitolab.com/raw/blogs/review-gmob-2025.md): รีวิวสอบ GMOB 2025 เจาะลึกเนื้อหา Mobile Security ครอบคลุมทั้ง Android และ iOS พร้อมสรุปเทคนิคการใช้เครื่องมือ Pentest และวิธีการทำ Index สำหรับสอบ Open Book เพื่อแนวทางการเตรียมตัวที่ครบถ้วนและตรงจุด - [Rockyou.txt](https://incognitolab.com/raw/blogs/rockyou.md): rockyou.txt ไฟล์ที่รวบรวม Password ที่ทั้งผู้เชี่ยวชาญด้าน Cybersecurity และ Hacker นิยมใช้ มีที่มาอย่างไร ทำไมต้องชื่อนี้? - [Rockyou.txt คืออะไร? ทำไมยังเป็นภัยคุกคามในปี 2025](https://incognitolab.com/raw/blogs/rockyou2024.md): หากคุณอยู่ในแวดวง Cybersecurity ชื่อของ "rockyou.txt" คงไม่ใช่เรื่องแปลกใหม่ บล็อกนี้จะพาคุณย้อนรอยไฟล์รหัสผ่านในตำนาน ตั้งแต่จุดเริ่มต้นจากเหตุการณ์แฮ็ก RockYou ในปี 2009 จนถึงเวอร์ชันล่าสุด Rockyou2024 - [ทำ Rogue Device เพื่อแทรกซึมเข้าสู่ระบบเครือข่ายเป้าหมาย](https://incognitolab.com/raw/blogs/rogue-device.md): ถ้าพูดถึงการแทรกซึม (Infiltrate) หลาย ๆ คนน่าจะเคยได้ยินมาบ้างจากหนังสงครามหรือหนังแนวสายลับ ในทาง Cybersecurity เองก็มีการใช้คำนี้ด้วยเช่นกัน ไม่ว่าจะเป็นการส่ง Spear Phishing โจมตีเป้าหมายแบบเฉพาะเจาะจง การเล่นงาน Vendor หรือ Service Provider ที่ทำงานให้กับองค์กรเป้าหมายเพื่อแทรกซึมอย่างแนบเนียน - [Rubber Ducky in action](https://incognitolab.com/raw/blogs/rubber-ducky-in-action.md): 1 ในอุปกรณ์สุดฮิตที่ Hacker ทั้งหลายควรจะต้องมี คงจะหนีไม่พ้นเจ้า USB Rubber Ducky - [ร่วมม็อบอย่างไรให้ Safe และ Secure](https://incognitolab.com/raw/blogs/safe-secure.md): ร่วมม็อบอย่างไรให้ Safe และ Secure - [SANS Holiday Challenge 2017 Write-up Part 1](https://incognitolab.com/raw/blogs/sans-holiday-challenge-2017-write-up-part-1.md): ช่วงเทศกาล Christmas ของทุกปีทาง SANS และ Counterhack จะมีการจัด CTF ที่เรียกว่า SANS Holiday Hack Challenge เป็นประจำ - [SANS Holiday Challenge 2017 Write-up Part 2](https://incognitolab.com/raw/blogs/sans-holiday-challenge-2017-write-up-part-2.md): ส่วนนี้จะพูดถึง Snowball game ถ้าใครเล่น snowball game แบบใช้ skill ปกติเล่น นี่จะอารมณ์เสียมากแน่ ๆ เพราะว่าใช้ resource ของเครื่องเยอะมาก - [SANS Holiday Challenge 2017 Write-up Part 3](https://incognitolab.com/raw/blogs/sans-holiday-challenge-2017-write-up-part-3.md): Investigate the Letters to Santa application - [SANS Holiday Challenge 2017 Write-up Part 4 (Final part)](https://incognitolab.com/raw/blogs/sans-holiday-challenge-2017-write-up-part-4-final-part.md): The North Pole engineering team has introduced an Elf as a Service - [SANS Holiday Hack Challenge 2020 ข้อ 11](https://incognitolab.com/raw/blogs/sans-holiday-hack-challenge-2020-11.md): ทาง SANS ได้เปิด Holiday Hack ประจำปีมานานแล้ว ถือได้ว่าเป็น CTF ให้ความรู้ได้ดีเลยทีเดียว โจทย์ในปีเก่า ๆ ก็ยังสามารถที่จะเข้าไปเล่นได้อยู่ตลอดเวลาครับ - [Secure Code Warrior](https://incognitolab.com/raw/blogs/secure-code-warrior.md): วันก่อนเจอ Tweet ที่คุณ Troy Hunt เจ้าของ haveibeenpwned ได้ share มาเกี่ยวกับ paper อันนึงที่น่าสนใจมาก - [หลักแห่งการออกแบบระบบอย่างมั่นคงปลอดภัย (Secure Design Principles)](https://incognitolab.com/raw/blogs/secure-design-principles.md): ธนาคารรายใหญ่มีกฎระเบียบข้อบังคับในการคัดเลือกผู้ให้บริการหลายข้อ ทั้งในแง่ขีดความสามารถและความมั่นคงทางการเงินของบริษัท แต่เมื่อมีการจัดซื้อจัดจ้างผลิตภัณฑ์หรือบริการไปแล้ว - [Security book on 2014](https://incognitolab.com/raw/blogs/security-book-on-2014.md): ผมเป็นคนหนึ่งที่ชอบสะสมหนังสือ Security ดังนั้นจึงอดไม่ได้ที่จะแนะนำหนังสือ Security ที่น่าสนใจที่เพิ่งออกมาในปี 2014 ซึ่งหนังสือ 2 เล่มนี้ได้แก่ - [Security Distro](https://incognitolab.com/raw/blogs/security-distro.md): เมื่อวานนี้ Distro ชื่อดังอย่าง Kali Linux ได้ออก Version 2.0 ซึ่งสามารถ Download ได้ที่ - [Security Professional’s Etiquette](https://incognitolab.com/raw/blogs/security-professionals-etiquette.md): สำหรับอาชีพนักเจาะระบบหรือสายงานอาชีพด้าน Information Security ผมคิดว่าเรื่อง Etiquette(จรรยาบรรณ) และ Ethics(จริยธรรม) - [Security story behind the Paris attack](https://incognitolab.com/raw/blogs/security-story-behind-the-paris-attack.md): สัปดาห์ที่ผ่านมามีเหตุการณ์น่าสลดใจคือเรื่องการก่อวินาศกรรมที่ Paris ซึ่งก่อให้เกิดความสูญเสียครั้งใหญ่ หลังจากเหตุการณ์เกิดขึ้นทางกลุ่ม ISIS ซึ่งเป็นกลุ่ม Terrorist - [Shadow Credentials in Active Directory: A Silent Threat](https://incognitolab.com/raw/blogs/shadows-credential-in-active-directory.md): Shadow Credentials เป็นเทคนิคในการโจมตีรูปแบบหนึ่งที่ทำให้ attacker สามารถแฝงตัวเข้ายึดเครื่อง computer หรือ user ที่อยู่บน environment ของ Active Directory (AD) โดยที่ไม่จำเป็นต้องรู้รหัสผ่านของเป้าหมาย - [Siri iOS6 Security](https://incognitolab.com/raw/blogs/siri-ios6-security.md): กระแสของ Technology ช่วงนี้คงไม่มีอะไรมาแรงเกิด iPhone 5 และ iOS version ใหม่ล่าสุดซึ่งคือ iOS 6 นั่นเอง - [Smart Contract Security Concisely](https://incognitolab.com/raw/blogs/smart-contract-security-concisely.md): บทความ Smart Contract Security Concisely ผู้เขียนจะรวบรวมความเห็น คำแนะนำและแนวทางการทำให้ Smart Contract มีความมั่นคงปลอดภัยต่อการนำไปใช้งาน โดยจะมีการ update ไปเรื่อย ๆ และจะขยายความอธิบายรายละเอียดหากเป็นหัวข้อที่ผู้เขียนสนใจหรือผู้อ่านอยากรู้ - [SMS Spoofing](https://incognitolab.com/raw/blogs/sms-spoofing.md): ช่วงนี้ถือว่าเป็นกระแสมากทีเดียว หลังจากมีผู้ใช้งานทั่วไปได้รับ SMS จากเบอร์โทร 02-777-777 - [SSH Tunnel for Penetration Testing](https://incognitolab.com/raw/blogs/ssh-tunnel-for-penetration-testing.md): หลาย ๆ คนน่าจะคุ้นเคยกับ Secure Shell (SSH) กันดี ว่าเป็น protocol ที่มีการเข้ารหัสซึ่งใช้ในการเชื่อมต่อไปยังเครื่องคอมพิวเตอร์ต่าง ๆ หรือแม้แต่ใช้งานในการเคลื่อนย้ายไฟล์ระหว่าง host แต่รู้หรือไม่ว่า SSH ยังสามารถที่จะทำสิ่งที่เรียกว่า "SSH Tunnel" ได้อีกด้วย - [Step into cybersecurity career](https://incognitolab.com/raw/blogs/step-into-cybersecurity-career.md): ในบทความนี้ก็จะขอพูดถึงทั้งการเตรียมตัวในการสมัครงาน และ มุมมองจากฝั่งผู้สัมภาษณ์ว่ามองหาอะไรใน Candidate นะครับ - [Super honorable mention](https://incognitolab.com/raw/blogs/super-honorable-mention.md): ในที่สุดเมื่อคืนทาง SANS ก็ได้ประกาศผลผู้ชนะงาน SANS Holiday Hack Challenge 2018 หรือ KringleCon แล้ว โดยเค้าได้สรุปสถิติเบื้องต้นคร่าวๆดังนี้ - [System Security Hardening for Beginner](https://incognitolab.com/raw/blogs/system-security-hardening-for-beginner.md): การทำ harden ของ system component (e.g. package, server, database, operating system, firewall, cloud service, etc.) - [Take a deep breath with Heartbleed](https://incognitolab.com/raw/blogs/take-a-deep-breath-with-heartbleed.md): สำหรับเรื่อง Heartbleed ผมขอเขียนให้กระชับที่สุดก็แล้วกันครับ - [Talk Talk Data Breach](https://incognitolab.com/raw/blogs/talk-talk-data-breach.md): วันนี้มาเล่าเรื่อง Data Breach ของบริษัทในอังกฤษนะครับ ใครไปเที่ยวคงเคยเห็น Carphone Warehouse บริษัทเริ่มจากขายโทรศัพท์มือถือแล้วก็ขยายจนไปทำธุรกิจของ Mobile Operator ซึ่งภายในระยะเวลาประมาณ​ 1 ปีเนี่ยเกิด Data Breach ไปมากถึง 3 ครั้งเลย - [Thailand IT Security Career](https://incognitolab.com/raw/blogs/thailand-it-security-career.md): งาน IT Security ในประเทศไทย - [Thailion air leak](https://incognitolab.com/raw/blogs/thailion-air-leak.md): เรื่องข้อมูลรั่วไหล ช่วงนี้คงหนีไม่พ้น Thai Lion Air ซึ่งนอกจาก Thai Lion Air แล้วก็มี Malindo Air โดยทั้งคู่เป็นบริษัทลูกของ Lion Air ข้อมูลที่หลุดออกมามี 4 Files ขนาดรวมกันทั้งหมดก็ประมาณ 15GB จำนวนบรรทั้งหมด 74,784,649 บรรทัด - [The 2016 SANS Holiday Hack Challenge Write-Ups (Part 1/5)](https://incognitolab.com/raw/blogs/the-2016-sans-holiday-hack-challenge-write-ups-part-15.md): The 2016 SANS Holiday Hack Challenge Write-Ups (Part 1/5) - [The 2016 SANS Holiday Hack Challenge Write-Ups (Part 2/5)](https://incognitolab.com/raw/blogs/the-2016-sans-holiday-hack-challenge-write-ups-part-25.md): สำหรับใน Part นี้ มี 2 คำถาม ที่เราจะต้องหาคำตอบให้ได้ คือ - [The 2016 SANS Holiday Hack Challenge Write-Ups (Part 3/5)](https://incognitolab.com/raw/blogs/the-2016-sans-holiday-hack-challenge-write-ups-part-35.md): กลับมาแล้วครับ สำหรับ Write-Ups ใน Part 3 ซึ่งอาจจะทิ้งช่วงห่างจาก Part 2 นานไปซักหน่อย ก็ขออภัยมา ณ ที่นี้ด้วยครับ - [อ่านมาเล่าต่อกับหนังสือ The Art of Invisibility: ศาสตร์แห่งการไร้ตัวตนบนโลกอินเทอร์เน็ต](https://incognitolab.com/raw/blogs/the-art-of-invisibility.md): People in their handlings of affairs often fail when they are about to succeed. If one remains as careful at the end as he was at the beginning, there will be no failure. - [The basic of developing iOS Tweak (Part 1/4)](https://incognitolab.com/raw/blogs/the-basic-of-developing-ios-tweak-part-1-4.md): หลาย ๆ คน คงเคย jailbreak iOS กันมาบ้าง และแน่นอนเมื่อ jailbreak แล้วก็ต้องเคยใช้พวก Tweak ทั้งหลายในการปรับแต่ง iOS กันตามใจชอบ หรือบางคนก็ jailbreak เพื่อใช้ application เถื่อน ใช้แล้วเคยสงสัยกันไหมครับว่าจริง ๆ แล้วพวก Tweak ทั้งหลาย ถูกพัฒนาขึ้นมาอย่างไร? ทำงานอย่างไร? - [The basic of developing iOS Tweak (Part 2/4)](https://incognitolab.com/raw/blogs/the-basic-of-developing-ios-tweak-part-2-4.md): สำหรับใน Part 2 นี้ เราจะมาเริ่มการวิเคราะห์ application เพื่อพัฒนา Tweak อย่างง่าย ๆ กัน ซึ่งขั้นตอนในการพัฒนาสามารถแบ่งคร่าว ๆ ได้เป็น 5 ขั้นตอน - [The basic of developing iOS Tweak (Part 3/4)](https://incognitolab.com/raw/blogs/the-basic-of-developing-ios-tweak-part-3-4.md): สำหรับขั้นตอนต่อไป คือขั้นตอนที่ 3 dynamic analysis จะเป็นการวิเคราะห์ application ขณะที่กำลังทำงานอยู่ - [The basic of developing iOS Tweak (Part 4/4)](https://incognitolab.com/raw/blogs/the-basic-of-developing-ios-tweak-part-4-4-2ea1587c712.md): ขั้นตอนการพัฒนา Tweak - [The Imitation Game: From Security View](https://incognitolab.com/raw/blogs/the-imitation-game-from-security-view.md): สวัสดีปีใหม่ ปี 2015 นี่เป็น Post แรกของปีนี้ ผมจำได้ว่าเคยเขียน Review หนังเรื่อง - [The Journey of the eWPTX Exam](https://incognitolab.com/raw/blogs/the-journey-of-the-ewptx-exam.md): ในช่วงเวลาหลังเดือนธันวาคม 2023 ที่ผ่านมา ผมได้มีประสบการณ์ในการสอบ certificate ในด้าน cyber security โดย certificate ที่สอบมาชื่อว่า eWPTX - [The Second World War](https://incognitolab.com/raw/blogs/the-second-world-war.md): สงครามโลกครั้งที่ 2 กับ โลกของ Security - [Tor map](https://incognitolab.com/raw/blogs/tor-map.md): การโจมตีที่ดีย่อมต้องคู่กับการทำอย่างไรให้จับตัวยาก ซึ่งหนึ่งในวิธีการพรางตัวยอดนิยมของคนกลุ่มนี้ในโลก Online นั่นคือการใช้ Tor - [Trust in Human or Trust in Technology](https://incognitolab.com/raw/blogs/trust-in-human-or-trust-in-technology.md): เมื่อวานได้มีโอกาสไป Live กับทาง Bitkub พูดเรื่องของ Blockchain Security จึงขอมาขยายความเพิ่มเติมในบทความนี้ - [Twitter ได้ทำการเผยแพร่ เครือข่าย IO (Information Operation)](https://incognitolab.com/raw/blogs/twitter-io-information-operation.md): เมื่อวานนี้ Twitter ได้ทำการเผยแพร่ เครือข่าย IO (Information Operation) ที่มีความเกี่ยวข้องกับรัฐ หรือพบว่าถูกสนับสนุนโดยรัฐ โดยพบ account จำนวนทั้งหมด 1,594 account ซึ่งเกี่ยวข้องกับประเทศ อิหร่าน, ซาอุดิอาระเบีย, คิวบา, รัสเซีย และไทย - [Types of Company](https://incognitolab.com/raw/blogs/types-of-company.md): เพราะเราไม่ได้ทำ Security แบบเล่นๆ - [VA/Pentest Service FAQs](https://incognitolab.com/raw/blogs/va-pentest-service-faqs.md): บทความนี้อยากทำให้ผู้อ่านได้เข้าใจถึง VA/Pentest Service ซึ่งเป็น Service หลักของ Incognito Lab - [VoidCrypt — Watch and Learn Style with Annoyance](https://incognitolab.com/raw/blogs/voidcrypt-watch-and-learn-style-with-annoyance-1.md): VoidCrypt — Watch and Learn Style with Annoyance - [Way Back Techniques for Black-box Scenario](https://incognitolab.com/raw/blogs/way-back-techniques-for-black-box-scenario.md): เวลาทดสอบเจาะระบบในรูปแบบ black-box หาก target ที่เรา focus อยู่เป็น web application และเราเจอแต่หน้า login จะทำอย่างไร? - [รู้จัก Web Tamper Prevention จาก BytePlus – ป้องกันเนื้อหาเว็บไซต์ถูกแก้ไข](https://incognitolab.com/raw/blogs/web-tamper-prevention.md): บทความนี้จะพาคุณทำความรู้จักกับ Web Tamper Prevention หนึ่งในฟีเจอร์ด้านความปลอดภัยจาก BytePlus ที่ออกแบบมาเพื่อป้องกันการแก้ไขหรือฝังเนื้อหาที่ไม่พึงประสงค์บนเว็บไซต์ โดยจะอธิบายแนวคิดการทำงานร่วมกับระบบ CDN และ WAF พร้อมแสดงตัวอย่างการตั้งค่าและทดลองใช้งานจริง (POC) เพื่อให้เห็นภาพชัดเจนว่าวิธีการสามารถช่วยเสริมความมั่นคงให้กับเว็บไซต์ได้อย่างไร - [WhatsApp insecurity part 1](https://incognitolab.com/raw/blogs/whatsapp-insecurity-part-1.md): วันนี้เรามาดู Whatsapp ซึ่งเป็น chat application ที่ได้รับความนิยมสูงนั้นมีความปลอดภัยมากแค่ไหนกัน - [WhatsApp insecurity part 2](https://incognitolab.com/raw/blogs/whatsapp-insecurity-part-2.md): หลังจากตอนแรกเราได้พูดกันถึง Concept ของ Data Leakage ไปแล้ว 2 ใน 3 ช่องทาง ในตอนนี้เราจะพูดถึงช่องทางที่ 3 กันซึ่งได้แก่ Data at rest หรือข้อมูลที่ถูกเก็บไว้ที่ Server นั่นเอง - [Windows Recall - "Privacy Nightmare"](https://incognitolab.com/raw/blogs/windows-recall-privacy-nightmare.md): Microsoft ได้มีการเปิดตัว Copilot+ PC ซึ่งเป็นแล็ปท็อประบบปฏิบัติการ Windows 11 ที่มีการใช้งานหน่วยประมวลผลที่เป็น Neural Processing Unit (NPU) - [เบื้องหลังความง่ายของ Let's Encrypt และอนาคตของโลกที่ใบรับรองจะมีอายุแค่ "47 วัน"](https://incognitolab.com/raw/blogs/you-need-ssl-automation-for-digital-certiificate.md): เบื้องหลัง "ความง่าย" นี้ คือโปรโตคอลที่เปลี่ยนวงการ Digital Certificate ไปตลอดกาล - [Zero Trust model](https://incognitolab.com/raw/blogs/zero-trust-model.md): เคยสงสัยมั้ยครับว่า Standard อะไรหรือ Framework อะไรที่ควรทำ หรือควร comply ดี ทำแล้วเหนื่อยน้อย ทำแล้วมั่นคงปลอดภัย จากการสังเกตมักจะมีเหตุผลประมาณ - [ชำแหละ Zerologon (CVE-2020-1472)](https://incognitolab.com/raw/blogs/zerologon-cve-2020-1472-1.md): สองสามวันที่ผ่านมานี้หลายคนอาจจะได้ยินเรื่องช่องโหว่ระดับความรุนแรงสูงมาก (CVSS v3 score เต็ม 10 ไม่มีหัก) - [การถอดรหัสข้อความที่ 2 ของฆาตรกรต่อเนื่องที่ใช้ชื่อ Zodiac](https://incognitolab.com/raw/blogs/zodiac.md): มีคนสามารถถอดรหัสข้อความที่ 2 ของฆาตรกรต่อเนื่องที่ใช้ชื่อ Zodiac ได้สำเร็จ ซึ่งเป็นคดีที่มีอายุมากว่า 50 ปีแล้ว และยังคงเป็นคดีที่เป็นปริศนาอยู่จนทุกวันนี้ ## Services Cybersecurity services offered by Incognito Lab — penetration testing, red teaming, OT security, consulting, training, and load testing - [AI Penetration Test](https://incognitolab.com/raw/services/ai-penetration-test.md): AI and LLM penetration testing in Thailand — prompt injection, RAG, and agent abuse, mapped to the OWASP Top 10 for LLM Applications. - [Cloud Security Assessment](https://incognitolab.com/raw/services/cloud-security-assessment.md): Cloud security assessment in Thailand — configuration review and testing across AWS, Azure, and GCP, framed by the shared responsibility model and CIS Benchmarks. - [Consulting](https://incognitolab.com/raw/services/consulting.md): Cyber security, risk and compliance consulting in Thailand — build a resilient security program with consultants who also run offensive operations. - [Infrastructure Penetration Test](https://incognitolab.com/raw/services/infrastructure-penetration-test.md): Infrastructure and network penetration testing in Thailand — external and internal, black-box and gray-box, from perimeter breach to lateral movement, based on NIST SP800-115. - [IoT Penetration Test](https://incognitolab.com/raw/services/iot-penetration-test.md): IoT penetration testing in Thailand — firmware, hardware, network protocol, application, and cloud, with reverse engineering, mapped to the OWASP IoT Top 10. - [Load Test & Stress Test](https://incognitolab.com/raw/services/load-test.md): Load and stress testing in Thailand — load, stress, endurance, and spike tests that find bottlenecks and breaking points before your users do. - [Mobile Application Penetration Test](https://incognitolab.com/raw/services/mobile-application-penetration-test.md): Mobile application penetration testing in Thailand for iOS and Android — static, dynamic, and network analysis by an OSCP/eMAPT-certified team. Book a scoping call. - [OT Security](https://incognitolab.com/raw/services/ot-security.md): OT and ICS security assessment in Thailand — protect critical infrastructure without disrupting operations. Talk to our OT security team. - [PCI DSS Penetration Test](https://incognitolab.com/raw/services/pci-dss-penetration-test.md): PCI DSS penetration testing in Thailand — Requirement 11 network, application, and segmentation testing plus ASV scan support, with deliverables built for your QSA. - [Penetration Test](https://incognitolab.com/raw/services/penetration-test.md): Penetration testing in Thailand by an OSCP/CREST-certified team — NIST SP800-115, web, mobile, cloud and PCI DSS. Zero blank reports. Book a scoping call. - [Red Teaming](https://incognitolab.com/raw/services/red-teaming.md): Adversary simulation in Thailand that goes deeper than a pentest — measure how well your organisation detects and responds to real attacks. Book a scoping call. - [Secure Code Review](https://incognitolab.com/raw/services/secure-code-review.md): Secure code review in Thailand — SAST tooling plus manual expert analysis to confirm real vulnerabilities in your source code, mapped to OWASP ASVS and the OWASP Top 10. - [Training](https://incognitolab.com/raw/services/training.md): Hands-on cyber security training in Thailand taught by practicing pentesters — offensive, defensive and secure development courses for your team. - [Vulnerability Assessment](https://incognitolab.com/raw/services/vulnerability-assessment.md): Vulnerability assessment in Thailand — authenticated and unauthenticated scanning with manual validation across network, web, and mobile, mapped to NIST SP800-115. - [Web Application Penetration Test](https://incognitolab.com/raw/services/web-application-penetration-test.md): Web application penetration testing in Thailand — manual technical and business logic testing mapped to the OWASP Top 10 by an OSCP/CREST-certified team. - [Wireless Network Penetration Test](https://incognitolab.com/raw/services/wireless-penetration-test.md): Wireless network penetration testing in Thailand — infrastructure, protocol, and client-side attacks, including rogue access point detection for PCI DSS. ## บริการ (Services — Thai) บริการด้านความปลอดภัยไซเบอร์ของ Incognito Lab — Penetration Test, Red Teaming, OT Security, Consulting, Training และ Load Test - [บริการทดสอบเจาะระบบ AI (AI Penetration Test)](https://incognitolab.com/raw/th/services/ai-penetration-test.md): บริการทดสอบเจาะระบบ AI และ LLM ในประเทศไทย ครอบคลุม prompt injection, RAG และการใช้ agent ในทางที่ผิด อิงตาม OWASP Top 10 for LLM Applications - [การประเมินความมั่นคงปลอดภัยของ Cloud](https://incognitolab.com/raw/th/services/cloud-security-assessment.md): บริการประเมินความมั่นคงปลอดภัยของ cloud ในประเทศไทย ทั้ง configuration review และการทดสอบบน AWS, Azure และ GCP อิงตาม shared responsibility model และ CIS Benchmarks - [บริการให้คำปรึกษาด้านความปลอดภัยไซเบอร์ (Consulting)](https://incognitolab.com/raw/th/services/consulting.md): ที่ปรึกษาด้าน cybersecurity, risk และ compliance ในประเทศไทย วางโปรแกรมความปลอดภัยกับทีมที่ปรึกษาที่ทำงานสายบุกจริงด้วย - [บริการทดสอบเจาะระบบโครงสร้างพื้นฐาน (Infrastructure Penetration Test)](https://incognitolab.com/raw/th/services/infrastructure-penetration-test.md): บริการทดสอบเจาะระบบโครงสร้างพื้นฐานและ network ในประเทศไทย ทั้งภายนอกและภายใน แบบ black-box และ gray-box ตั้งแต่การเจาะ perimeter ไปจนถึง lateral movement อิงตาม NIST SP800-115 - [บริการทดสอบเจาะระบบ IoT (IoT Penetration Test)](https://incognitolab.com/raw/th/services/iot-penetration-test.md): บริการทดสอบเจาะระบบ IoT ในประเทศไทย ครอบคลุม firmware, hardware, network protocol, application และ cloud พร้อม reverse engineering อิงตาม OWASP IoT Top 10 - [บริการทดสอบโหลดและความเครียดของระบบ (Load Test & Stress Test)](https://incognitolab.com/raw/th/services/load-test.md): บริการ load test และ stress test ในประเทศไทย — ทดสอบ load, stress, endurance และ spike หา bottleneck และ breaking point ก่อนผู้ใช้จะเจอ - [บริการทดสอบเจาะระบบแอปพลิเคชันมือถือ (Mobile Application Penetration Test)](https://incognitolab.com/raw/th/services/mobile-application-penetration-test.md): ทดสอบเจาะระบบแอปพลิเคชันมือถือ iOS และ Android ในประเทศไทย ด้วย static, dynamic, network analysis โดยทีม OSCP/eMAPT นัดคุยขอบเขตงานได้เลย - [OT Security](https://incognitolab.com/raw/th/services/ot-security.md): ประเมินความปลอดภัยระบบ OT และ ICS โดยไม่กระทบการเดินเครื่อง ปกป้องโครงสร้างพื้นฐานสำคัญขององค์กร คุยกับทีม OT security ได้เลย - [การทดสอบเจาะระบบตามมาตรฐาน PCI DSS](https://incognitolab.com/raw/th/services/pci-dss-penetration-test.md): การทดสอบเจาะระบบตามมาตรฐาน PCI DSS ในประเทศไทย ครอบคลุมการทดสอบ network, application และ segmentation ตาม Requirement 11 พร้อมสนับสนุน ASV scan และเอกสารส่งมอบที่จัดทำเพื่อ QSA ของคุณ - [บริการทดสอบเจาะระบบ (Penetration Test)](https://incognitolab.com/raw/th/services/penetration-test.md): ทีม pentest OSCP/CREST ทดสอบเจาะระบบในประเทศไทย ตามแนวทาง NIST SP800-115 ครอบคลุมเว็บ มือถือ คลาวด์ และ PCI DSS ไม่เคยส่งรายงานเปล่า นัดคุยขอบเขตงานได้เลย - [Red Teaming](https://incognitolab.com/raw/th/services/red-teaming.md): จำลองการโจมตีเสมือนจริงที่ลึกกว่า pentest ทั่วไป วัดว่าองค์กรตรวจจับและรับมือการโจมตีได้จริงแค่ไหน ทีม red team ในไทยพร้อมคุยขอบเขตงาน - [บริการตรวจสอบความปลอดภัยของ Source Code (Secure Code Review)](https://incognitolab.com/raw/th/services/secure-code-review.md): บริการ Secure Code Review ในประเทศไทย ใช้เครื่องมือ SAST ร่วมกับการวิเคราะห์ด้วยผู้เชี่ยวชาญ เพื่อยืนยันช่องโหว่จริงใน source code ของคุณ อิงตาม OWASP ASVS และ OWASP Top 10 - [Training](https://incognitolab.com/raw/th/services/training.md): คอร์สอบรม cyber security แบบลงมือทำ สอนโดยทีมที่ทำ pentest จริง มีทั้งสายบุก สายรับ และ secure coding สำหรับทีมของคุณ - [การประเมินช่องโหว่ (Vulnerability Assessment)](https://incognitolab.com/raw/th/services/vulnerability-assessment.md): บริการประเมินช่องโหว่ในประเทศไทย — สแกนแบบ authenticated และ unauthenticated พร้อมการตรวจสอบด้วยมือ ครอบคลุม network เว็บ และ mobile อ้างอิงตาม NIST SP800-115 - [บริการทดสอบเจาะระบบเว็บแอปพลิเคชัน (Web Application Penetration Test)](https://incognitolab.com/raw/th/services/web-application-penetration-test.md): บริการทดสอบเจาะระบบเว็บแอปพลิเคชันในประเทศไทย ทดสอบด้วยมือทั้งเชิงเทคนิคและ business logic เทียบกับ OWASP Top 10 โดยทีมที่ถือ OSCP และ CREST - [การทดสอบเจาะระบบเครือข่ายไร้สาย (Wireless Network Penetration Test)](https://incognitolab.com/raw/th/services/wireless-penetration-test.md): บริการทดสอบเจาะระบบเครือข่ายไร้สายในประเทศไทย ครอบคลุมการโจมตีระดับ infrastructure, protocol และ client-side รวมถึงการตรวจจับ rogue access point เพื่อ PCI DSS ## Products & Partners Cybersecurity products and partner solutions — Cyber Range, Black Kite, Confix, Akamai, BytePlus, Craig, HackDiver, and VulnWolf - [Akamai](https://incognitolab.com/raw/products/akamai.md): Performance, reliability, and security through the world's most distributed cloud computing platform and edge network. - [Black Kite](https://incognitolab.com/raw/products/black-kite.md): Scalable cyber ecosystem risk management platform for security and business professionals to improve business resiliency. - [BytePlus](https://incognitolab.com/raw/products/byteplus.md): AI-powered Web Application and API Protection (WAAP) with real-time detection, automated rate tuning, and adaptive defense against DDoS, SQL injection, XSS, and bots. - [Confix](https://incognitolab.com/raw/products/confix.md): Automated system hardening and auditing tool for Windows and Unix servers using customizable templates aligned with security best practices. - [Cyber Range](https://incognitolab.com/raw/products/cyber-range.md): World-class cyber security training and capability development exercises using next-generation simulation-based technology. - [HackDiver](https://incognitolab.com/raw/products/hackdiver.md): Lightweight, fast, and easy-to-use vulnerability scanner powered by multiple scanning engines for efficient security flaw detection. - [VulnWolf](https://incognitolab.com/raw/products/vulnwolf.md): Comprehensive vulnerability management platform that eliminates the need for juggling multiple feeds and deciphering complex alerts. ## ผลิตภัณฑ์และพาร์ทเนอร์ (Products — Thai) ผลิตภัณฑ์และโซลูชันพาร์ทเนอร์ด้านความปลอดภัยไซเบอร์ — Cyber Range, Black Kite, Confix, Akamai, BytePlus, Craig, HackDiver และ VulnWolf - [Akamai](https://incognitolab.com/raw/th/products/akamai.md): ประสิทธิภาพ ความเสถียร และความปลอดภัย ผ่านแพลตฟอร์ม cloud computing และ edge network ที่กระจายตัวมากที่สุดในโลก - [Black Kite](https://incognitolab.com/raw/th/products/black-kite.md): แพลตฟอร์มบริหารความเสี่ยงของระบบนิเวศไซเบอร์ที่ปรับขนาดได้ ช่วยผู้เชี่ยวชาญด้านความปลอดภัยและธุรกิจเสริมความยืดหยุ่นขององค์กร - [BytePlus](https://incognitolab.com/raw/th/products/byteplus.md): การปกป้อง Web Application และ API (WAAP) ด้วย AI พร้อม real-time detection, automated rate tuning และการป้องกันแบบปรับตัวจาก DDoS, SQL injection, XSS และบอท - [Confix](https://incognitolab.com/raw/th/products/confix.md): เครื่องมือ hardening และ audit ระบบอัตโนมัติสำหรับเซิร์ฟเวอร์ Windows และ Unix ด้วย template ที่ปรับแต่งได้ตาม best practice - [Cyber Range](https://incognitolab.com/raw/th/products/cyber-range.md): การอบรมความปลอดภัยไซเบอร์ระดับโลกและการพัฒนาขีดความสามารถ ด้วยเทคโนโลยีจำลองสถานการณ์ยุคใหม่ - [HackDiver](https://incognitolab.com/raw/th/products/hackdiver.md): เครื่องมือสแกนช่องโหว่ที่เบา รวดเร็ว และใช้งานง่าย ขับเคลื่อนด้วย scanning engine หลายตัว เพื่อตรวจจับช่องโหว่อย่างมีประสิทธิภาพ - [VulnWolf](https://incognitolab.com/raw/th/products/vulnwolf.md): แพลตฟอร์มบริหารจัดการช่องโหว่แบบครบวงจร ตัดความยุ่งยากของการจัดการ feed หลายแหล่งและ alert ที่ซับซ้อน