[{"content":"\u0026ldquo;How much does a security audit cost?\u0026rdquo; – I hear that question almost as often as \u0026ldquo;Do we even need one?\u0026rdquo;. The honest answer upfront: There is no serious fixed price – and that is a good thing. Here is why audit effort varies so much, how prices actually form, and what a good offer looks like.\nWhat drives the effort of an audit A security audit is not a standard product. Four factors decide how much work goes into it:\nNumber and type of systems: A single on-premise server is a different scope than a cloud environment with dozens of instances, containers, and pipelines. More systems means more configurations, more access paths, more risks – and more analysis work. Complexity of the environment: CI/CD pipelines, identity providers, container orchestration, and heterogeneous setups require deeper understanding than a classic environment. What looks simple is often the hard part – and what looks complex is sometimes quick to review. Depth and documentation: What do you need as the result? A compact finding for management, technical detail per system, runbooks for your team, or evidence for an auditor or regulator? Follow-on services: A re-check after the fixes, support during remediation, working out baselines (e.g., as Ansible playbooks) – all of it is effort that has to be clear upfront. Anyone who names a price without clarifying these things can only guess.\nWhy \u0026ldquo;starting at\u0026rdquo; prices often calculate at your risk Offers like \u0026ldquo;security audit from\u0026rdquo; a certain amount sound attractive – and hide a shift of risk: the provider calculates on the average environment, but your environment is not the average environment. In the end, either too little time is planned for your project (you get a shallow finding), or the price falls apart and gets renegotiated. Both are annoying, because you only notice after the project.\nA transparent frame – justified, in writing, traceable – is the better alternative: you know upfront roughly how much work is ahead, without a fictitious standard case being billed against you.\nHow I work: transparently by the hour Intro call (free): 30 minutes to discuss your situation. I ask about systems, cloud scope, and goals. Written offer: Based on the call I define the scope and name the expected frame – as an order of magnitude, not as a fixed price. Invoicing: Only what was actually worked is billed. Documented and traceable. What to look for in offers Good signals:\nScope is clarified before price. Serious providers ask questions first, then name prices. The frame is justified in a traceable way – with reference to your setup, not as an industry average. The result is described: report format, prioritisation, handover, re-check option. Questions after the contract are normal – a finding gets explained, a fix gets verified. Warning signals:\n\u0026ldquo;From\u0026rdquo; prices without scope clarification – calculated at risk. Tool output as the result instead of a prioritised report. No re-check option – then the proof ends at the PDF. Pressure to close instead of room for your questions. The right first step: audit before pentest Before you compare prices, you should have chosen the right service. A security audit – the technical assessment without an active attack – is the more sensible entry point for most businesses and usually significantly less effort than a full penetration test that builds on the audit\u0026rsquo;s result. The article Security audit or pentest? goes into the difference in detail – and what a pentest costs when you plan the second step.\nDetails about the audit itself – scope, process, methodology – are on my security audit page.\nClarity instead of guesswork If you want to know a realistic frame for your environment, the fastest way is a short conversation: describe your situation, I explain what needs to be reviewed and roughly how much time that costs. Free and non-binding for initial guidance.\nBook a 30-minute intro call Security audit in detail: process, methodology, FAQ All services at a glance ","permalink":"https://heidelsec.de/en/posts/2026-09-15-was-kostet-ein-security-audit/","summary":"\u003cp\u003e\u0026ldquo;How much does a security audit cost?\u0026rdquo; – I hear that question almost as often as \u0026ldquo;Do we even need one?\u0026rdquo;. The honest answer upfront: \u003cstrong\u003eThere is no serious fixed price\u003c/strong\u003e – and that is a good thing. Here is why audit effort varies so much, how prices actually form, and what a good offer looks like.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"what-drives-the-effort-of-an-audit\"\u003eWhat drives the effort of an audit\u003c/h2\u003e\n\u003cp\u003eA security audit is not a standard product. Four factors decide how much work goes into it:\u003c/p\u003e","title":"What does a security audit cost? How the price is formed – and what a good offer looks like"},{"content":"\u0026ldquo;Should we get an audit or a pentest?\u0026rdquo; – the question comes up again and again, and honestly: the answer is less often \u0026ldquo;simply both\u0026rdquo; than you might think. The two approaches answer different questions. Understand that, and you also know where to start.\nWhat a security audit checks A security audit is a systematic technical assessment: I look at your configurations, architectures, processes, and settings – cloud setup, Linux and container environments, access rights, secrets, monitoring. The goal is to find and assess known vulnerabilities, misconfigurations, and design problems.\nThe result is a prioritized finding with an action plan: what is risky, what is urgent, what can wait – and how to fix it with the least sensible effort.\nImportant: an audit is not an attack. No systems are actively compromised, no flaws are exploited. It is the view of an examining expert on your setup – with no risk to operations.\nWhat a pentest delivers A penetration test (pentest) is the opposite: a controlled attack. A security expert tries to break into your systems using the methods of a real attacker – and thereby proves that a vulnerability is not only theoretical but practically exploitable.\nPentests are powerful – but they need a clear scope, legal clearance, and good preparation. And they answer a narrower question than an audit: \u0026ldquo;Can damage actually be done from point X?\u0026rdquo; Not: \u0026ldquo;Where do we stand overall?\u0026rdquo;\nThe honest comparison Security Audit Pentest Method Analysis of configuration, architecture, processes Controlled attack Answer \u0026ldquo;Where do we stand, what is risky?\u0026rdquo; \u0026ldquo;Is this gap practically exploitable?\u0026rdquo; Effort before Low (clarify scope) Higher (scope, rights, clearance) Outcome Prioritized findings + action plan Exploitation evidence + fix recommendations Typical for Getting started, regular assessments Evidence for auditors/insurers, focus systems Where you should start For most businesses, the security audit is the more sensible first step – for three reasons:\nIt gives the big picture. A pentest on a single system says little about the rest of the environment. If you have never had an audit, you simply do not know your risks. It finds the cheap mistakes first. Many of the riskiest gaps – open storage buckets, weak access rights, missing MFA – are configuration errors that an audit reveals immediately and that are quick to fix. It makes a later pentest better. With a clear scope from the audit, a pentest becomes more precise – and that is exactly the case where it is worth its price. A pentest makes proper sense when you have a specific reason: an insurer or a client requires it, a critical system needs to be demonstrably secured, or an audit produced gaps whose practical exploitability you want to clarify.\nAnd what about NIS2? NIS2 does not require a classic pentest – but it does require organised risk management and appropriate technical measures. An audit delivers exactly that foundation, and my NIS2 Readiness Check additionally shows you whether you are in scope at all. As a quick first step, the free NIS2 self-assessment on my tools page is a good fit.\nConclusion Audit and pentest are not alternatives, but two stages: understand first, then prove selectively. If you are unsure where your business should start, we clarify that in a free 30-minute intro call – with an independent, honest recommendation.\nBook a 30-minute intro call Security audit in detail: process, methodology, FAQ Penetration test in detail: process, methodology, FAQ More about my security audit offering ","permalink":"https://heidelsec.de/en/posts/2026-09-14-security-audit-oder-pentest/","summary":"\u003cp\u003e\u0026ldquo;Should we get an audit or a pentest?\u0026rdquo; – the question comes up again and again, and honestly: the answer is less often \u0026ldquo;simply both\u0026rdquo; than you might think. The two approaches answer different questions. Understand that, and you also know where to start.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"what-a-security-audit-checks\"\u003eWhat a security audit checks\u003c/h2\u003e\n\u003cp\u003eA security audit is a \u003cstrong\u003esystematic technical assessment\u003c/strong\u003e: I look at your configurations, architectures, processes, and settings – cloud setup, Linux and container environments, access rights, secrets, monitoring. The goal is to find and assess known vulnerabilities, misconfigurations, and design problems.\u003c/p\u003e","title":"Security Audit vs. Penetration Test: The Difference – and Which One Is the Right First Step"},{"content":"\u0026ldquo;What does a pentest cost?\u0026rdquo; is the most common question after \u0026ldquo;what is a pentest?\u0026rdquo; – and it is a fair one. The honest answer up front: there is no serious fixed price. Anyone offering you pentests \u0026ldquo;from\u0026rdquo; a certain amount is calculating at a risk – yours. Here is how prices for security services actually come about, and how to recognise a good proposal.\nWhy there is no fixed price A pentest (or a security audit) is not a standard product like a firewall license. The effort depends on things that differ completely from business to business:\nScope: How many systems, networks, cloud subscriptions, and applications should be reviewed? A single server and a distributed cloud environment with dozens of services are not comparable effort. Complexity: Modern setups with containers, CI/CD pipelines, identity providers, and APIs require deeper understanding than a classic on-premise environment. Documentation: What do you need as the outcome? A compact finding, runbooks, evidence for auditors, or a complete list of issues with reproduction? A provider who names a fixed price before clarifying the scope can only do one of two things: guess an average – and at the end either put too little work into the project or let the engagement fall short.\nHow does a pentest work? Intro call (free): 30 minutes in which you describe your situation. I ask about scope, systems, and goals. Written proposal: Based on the conversation, I define the scope and give you the expected frame – as an order of magnitude, not a fixed price. Billing: Only what was actually worked is billed. Documented and verifiable. This shifts the risk distribution: the provider does not have to hope for a guessed price, and you do not pay for a flat rate that ends up above – or below – your actual needs.\nWhat to look for in a proposal Good signals:\nScope is clarified before the price. Serious providers ask questions first, then name prices. The frame is justified understandably – not just \u0026ldquo;from X\u0026rdquo;, but with reference to your setup. The outcome is described: What form does the report take, what prioritisation, what handover? Follow-up questions are possible: A fix is verified, a finding is explained. Warning signs:\nFixed prices without scope clarification – calculated at a risk. No report promised, just \u0026ldquo;the list of found holes\u0026rdquo;. Pressure to close instead of room for your questions. Audit or pentest: price is not the first criterion Before you compare prices, you should have chosen the right service. A security audit – the technical assessment without an active attack – is the more sensible first step for most businesses and significantly less effort than a full pentest. My article Security Audit or Pentest? goes into the difference in detail.\nThe most common expensive mistake is not the high hourly rate, but the wrong project: a pentest on a system that was never audited before often does not find the biggest gaps – because nobody knew what to look for.\nClarity instead of guesswork If you want to know a realistic frame for your business, the fastest way is a short conversation: describe your situation to me, I explain what needs to be reviewed, roughly how much time that costs – and which format makes the most sense for you. Free and non-binding for initial guidance.\nBook a 30-minute intro call Penetration test in detail: process, methodology, FAQ What does a security audit cost? All services at a glance ","permalink":"https://heidelsec.de/en/posts/2026-09-14-was-kostet-ein-pentest/","summary":"\u003cp\u003e\u0026ldquo;What does a pentest cost?\u0026rdquo; is the most common question after \u0026ldquo;what is a pentest?\u0026rdquo; – and it is a fair one. The honest answer up front: \u003cstrong\u003ethere is no serious fixed price.\u003c/strong\u003e Anyone offering you pentests \u0026ldquo;from\u0026rdquo; a certain amount is calculating at a risk – yours. Here is how prices for security services actually come about, and how to recognise a good proposal.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"why-there-is-no-fixed-price\"\u003eWhy there is no fixed price\u003c/h2\u003e\n\u003cp\u003eA pentest (or a security audit) is not a standard product like a firewall license. The effort depends on things that differ completely from business to business:\u003c/p\u003e","title":"What Does a Pentest Cost? How the Price Is Built Up – and What to Look for in a Proposal"},{"content":"The good news first: most ransomware cases are not decided during the attack, but during recovery. Companies with usable backups and a rehearsed recovery get away with a bad weekend. Those without end up negotiating ransom demands. The difference lies in a handful of decisions made in advance – and that is what this article is about.\nWhy attackers go for your backups first Modern ransomware groups don\u0026rsquo;t just encrypt blindly. They work systematically: escalate privileges first, then locate the backup infrastructure – backup servers, NAS shares, cloud backups – and eliminate the backups first. On top comes the second extortion stage: data is copied before encryption and used as leverage (double extortion). Your backups only help if they survive the encryption – and having your data leaked changes nothing about your reporting obligations.\nThis leads to the most important rule: at least one copy must be out of the attacker\u0026rsquo;s reach. Offline, immutable, or in a separate tenant – what matters is that an attacker with domain admin rights cannot delete it along with everything else.\n3-2-1-1-0: the rule that counts The classic 3-2-1 rule has gained an addition that responds to ransomware:\n3 copies of the data (original plus two backups) 2 different media types or systems 1 copy offline or immutable 1 tested restore – nothing counts unless it has been played back at least once 0 errors during restore verification The last point is where it almost always breaks. A backup that has never been tested is not a backup – it\u0026rsquo;s a hope.\nThe four mistakes I see most often Backups on the same system as the data. The NAS backs up to itself, the backup software runs as domain admin – one compromise and every copy is gone. Restore never attempted. The backup job runs green, but whether the database re-import actually works, nobody knows – until the incident. Microsoft 365 without backup. \u0026ldquo;It\u0026rsquo;s in the cloud\u0026rdquo; – yes, but cloud mailboxes and SharePoint have no ransomware-proof version history of unlimited depth. Deleted or encrypted content needs its own backup. No recovery order. When everything is equally important, nothing is. Without a defined order (domain controllers and finance first, the rest later), you lose the first critical days to discussions. The 5-minute check For exactly these points I built a backup self-assessment: six yes/no questions based on the 3-2-1 rule, with an honest assessment. Runs entirely in your browser – no data is transmitted.\nIf the check shows gaps: that\u0026rsquo;s exactly what my Security Audit and a backup \u0026amp; recovery concept are for, which I set up with you – including a tested restore instead of theory. Before that, you can meet me in the free 30-minute intro call.\nThe self-assessment is a first orientation and does not replace an assessment of your actual environment.\n","permalink":"https://heidelsec.de/en/posts/2026-09-13-ransomware-backup-check/","summary":"\u003cp\u003eThe good news first: most ransomware cases are not decided during the attack, but during recovery. Companies with usable backups and a rehearsed recovery get away with a bad weekend. Those without end up negotiating ransom demands. The difference lies in a handful of decisions made in advance – and that is what this article is about.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"why-attackers-go-for-your-backups-first\"\u003eWhy attackers go for your backups first\u003c/h2\u003e\n\u003cp\u003eModern ransomware groups don\u0026rsquo;t just encrypt blindly. They work systematically: escalate privileges first, then locate the backup infrastructure – backup servers, NAS shares, cloud backups – and \u003cstrong\u003eeliminate the backups first\u003c/strong\u003e. On top comes the second extortion stage: data is copied before encryption and used as leverage (double extortion). Your backups only help if they survive the encryption – and having your data leaked changes nothing about your reporting obligations.\u003c/p\u003e","title":"Ransomware: Will your backups hold up when it hits?"},{"content":"\u0026ldquo;Does NIS2 apply to us?\u0026rdquo; — lately I hear this question from almost every mid-sized company in my region. Understandable: the directive covers far more businesses than its predecessor, and the uncertainty about what exactly applies is huge. The good news: whether you\u0026rsquo;re probably in scope can be narrowed down with three questions. That\u0026rsquo;s what this article is about.\nWhat NIS2 is — and where Germany stands now The NIS2 Directive ((EU) 2022/2555) is the successor to the first NIS Directive and requires member states to make cybersecurity mandatory for essential and important entities. At its core: organised risk management, reporting of significant incidents, and management responsibility.\nImportant current status: The German implementing law (NIS2UmsuCG, BGBl I 2025 No. 301) has been in force since December 6, 2025 — and the statutory registration deadline has already passed (March 2026). In-scope entities must register via an ELSTER organisation certificate („Mein Unternehmenskonto“) and in the BSI portal (§ 33(6) BSIG). If you are in scope and have not registered yet: register immediately — the BSI is explicitly calling for it. Alongside registration, the obligations apply: risk management, reporting deadlines, management training.\nThe BSI also offers an official NIS-2 scope-of-application check — sensible as a first rough assessment. The three questions below show the logic behind that assessment.\nThe three questions that decide 1. Sector The directive distinguishes two groups of sectors:\nSectors of high criticality: energy, transport, banking and finance, health, drinking and waste water, digital infrastructure including ICT service management for businesses, public administration, space. Other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing (e.g. machinery, vehicles, electronics), digital providers such as marketplaces and search engines, research. If you\u0026rsquo;re not active in any of these sectors, a direct obligation is unlikely — but keep reading, because there are exceptions.\n2. Size The sector alone isn\u0026rsquo;t enough; company size matters:\nLarge companies (typically 250+ employees or more than €50 million annual turnover) in high-criticality sectors are usually essential entities — with the most extensive obligations. Medium-sized companies (typically 50+ employees or more than €10 million annual turnover) in high-criticality sectors, plus medium and large companies in other critical sectors, are usually important entities. 3. Role And then there are service providers that can be in scope regardless of their sector: managed service providers (running IT operations for clients), managed security service providers, cloud hosting and data centres, as well as DNS and domain services. IT providers who see themselves as \u0026ldquo;just a small shop\u0026rdquo; are more often in focus than they think.\nEven without an obligation: the supply chain comes for you This is often overlooked: even if you don\u0026rsquo;t fall directly under NIS2, you will feel the directive through your customers. Companies in scope must secure their supply chain and are increasingly passing security requirements on to their partners and suppliers. If you don\u0026rsquo;t have the basics under control (risk management, MFA, tested backups, an incident response plan), you\u0026rsquo;ll notice it at the latest when the next big customer sends their security questionnaire.\nWhat you can do concretely Clarify applicability. Sector, size, role — that narrows the probability down well. For exactly these questions I built a NIS2 self-assessment that gives you a first assessment. Runs entirely in your browser, takes a few minutes. Assess your current state. If NIS2 probably applies: where do you stand on risk management, reporting, baseline measures? Prioritise the gaps. Not everything at once — first the measures with the biggest risk impact. Execute and document the roadmap. Authorities and customers don\u0026rsquo;t ask \u0026ldquo;What did you think?\u0026rdquo;, they ask \u0026ldquo;What did you implement?\u0026rdquo;. If you want clarity after the self-assessment: that\u0026rsquo;s exactly what my NIS2 Readiness Check is for — applicability analysis, gap analysis, and a prioritised action plan. Before that, you can meet me in the free 30-minute intro call.\nThe self-assessment is an orientation based on the EU directive and does not constitute legal advice — the binding German implementation may regulate details differently.\n","permalink":"https://heidelsec.de/en/posts/2026-09-12-nis2-pflichtig-check-fuer-kmu/","summary":"\u003cp\u003e\u0026ldquo;Does NIS2 apply to us?\u0026rdquo; — lately I hear this question from almost every mid-sized company in my region. Understandable: the directive covers far more businesses than its predecessor, and the uncertainty about what exactly applies is huge. The good news: whether you\u0026rsquo;re probably in scope can be narrowed down with three questions. That\u0026rsquo;s what this article is about.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"what-nis2-is--and-where-germany-stands-now\"\u003eWhat NIS2 is — and where Germany stands now\u003c/h2\u003e\n\u003cp\u003eThe NIS2 Directive ((EU) 2022/2555) is the successor to the first NIS Directive and requires member states to make cybersecurity mandatory for \u003cstrong\u003eessential\u003c/strong\u003e and \u003cstrong\u003eimportant\u003c/strong\u003e entities. At its core: organised risk management, reporting of significant incidents, and management responsibility.\u003c/p\u003e","title":"Does NIS2 apply to you? The 5-minute check for your company"},{"content":"Why Pandas Instead of Excel Formulas? Excel is ideal for simple tables, but with larger datasets it quickly becomes unwieldy. With Pandas, you can read, analyze, and statistically evaluate Excel files – reproducibly and automatically.\nInstallation pip install pandas openpyxl openpyxl is required for Excel files (.xlsx).\nReading Excel Files import pandas as pd # Read Excel file df = pd.read_excel(\u0026#39;sales_data.xlsx\u0026#39;, sheet_name=\u0026#39;Revenue\u0026#39;) # First look at the data print(df.head()) print(df.info()) Important parameters:\nsheet_name='Name' – Select specific worksheet usecols='A:E' – Read only specific columns skiprows=2 – Skip first rows Basic Statistics # Quick overview print(df.describe()) # Individual statistics print(f\u0026#34;Average: ${df[\u0026#39;Revenue\u0026#39;].mean():.2f}\u0026#34;) print(f\u0026#34;Median: ${df[\u0026#39;Revenue\u0026#39;].median():.2f}\u0026#34;) print(f\u0026#34;Minimum: ${df[\u0026#39;Revenue\u0026#39;].min():.2f}\u0026#34;) print(f\u0026#34;Maximum: ${df[\u0026#39;Revenue\u0026#39;].max():.2f}\u0026#34;) print(f\u0026#34;Total: ${df[\u0026#39;Revenue\u0026#39;].sum():.2f}\u0026#34;) Output:\nAverage: $15234.56 Median: $12300.00 Minimum: $450.00 Maximum: $89700.00 Total: $2134561.23 Grouped Analysis # Revenue by product revenue_by_product = df.groupby(\u0026#39;Product\u0026#39;)[\u0026#39;Revenue\u0026#39;].agg([ (\u0026#39;Count\u0026#39;, \u0026#39;count\u0026#39;), (\u0026#39;Total\u0026#39;, \u0026#39;sum\u0026#39;), (\u0026#39;Average\u0026#39;, \u0026#39;mean\u0026#39;) ]) print(revenue_by_product) Result:\nCount Total Average Product Laptop 45 678900.0 15086.67 Monitor 89 234560.0 2636.18 Keyboard 156 23450.0 150.32 Filtering and Conditions # Revenue over $10,000 high_revenue = df[df[\u0026#39;Revenue\u0026#39;] \u0026gt; 10000] # Multiple conditions premium_sales = df[ (df[\u0026#39;Revenue\u0026#39;] \u0026gt; 10000) \u0026amp; (df[\u0026#39;Product\u0026#39;] == \u0026#39;Laptop\u0026#39;) ] # Filter by date df[\u0026#39;Date\u0026#39;] = pd.to_datetime(df[\u0026#39;Date\u0026#39;]) q1_2026 = df[(df[\u0026#39;Date\u0026#39;] \u0026gt;= \u0026#39;2026-01-01\u0026#39;) \u0026amp; (df[\u0026#39;Date\u0026#39;] \u0026lt;= \u0026#39;2026-03-31\u0026#39;)] print(f\u0026#34;Q1 Revenue: ${q1_2026[\u0026#39;Revenue\u0026#39;].sum():.2f}\u0026#34;) Monthly Analysis # Set date as index df[\u0026#39;Date\u0026#39;] = pd.to_datetime(df[\u0026#39;Date\u0026#39;]) df.set_index(\u0026#39;Date\u0026#39;, inplace=True) # Monthly sums monthly = df.resample(\u0026#39;M\u0026#39;)[\u0026#39;Revenue\u0026#39;].agg([ \u0026#39;sum\u0026#39;, \u0026#39;mean\u0026#39;, \u0026#39;count\u0026#39; ]) print(monthly) Output:\nsum mean count Date 2026-01-31 456234.50 15207.82 30 2026-02-28 389012.30 14037.60 28 Top/Flop Analysis # Top 10 revenue top10 = df.nlargest(10, \u0026#39;Revenue\u0026#39;)[[\u0026#39;Product\u0026#39;, \u0026#39;Customer\u0026#39;, \u0026#39;Revenue\u0026#39;]] # Bottom 5 flop5 = df.nsmallest(5, \u0026#39;Revenue\u0026#39;)[[\u0026#39;Product\u0026#39;, \u0026#39;Revenue\u0026#39;]] print(\u0026#34;Top 10 Deals:\u0026#34;) print(top10) Writing Results Back to Excel # Single sheet revenue_by_product.to_excel(\u0026#39;analysis.xlsx\u0026#39;, sheet_name=\u0026#39;Product Stats\u0026#39;) # Multiple sheets with pd.ExcelWriter(\u0026#39;analysis.xlsx\u0026#39;) as writer: revenue_by_product.to_excel(writer, sheet_name=\u0026#39;Products\u0026#39;) monthly.to_excel(writer, sheet_name=\u0026#39;Monthly\u0026#39;) top10.to_excel(writer, sheet_name=\u0026#39;Top10\u0026#39;, index=False) print(\u0026#34;Analysis saved: analysis.xlsx\u0026#34;) Practical Example: Sales Report import pandas as pd from datetime import datetime # Read data df = pd.read_excel(\u0026#39;sales_data.xlsx\u0026#39;) df[\u0026#39;Date\u0026#39;] = pd.to_datetime(df[\u0026#39;Date\u0026#39;]) # Define period today = datetime.now() last_month = today - pd.DateOffset(months=1) df_month = df[df[\u0026#39;Date\u0026#39;] \u0026gt;= last_month] # Calculate statistics report = { \u0026#39;Total Revenue\u0026#39;: df_month[\u0026#39;Revenue\u0026#39;].sum(), \u0026#39;Average\u0026#39;: df_month[\u0026#39;Revenue\u0026#39;].mean(), \u0026#39;Number of Sales\u0026#39;: len(df_month), \u0026#39;Best Product\u0026#39;: df_month.groupby(\u0026#39;Product\u0026#39;)[\u0026#39;Revenue\u0026#39;].sum().idxmax(), \u0026#39;Top Customer\u0026#39;: df_month.groupby(\u0026#39;Customer\u0026#39;)[\u0026#39;Revenue\u0026#39;].sum().idxmax() } # As DataFrame for Excel report_df = pd.DataFrame([report]) report_df.to_excel(\u0026#39;monthly_report.xlsx\u0026#39;, index=False) print(\u0026#34;Monthly report created!\u0026#34;) for key, value in report.items(): print(f\u0026#34;{key}: {value}\u0026#34;) Common Problems Excel File is Too Large # Load only required columns df = pd.read_excel(\u0026#39;large_file.xlsx\u0026#39;, usecols=[\u0026#39;Date\u0026#39;, \u0026#39;Revenue\u0026#39;]) # Or: Read only sample df = pd.read_excel(\u0026#39;large_file.xlsx\u0026#39;, nrows=10000) Missing Values # Check for NaN values print(df.isnull().sum()) # Remove or replace NaN df_clean = df.dropna() # Remove rows with NaN df[\u0026#39;Revenue\u0026#39;].fillna(0, inplace=True) # Replace NaN with 0 Date Formats # Parse date with format df[\u0026#39;Date\u0026#39;] = pd.to_datetime(df[\u0026#39;Date\u0026#39;], format=\u0026#39;%m/%d/%Y\u0026#39;) # Handle different date formats df[\u0026#39;Date\u0026#39;] = pd.to_datetime(df[\u0026#39;Date\u0026#39;], format=\u0026#39;%d.%m.%Y\u0026#39;) Conclusion Pandas makes Excel analysis faster, repeatable, and scalable. Instead of complex formulas in Excel, write Python code once and simply re-run it with new data.\nWhen to use Pandas instead of Excel?\n✅ Large datasets (\u0026gt; 100,000 rows) ✅ Recurring analyses ✅ Complex groupings ✅ Automation (cronjobs, pipelines) When Excel is sufficient?\n📊 One-time, small analyses 📊 Visualizations for presentations 📊 Ad-hoc analysis without code Further Resources:\nPandas Documentation 10 minutes to pandas ","permalink":"https://heidelsec.de/en/posts/2026-02-21-pandas-excel-statistics/","summary":"\u003ch2 id=\"why-pandas-instead-of-excel-formulas\"\u003eWhy Pandas Instead of Excel Formulas?\u003c/h2\u003e\n\u003cp\u003eExcel is ideal for simple tables, but with larger datasets it quickly becomes unwieldy. With \u003cstrong\u003ePandas\u003c/strong\u003e, you can read, analyze, and statistically evaluate Excel files – reproducibly and automatically.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003epip install pandas openpyxl\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003ccode\u003eopenpyxl\u003c/code\u003e is required for Excel files (.xlsx).\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"reading-excel-files\"\u003eReading Excel Files\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"kn\"\u003eimport\u003c/span\u003e \u003cspan class=\"nn\"\u003epandas\u003c/span\u003e \u003cspan class=\"k\"\u003eas\u003c/span\u003e \u003cspan class=\"nn\"\u003epd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"c1\"\u003e# Read Excel file\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"n\"\u003epd\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003eread_excel\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;sales_data.xlsx\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e \u003cspan class=\"n\"\u003esheet_name\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;Revenue\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"c1\"\u003e# First look at the data\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003ehead\u003c/span\u003e\u003cspan class=\"p\"\u003e())\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003einfo\u003c/span\u003e\u003cspan class=\"p\"\u003e())\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eImportant parameters:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003esheet_name='Name'\u003c/code\u003e – Select specific worksheet\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eusecols='A:E'\u003c/code\u003e – Read only specific columns\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eskiprows=2\u003c/code\u003e – Skip first rows\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"basic-statistics\"\u003eBasic Statistics\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"c1\"\u003e# Quick overview\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003edescribe\u003c/span\u003e\u003cspan class=\"p\"\u003e())\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"c1\"\u003e# Individual statistics\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"sa\"\u003ef\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;Average: $\u003c/span\u003e\u003cspan class=\"si\"\u003e{\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;Revenue\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e]\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003emean\u003c/span\u003e\u003cspan class=\"p\"\u003e()\u003c/span\u003e\u003cspan class=\"si\"\u003e:\u003c/span\u003e\u003cspan class=\"s2\"\u003e.2f\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"sa\"\u003ef\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;Median: $\u003c/span\u003e\u003cspan class=\"si\"\u003e{\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;Revenue\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e]\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003emedian\u003c/span\u003e\u003cspan class=\"p\"\u003e()\u003c/span\u003e\u003cspan class=\"si\"\u003e:\u003c/span\u003e\u003cspan class=\"s2\"\u003e.2f\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"sa\"\u003ef\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;Minimum: $\u003c/span\u003e\u003cspan class=\"si\"\u003e{\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;Revenue\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e]\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003emin\u003c/span\u003e\u003cspan class=\"p\"\u003e()\u003c/span\u003e\u003cspan class=\"si\"\u003e:\u003c/span\u003e\u003cspan class=\"s2\"\u003e.2f\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"sa\"\u003ef\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;Maximum: $\u003c/span\u003e\u003cspan class=\"si\"\u003e{\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;Revenue\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e]\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003emax\u003c/span\u003e\u003cspan class=\"p\"\u003e()\u003c/span\u003e\u003cspan class=\"si\"\u003e:\u003c/span\u003e\u003cspan class=\"s2\"\u003e.2f\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nb\"\u003eprint\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"sa\"\u003ef\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;Total: $\u003c/span\u003e\u003cspan class=\"si\"\u003e{\u003c/span\u003e\u003cspan class=\"n\"\u003edf\u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;Revenue\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e]\u003c/span\u003e\u003cspan class=\"o\"\u003e.\u003c/span\u003e\u003cspan class=\"n\"\u003esum\u003c/span\u003e\u003cspan class=\"p\"\u003e()\u003c/span\u003e\u003cspan class=\"si\"\u003e:\u003c/span\u003e\u003cspan class=\"s2\"\u003e.2f\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eOutput:\u003c/strong\u003e\u003c/p\u003e","title":"Excel Analysis with Pandas – Quick Statistics Without Formulas"},{"content":"DNS is one of the most critical infrastructure components on the internet – and simultaneously one of the most vulnerable. DNSSEC (Domain Name System Security Extensions) was developed to close fundamental security gaps in DNS. Despite its importance, DNSSEC is often misunderstood or incorrectly implemented.\nWhat is DNSSEC and Why Does it Matter? Classic DNS has a fundamental problem: there\u0026rsquo;s no way to verify whether a DNS response actually comes from the authoritative nameserver or has been manipulated by an attacker. This enables attacks such as:\nDNS Spoofing: Attackers redirect users to fake websites Cache Poisoning: Manipulation of DNS caches with false entries Man-in-the-Middle Attacks: Interception and redirection of traffic DNSSEC solves this problem through cryptographic signatures. Every DNS response is digitally signed, allowing the recipient to verify the authenticity and integrity of the data.\nHow Does DNSSEC Work? DNSSEC extends DNS with four new record types:\nRRSIG (Resource Record Signature): Contains the cryptographic signature for a DNS record DNSKEY: Contains the public key for signature verification DS (Delegation Signer): Links the chain of trust to the parent zone NSEC/NSEC3: Proves the non-existence of records (important for negative responses) The chain of trust begins at the root zone and flows across all levels down to the target domain. Each level signs the keys of the next level.\nExample: www.example.com\nRoot (.) → signs .com .com → signs example.com example.com → signs www.example.com Common DNSSEC Implementation Mistakes 1. Missing Key Rotation DNSSEC keys must be rotated regularly. Many administrators forget this or lack automation for it.\nBest Practice:\nZSK (Zone Signing Key): Rotation every 1-3 months KSK (Key Signing Key): Rotation every 1-2 years Automation with tools like dnssec-keymgr or cloud provider features 2. Broken Chain of Trust The DS records at the registry (e.g., at .com or .de) must match the DNSKEY records of the zone. After a key rotation, the DS record must be updated.\nSymptom: Domain becomes unreachable when the resolver validates DNSSEC.\n3. Incorrect TTL Values During key rotation, TTL values must be considered to prevent old signatures from remaining in the cache.\nBest Practice: TTL of DNSKEY records should be at least 1 day to enable safe rollovers.\n4. NSEC vs. NSEC3 NSEC allows \u0026ldquo;zone walking\u0026rdquo; – attackers can enumerate all records of a zone. NSEC3 fixes this through hashing.\nRecommendation for production environments: NSEC3 with opt-out for unsigned delegations.\nImplementing DNSSEC in Practice Step 1: Generate Keys # Generate KSK (Key Signing Key) dnssec-keygen -a ECDSAP256SHA256 -f KSK example.com # Generate ZSK (Zone Signing Key) dnssec-keygen -a ECDSAP256SHA256 example.com Why ECDSA?: ECDSA P-256 offers good security with small signature sizes, keeping DNS responses efficient.\nStep 2: Sign the Zone dnssec-signzone -A -3 $(head -c 1000 /dev/random | sha1sum | cut -b 1-16) \\ -N INCREMENT -o example.com -t example.com.zone Step 3: Submit DS Record to Registry dnssec-dsfromkey -2 Kexample.com.+013+12345.key Submit the generated DS record to your domain registrar.\nStep 4: Test Validation # Check with dig dig +dnssec example.com # Visualize with DNSViz https://dnsviz.net/d/example.com/dnssec/ DNSSEC with Cloud Providers Most cloud DNS providers offer DNSSEC support:\nCloudflare: One-click activation, automatic key rotation AWS Route 53: Full DNSSEC support since 2020, key management with KMS Google Cloud DNS: Managed DNSSEC with automatic rotation Advantage: The provider handles key management and rotation. Disadvantage: You\u0026rsquo;re dependent on the provider and have less control.\nWho Should Use DNSSEC? DNSSEC should be considered for:\nFinancial services: Protection against phishing and spoofing E-commerce: Trust in domain authenticity Critical infrastructure: Protection against targeted attacks Compliance requirements: Some standards mandate DNSSEC DNSSEC is Not a Silver Bullet Important limitations:\nNo transport encryption protection: DNSSEC only validates authenticity, not confidentiality. DNS queries remain visible in plaintext. Solution: Additionally use DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) Complexity: DNSSEC increases operational complexity and requires careful key management No guarantee: Not all resolvers validate DNSSEC Conclusion DNSSEC is an important security measure that prevents DNS-based attacks. Implementation requires care, especially regarding key management and the chain of trust.\nMy recommendation:\nUse managed DNSSEC from cloud providers when possible – this drastically reduces error sources Test extensively in a staging environment before production rollout Automate key rotation from the start Continuously monitor your DNSSEC configuration with tools like DNSViz If you have questions about DNSSEC implementation or need a security audit of your DNS infrastructure, I\u0026rsquo;m happy to help.\nTools and Resources:\nDNSViz – DNSSEC visualization and validation Verisign DNSSEC Debugger – Testing tool BIND DNSSEC Guide – Comprehensive documentation ","permalink":"https://heidelsec.de/en/posts/2026-02-20-dnssec-verstehen-und-richtig-einsetzen/","summary":"\u003cp\u003eDNS is one of the most critical infrastructure components on the internet – and simultaneously one of the most vulnerable. DNSSEC (Domain Name System Security Extensions) was developed to close fundamental security gaps in DNS. Despite its importance, DNSSEC is often misunderstood or incorrectly implemented.\u003c/p\u003e\n\u003ch2 id=\"what-is-dnssec-and-why-does-it-matter\"\u003eWhat is DNSSEC and Why Does it Matter?\u003c/h2\u003e\n\u003cp\u003eClassic DNS has a fundamental problem: there\u0026rsquo;s no way to verify whether a DNS response actually comes from the authoritative nameserver or has been manipulated by an attacker. This enables attacks such as:\u003c/p\u003e","title":"Understanding and Implementing DNSSEC Correctly"},{"content":"Saving a Website for Offline Use Using wget, you can download an entire website for offline access with this command:\nwget -rkpNc -e robots=off http://www.example.com/ Parameters Explained -r: Download pages recursively. -k: Adjust links for local viewing. -p: Fetch all resources (images, scripts). -N: Only download new or modified files. -e robots=off: Ignore robots.txt restrictions. -c: Continue the download if interrupted. With this command, wget reliably saves the entire site for offline use.\n","permalink":"https://heidelsec.de/en/posts/2024-11-08-wget-mirror-website/","summary":"\u003ch2 id=\"saving-a-website-for-offline-use\"\u003eSaving a Website for Offline Use\u003c/h2\u003e\n\u003cp\u003eUsing \u003ccode\u003ewget\u003c/code\u003e, you can download an entire website for offline access with this command:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003ewget -rkpNc -e \u003cspan class=\"nv\"\u003erobots\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003eoff http://www.example.com/\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"parameters-explained\"\u003eParameters Explained\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003e-r\u003c/code\u003e\u003c/strong\u003e: Download pages recursively.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003e-k\u003c/code\u003e\u003c/strong\u003e: Adjust links for local viewing.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003e-p\u003c/code\u003e\u003c/strong\u003e: Fetch all resources (images, scripts).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003e-N\u003c/code\u003e\u003c/strong\u003e: Only download new or modified files.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003e-e robots=off\u003c/code\u003e\u003c/strong\u003e: Ignore \u003ccode\u003erobots.txt\u003c/code\u003e restrictions.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003e-c\u003c/code\u003e\u003c/strong\u003e: Continue the download if interrupted.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eWith this command, \u003ccode\u003ewget\u003c/code\u003e reliably saves the entire site for offline use.\u003c/p\u003e","title":"Download a Complete Website with wget"},{"content":"cAdvisor on Synology Running cAdvisor in Docker on Synology was a challenge, as it often wouldn\u0026rsquo;t start despite no changes to the launch options. The issue turned out to be related to the inotify settings.\nThe Problem When running the following command to start cAdvisor:\ndocker run --name=cadvisor \\ --volume=\u0026#34;/:/rootfs:ro\u0026#34; \\ --volume=\u0026#34;/var/run:/var/run:ro\u0026#34; \\ --volume=\u0026#34;/sys:/sys:ro\u0026#34; \\ --volume=\u0026#34;/var/packages/ContainerManager/var/docker/:/var/lib/docker:ro\u0026#34; \\ --security-opt no-new-privileges=true \\ --restart=on-failure:5 \\ google/cadvisor:latest --docker_only=true cadvisor: image: gcr.io/cadvisor/cadvisor:latest container_name: cadvisor read_only: true security_opt: - no-new-privileges=true command: - \u0026#34;--docker_only=true\u0026#34; volumes: - /:/rootfs:ro - /var/run:/var/run:ro - /sys:/sys:ro - /var/packages/ContainerManager/var/docker/:/var/lib/docker:ro restart: on-failure:5 I encountered the error:\nF0701 00:00:00.000000 1 cadvisor.go:156] Failed to start container manager: inotify_add_watch /sys/fs/cgroup/cpu: no space left on device This was caused by an insufficient number of inotify watches.\nThe Solution To fix this, I used the Synology Task Scheduler to set the max_user_watches value at startup:\nOpen the Task Scheduler in Synology DSM.\nCreate a new User-defined Script.\nSet the task to run at Startup.\nIn the script field, add the following command:\nsysctl fs.inotify.max_user_watches=104857 Save the task.\nThis ensures that the inotify watch limit is increased every time the Synology NAS starts up, preventing the issue with cAdvisor. This simple fix solved the problem and allowed cAdvisor to run smoothly on my Synology NAS.\n","permalink":"https://heidelsec.de/en/posts/2024-11-07-docker-cadvisor-synology/","summary":"\u003ch2 id=\"cadvisor-on-synology\"\u003ecAdvisor on Synology\u003c/h2\u003e\n\u003cp\u003eRunning cAdvisor in Docker on Synology was a challenge, as it often wouldn\u0026rsquo;t start despite no changes to the launch options. The issue turned out to be related to the \u003ccode\u003einotify\u003c/code\u003e settings.\u003c/p\u003e\n\u003ch3 id=\"the-problem\"\u003eThe Problem\u003c/h3\u003e\n\u003cp\u003eWhen running the following command to start cAdvisor:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003edocker run --name\u003cspan class=\"o\"\u003e=\u003c/span\u003ecadvisor \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  --volume\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;/:/rootfs:ro\u0026#34;\u003c/span\u003e \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  --volume\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;/var/run:/var/run:ro\u0026#34;\u003c/span\u003e \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  --volume\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;/sys:/sys:ro\u0026#34;\u003c/span\u003e \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  --volume\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;/var/packages/ContainerManager/var/docker/:/var/lib/docker:ro\u0026#34;\u003c/span\u003e \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  --security-opt no-new-privileges\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"nb\"\u003etrue\u003c/span\u003e \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  --restart\u003cspan class=\"o\"\u003e=\u003c/span\u003eon-failure:5 \u003cspan class=\"se\"\u003e\\\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  google/cadvisor:latest --docker_only\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"nb\"\u003etrue\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-yml\" data-lang=\"yml\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003ecadvisor\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003eimage\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003egcr.io/cadvisor/cadvisor:latest\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003econtainer_name\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003ecadvisor\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003eread_only\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"kc\"\u003etrue\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003esecurity_opt\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e- \u003cspan class=\"kc\"\u003eno\u003c/span\u003e-\u003cspan class=\"l\"\u003enew-privileges=true\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003ecommand\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e- \u003cspan class=\"s2\"\u003e\u0026#34;--docker_only=true\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003evolumes\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e- \u003cspan class=\"l\"\u003e/:/rootfs:ro\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e- \u003cspan class=\"l\"\u003e/var/run:/var/run:ro\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e- \u003cspan class=\"l\"\u003e/sys:/sys:ro\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e- \u003cspan class=\"l\"\u003e/var/packages/ContainerManager/var/docker/:/var/lib/docker:ro\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003erestart\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"kc\"\u003eon\u003c/span\u003e-\u003cspan class=\"l\"\u003efailure:5\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eI encountered the error:\u003c/p\u003e","title":"cAdvisor on Synology"},{"content":"This is the first blog post on my new website. I am very excited to share my thoughts and ideas with the world!\nWhat I will cover in this blog I plan to write about several topics in this blog, including:\nAutomation Data Science IT Security I hope you are interested in some of these topics and that you will enjoy my future posts.\nUntil next time!\n","permalink":"https://heidelsec.de/en/posts/2023-03-25-hello-world/","summary":"\u003cp\u003eThis is the first blog post on my new website. I am very excited to share my thoughts and ideas with the world!\u003c/p\u003e\n\u003ch2 id=\"what-i-will-cover-in-this-blog\"\u003eWhat I will cover in this blog\u003c/h2\u003e\n\u003cp\u003eI plan to write about several topics in this blog, including:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAutomation\u003c/li\u003e\n\u003cli\u003eData Science\u003c/li\u003e\n\u003cli\u003eIT Security\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eI hope you are interested in some of these topics and that you will enjoy my future posts.\u003c/p\u003e\n\u003cp\u003eUntil next time!\u003c/p\u003e","title":"My first blog post"},{"content":"Free security tools for daily use. The checks run in your browser – the domain checks transmit only the domain name.\n🔑 Password Strength Checker 🔐 Password Generator 🌐 Domain, DNS \u0026 Mail Check 🧯 Backup Self-Assessment 🔒 MFA Self-Assessment 🛡️ NIS2 Self-Assessment 🔑 Password Strength Checker Check the strength of an existing password.\n👁️ Anzeigen Passwort-Stärke: Analyse: Entropie: Bit\nGeschätzte Crack-Zeit: Verbesserungsvorschläge: ℹ️ Hinweis: Die Passwort-Analyse erfolgt ausschließlich in Ihrem Browser. Das Passwort wird nicht gespeichert oder übertragen. Crack-Zeiten sind Schätzungen für einen Offline-Angriff mit 100 Mrd. Versuchen/Sekunde (z. B. gegen unsalted MD5) — gegen bcrypt oder Argon2 verlängern sich die Werte deutlich.\n🔐 Password Generator Generate cryptographically secure random passwords using crypto.getRandomValues().\nPasswort-Länge: 31 Großbuchstaben (A-Z) Kleinbuchstaben (a-z) Zahlen (0-9) Sonderzeichen (!@#$%^\u0026*) Mehrdeutige Zeichen ausschließen (0, O, l, I, 1) Passwort generieren Kopieren Passwort-Stärke: ℹ️ Hinweis: Alle Passwörter werden ausschließlich in Ihrem Browser generiert. Keine Daten werden an einen Server übertragen.\n🌐 Domain, DNS \u0026amp; Mail Security Check E-mail (SPF, DKIM, DMARC, MX), SSL/HTTPS, and DNS (including DNSSEC, nameserver redundancy, and IPv6) at a glance in 10 seconds: Are all security settings correct for your domain?\nE-mail (SPF/DKIM/DMARC), SSL/HTTPS and DNS at a glance: Are all security settings correct for your domain? Checked in 10 seconds – runs in your browser and through our security checks.\nCheck now Would you like to resolve open findings?\nLet's discuss the technical details in a free 30-minute intro call.\n📅 Book intro call ℹ️ Note: The check reads public DNS records via Cloudflare DNS-over-HTTPS and verifies HTTP/SSL reachability. No private credentials or mailbox contents are transmitted.\n🧯 Backup Self-Assessment Will your backups hold up when ransomware hits? Six yes/no questions based on the 3-2-1 rule – with an honest evaluation. Runs entirely locally in your browser.\nSix yes/no questions based on the 3-2-1 rule and what ransomware groups attack first. Unchecked counts as \"no\" – honesty pays off.\nThere are at least three copies of the data – original plus two independent backups. The copies live on at least two separate paths (e.g. on-site NAS and cloud). At least one copy is stored offline or immutably. A restore was actually tested within the last 6 months – single file or full system. For critical systems it is known how long recovery takes and in which order to work. Cloud data (e.g. Microsoft 365, Google Workspace) is included in the backup. Evaluate 0 / 6 🚨 Critical risk As it looks, your data would hardly be recoverable in a real incident – exactly the scenario where companies end up paying or giving up. Priority one: at least one offline/immutable copy and a restore that has actually been rehearsed.\n⚠️ Partially covered The basics are in place – but the missing points are precisely what ransomware groups exploit: the copy that is not separated, the restore that was never tested, the cloud mailbox nobody backed up.\n✅ Well positioned The foundation is solid. Remaining risks usually hide in the details: exceptions to the rule, permissions on the backup server, a recovery plan that only exists on paper. An outside look is worthwhile.\n📅 Book an intro call (free) More about backup and recovery concepts ℹ️ Note: Orientation, not a guarantee: the check condenses proven rules (3-2-1-1-0) and does not replace an assessment of your actual environment. All answers stay local in your browser.\n🔒 MFA Self-Assessment Where is multi-factor authentication missing? Eight yes/no questions about the access points attackers target first – with an honest evaluation. Runs entirely locally in your browser.\nEight yes/no questions on multi-factor authentication (MFA) – the single most effective protection against compromised credentials. Unchecked counts as \"no\" – honesty pays off.\nAdmin accounts (servers, NAS, cloud) require multi-factor authentication. All corporate mailboxes require multi-factor authentication. Cloud services (Microsoft 365, Google Workspace, others) require multi-factor authentication. VPN and remote access require multi-factor authentication. Online banking and payment accounts require multi-factor authentication. The code comes from an authenticator app or a hardware key – not just via SMS. There is a documented way back if the phone is lost (backup codes, spare key). New accounts and systems get MFA from day one – not retrofitted. Evaluate 0 / 8 🚨 MFA is missing almost everywhere This is the most common finding I see in audits: a single compromised password is enough to reach email, cloud, and admin access. MFA is by far the most effective single lever – and in most cases quick to add.\n⚠️ Partially protected The basics are in place – but the gaps are exactly what attackers take: the mailbox without MFA, the remote access, the banking, the SMS code that can be intercepted. Attackers only need one open point.\n✅ Well positioned MFA is the most important piece – and it is in place. The remaining levers are elsewhere: password management, permissions, monitoring, and a recovery path that actually works under pressure.\n📅 Book an intro call (free) More about access control and hardening ℹ️ Note: Orientation, not a guarantee: the check condenses proven MFA principles and does not replace an assessment of your actual environment. All answers stay local in your browser.\n🛡️ NIS2 Self-Assessment Not sure whether NIS2 applies to your company? Four questions on sector, role and size – plus a quick check of your security foundation. Runs locally in your browser.\n1. Which sector is your company active in? Please choose… Energy (electricity, gas, heating, oil) Transport (rail, air, water, road) Banking \u0026 finance Health (hospitals, pharmacies, labs) Drinking \u0026amp; waste water Digital infrastructure \u0026amp; ICT service management (B2B) Public administration Space Postal \u0026amp; courier services Waste management Chemicals (incl. hazardous substances) Food Manufacturing (machinery, vehicles, electronics) Digital providers (marketplaces, search engines, social networks) Research None of these 2. Does your company provide any of these services to third parties? Managed service provider (IT operations for clients) Managed security service provider Cloud hosting, data centre or CDN DNS service or domain registration 3. How many employees does your company have? Please choose… Fewer than 50 50–249 250 or more 4. What is your annual turnover? Please choose… Below €10 million €10–50 million Above €50 million Evaluate Please answer all four questions first. ✅ Probably an essential entity With high probability your company falls within the scope of NIS2 — with the most extensive obligations: risk management, reporting of significant incidents, and management responsibility. Time to assess your current state and close the gaps in priority order.\n✅ Probably an important entity Even as an \"important entity\", NIS2 obligations apply to you: risk management, reporting of significant incidents and baseline security measures. The requirements are somewhat lighter than for essential entities — but supervision and reporting duties still apply.\nℹ️ Probably not directly in scope You probably don't fall directly under NIS2. However: companies outside the scope still feel NIS2 through the supply chain — customers in scope increasingly expect security evidence from their partners. It pays to put the basics in place before that request arrives.\nBonus: How solid is your foundation? Which of these are already in place?\nRisk management / ISMS in place MFA for remote access and admin accounts Backups including tested restore Documented incident response plan Central logging / monitoring Structured patch management Supplier assessment (supply chain security) 0 % · 📅 Book an intro call (free) More about the NIS2 Readiness Check ℹ️ Note: Orientation, not legal advice: this check is based on EU Directive (EU) 2022/2555 (\"NIS2\"). The binding German implementation (NIS2UmsuCG) may regulate details differently — only an individual assessment is binding. All inputs stay local in your browser.\n","permalink":"https://heidelsec.de/en/tools/","summary":"\u003cp\u003e\u003cstrong\u003eFree security tools for daily use. The checks run in your browser – the domain checks transmit only the domain name.\u003c/strong\u003e\u003c/p\u003e\n\u003cdiv class=\"td-tool-nav\"\u003e\n  \u003ca class=\"td-btn\" href=\"#password-checker\"\u003e🔑 Password Strength Checker\u003c/a\u003e\n  \u003ca class=\"td-btn\" href=\"#password-generator\"\u003e🔐 Password Generator\u003c/a\u003e\n  \u003ca class=\"td-btn\" href=\"#domain-security-check\"\u003e🌐 Domain, DNS \u0026 Mail Check\u003c/a\u003e\n  \u003ca class=\"td-btn\" href=\"#backup-check\"\u003e🧯 Backup Self-Assessment\u003c/a\u003e\n  \u003ca class=\"td-btn\" href=\"#mfa-self-assessment\"\u003e🔒 MFA Self-Assessment\u003c/a\u003e\n  \u003ca class=\"td-btn\" href=\"#nis2-self-assessment\"\u003e🛡️ NIS2 Self-Assessment\u003c/a\u003e\n\u003c/div\u003e\n\u003chr\u003e\n\u003ch2 id=\"password-checker\"\u003e🔑 Password Strength Checker\u003c/h2\u003e\n\u003cp\u003eCheck the strength of an existing password.\u003c/p\u003e\n\u003cdiv class=\"tool-container\"\u003e\n  \u003cdiv class=\"password-input-group\"\u003e\n    \u003cinput type=\"password\" id=\"password-check-input\" placeholder=\"Geben Sie ein Passwort ein…\"\u003e\n    \u003cbutton id=\"toggle-visibility\" class=\"tool-button secondary\"\u003e👁️ Anzeigen\u003c/button\u003e\n  \u003c/div\u003e\n  \u003cdiv class=\"password-strength\"\u003e\n    \u003cdiv class=\"strength-label\"\u003ePasswort-Stärke:\u003c/div\u003e\n    \u003cdiv class=\"strength-bar-container\"\u003e\u003cdiv id=\"check-strength-bar\" class=\"strength-bar\"\u003e\u003c/div\u003e\u003c/div\u003e\n    \u003cdiv id=\"check-strength-text\" class=\"strength-text\"\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cdiv id=\"password-analysis\" class=\"password-analysis\" style=\"display: none;\"\u003e\n    \u003ch3\u003eAnalyse:\u003c/h3\u003e\n    \u003cul id=\"analysis-list\"\u003e\u003c/ul\u003e\n    \u003cdiv class=\"analysis-details\"\u003e\n      \u003cp\u003e\u003cstrong\u003eEntropie:\u003c/strong\u003e \u003cspan id=\"entropy-value\"\u003e\u003c/span\u003e Bit\u003c/p\u003e\n      \u003cp\u003e\u003cstrong\u003eGeschätzte Crack-Zeit:\u003c/strong\u003e \u003cspan id=\"crack-time\"\u003e\u003c/span\u003e\u003c/p\u003e\n    \u003c/div\u003e\n    \u003cdiv id=\"suggestions\" class=\"suggestions\" style=\"display: none;\"\u003e\n      \u003ch4\u003eVerbesserungsvorschläge:\u003c/h4\u003e\n      \u003cul id=\"suggestions-list\"\u003e\u003c/ul\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n  \u003cdiv class=\"tool-info\"\u003e\n    \u003cp\u003e\u003cstrong\u003eℹ️ Hinweis:\u003c/strong\u003e Die Passwort-Analyse erfolgt ausschließlich in Ihrem Browser. Das Passwort wird nicht gespeichert oder übertragen. Crack-Zeiten sind Schätzungen für einen Offline-Angriff mit 100 Mrd. Versuchen/Sekunde (z. B. gegen unsalted MD5) — gegen bcrypt oder Argon2 verlängern sich die Werte deutlich.\u003c/p\u003e\n  \u003c/div\u003e\n\u003c/div\u003e","title":"Security Tools"},{"content":"","permalink":"https://heidelsec.de/en/tags/","summary":"","title":"Tags"}]