Skip to content
INCIDENT RESPONSE TEAM · FIRST MEMBER

CERT-CBRT, the operation's public radar

Recent vulnerabilities ranked by real exploitation probability, and analysis from the team that responds to incidents every day. What we learn on shift, shared., published under TLP policy.

See vulnerability alerts Go to the blog TLP:CLEAR · FIRST MEMBER · UTC-4
VULNERABILITY ALERTS

Most likely to be exploited right now

LIVE DATA · NVD + EPSS

Prioritized by exploitation probability (FIRST EPSS), not CVSS. CROC clients also get the concrete action per stack and the deployed detection before the bulletin.

Querying the public vulnerability sources…

Public data, no manual curation. Subscribe to the bulletin →
RFC 2350 · PUBLIC CSIRT PROFILE

The CERT-CBRT RFC 2350 profile

Formal description of the team under the RFC 2350 standard: who we are, whom we serve, under which policies we operate and how to reach us.

VERSION 1.0 · DEC 1, 2022 TLP:CLEAR UTC-4
1 · DOCUMENT INFORMATION

Version and distribution

Version: 1.0, dated December 1, 2022.
Distribution: changes to this document are not distributed by a mailing list; questions or comments to contacto@cbrt.com.do.
2 · CONTACT INFORMATION

How to reach the team

Team: CERT-CBRT · timezone UTC/GMT −4.
Incidents: incidentes@cbrt.com.do — the duty officer responds 24×7×365.
General information: info@cbrt.com.do.
Members: the full roster is not public; each member identifies to the reporting party with their full name in the official incident communication.
3 · CHARTER

Mission, constituency and authority

Mission: provide the support needed for incident response in all its phases, remotely or on site, with centralized management of client security.
Constituency: incidents affecting systems of internal and external clients, and any system processing classified information.
Sponsorship: sponsored by Cybersecurity Blue & Red Team, S.R.L.; seeks affiliation with institutions around the world to collaborate, share information and support cyber incident response.
Authority: coordinates incident response and advises clients on proper incident handling.
4 · POLICIES

Support, confidentiality and TLP

Incident types and support level: different incident types are handled; the level of support depends on the type, its severity criteria and the criticality determined by CERT-CBRT staff.
Disclosure: all information is handled confidentially; highly sensitive information is communicated and stored in a secure environment, encrypted when necessary, and shared only on a need-to-know basis, preferably anonymized. TLP is used for information exchange.
Communication: the preferred method is email: incidentes@cbrt.com.do.
5 · SERVICES

Reactive and proactive

Reactive: 24/7 cyber incident response — incident classification, coordination and resolution.
Proactive: cybersecurity assessments, framework-based risk management, vulnerability analysis, education and culture, audits and holistic 360° penetration testing, 360 protection, threat intelligence and 24×7×365 real-time monitoring (SOC as a service).
6 · INCIDENT REPORTING

How to report

To report an incident send a communication to incidentes@cbrt.com.do, or use this portal’s “Report an incident” form.

Disclaimer: CERT-CBRT takes every precaution in preparing information, notifications, alerts and reports, but assumes no responsibility for errors or omissions, nor for damages resulting from the use of the information supplied.

Active incident?

The DFIR team responds 24/7. Containment, forensics and recovery with chain of custody.