<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Tarush Arora</title>
    <description>The latest articles on DEV Community by Tarush Arora (@whotarusharora).</description>
    <link>https://dev.to/whotarusharora</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F533336%2F6cfc578e-c588-4436-ad99-9d4009661e0d.png</url>
      <title>DEV Community: Tarush Arora</title>
      <link>https://dev.to/whotarusharora</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/whotarusharora"/>
    <language>en</language>
    <item>
      <title>Digital Forensic Services: What They Are, What They Recover, and Why Most Organizations Call Too Late</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Wed, 23 Sep 2026 06:10:58 +0000</pubDate>
      <link>https://dev.to/whotarusharora/digital-forensic-services-what-they-are-what-they-recover-and-why-most-organizations-call-too-2mn4</link>
      <guid>https://dev.to/whotarusharora/digital-forensic-services-what-they-are-what-they-recover-and-why-most-organizations-call-too-2mn4</guid>
      <description>&lt;p&gt;Here is a scenario that plays out more often than any forensics professional wants to admit.&lt;/p&gt;

&lt;p&gt;A company discovers unusual activity in their network logs on a Tuesday. The IT team investigates — they reboot the affected servers, run a commercial antivirus scan, patch the vulnerability they think was exploited, and send a "we handled it" email to leadership. On Thursday, the company's cyber insurance carrier requests a forensic investigation report to process the claim. A digital forensics firm is called in on Friday.&lt;/p&gt;

&lt;p&gt;By Friday, the volatile memory — RAM — that would have contained live malware code, attacker credentials, and encryption keys has been wiped clean by the reboot. The log files that would have shown lateral movement have been overwritten by normal system operations. The timeline of the attack, the scope of data accessed, the identity of the threat actor — all of it is either degraded or gone.&lt;/p&gt;

&lt;p&gt;Not stolen by the attacker. Deleted by the response.&lt;/p&gt;

&lt;p&gt;This is the problem digital forensic services exist to solve — and the reason why calling them after you've already responded is often too late.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The average cost of a data breach reached &lt;a href="https://www.ibm.com/reports/data-breach" rel="noopener noreferrer"&gt;$4.88 million &lt;/a&gt;in 2024. Organizations that identified breaches through their own security teams took an average of 241 days to identify and 89 days to contain — 330 days total exposure window. &lt;/p&gt;

&lt;p&gt;The &lt;a href="https://acecomputers.com/chain-of-custody-in-digital-forensics/" rel="noopener noreferrer"&gt;chain of custody in digital forensics &lt;/a&gt;is a detailed, chronological record that documents the entire lifecycle of digital evidence, from its collection to its presentation in court. Any breach or lapse in documentation can lead to evidence being challenged or excluded during legal proceedings.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What Digital Forensic Services Actually Cover
&lt;/h2&gt;

&lt;p&gt;The word "forensics" leads most people to think about criminal investigations and courtrooms. That is accurate — but it captures only part of the actual scope. Digital forensic services are engaged across a much wider range of situations than most organizations realize until they need one.&lt;/p&gt;

&lt;p&gt;The full service scope:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Incident investigation and breach forensics&lt;/strong&gt; Determining what happened, when it started, how the attacker got in, what systems were accessed, and what data was exfiltrated. This is the most common engagement type — and the one where timing matters most, because evidence degrades from the moment normal operations resume on affected systems.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Malware analysis and reverse engineering&lt;/strong&gt; Examining malicious code to understand its behavior, origin, persistence mechanisms, and the attacker's objectives. This work informs both containment and attribution — and can determine whether the organization has fully removed the threat or only surface-patched it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Email and communications forensics&lt;/strong&gt; Recovering deleted emails, establishing communication timelines, identifying spoofed addresses, and tracing the origin of phishing campaigns. Relevant in both cybersecurity incidents and internal investigations involving HR, compliance, or legal disputes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Mobile device forensics&lt;/strong&gt; Extracting evidence from smartphones and tablets — including deleted messages, application data, location history, and encrypted content — for use in litigation, employee investigations, or criminal proceedings.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cloud forensics&lt;/strong&gt; Investigating incidents in cloud environments — AWS, Azure, Google Cloud — where traditional physical evidence collection does not apply. Cloud services impose different preservation windows, export capabilities, authentication needs, and chain-of-custody requirements than on-premise evidence sources. Log retention limits in cloud platforms mean the investigation window can be measured in days, not weeks.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;eDiscovery support&lt;/strong&gt; Identifying, preserving, and producing electronically stored information (ESI) in response to litigation holds, regulatory subpoenas, or court orders. The intersection of forensics and legal proceedings where defensible preservation methodology is essential.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Insider threat and employee investigations&lt;/strong&gt; Establishing whether an employee accessed, copied, or exfiltrated confidential data — including intellectual property theft, unauthorized system access, or policy violations. These investigations require the same chain-of-custody discipline as external breach investigations.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Evidence Preservation Window — Why It Closes Faster Than You Think
&lt;/h2&gt;

&lt;p&gt;Chain of custody for digital evidence should start with preservation, not interpretation. The examiner's first job is to protect sources before normal use changes them.&lt;/p&gt;

&lt;p&gt;This principle sounds obvious. It is routinely violated by well-intentioned IT teams who begin investigating before preserving — rebooting systems, clearing logs, running scans that write to affected drives, or deleting files they believe are malicious before they have been imaged.&lt;/p&gt;

&lt;p&gt;The categories of evidence most commonly destroyed by improper first response:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Volatile memory (RAM)&lt;/strong&gt; RAM contains running processes, network connections, decryption keys, and attacker credentials that exist only while the system is powered on. A reboot wipes it completely. In ransomware incidents specifically, the decryption key — the thing that would allow recovery without paying the ransom — may exist only in RAM at the moment of&lt;br&gt;
discovery. A forensics team called in after the reboot cannot recover it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Log files&lt;/strong&gt; Most systems overwrite logs on a rolling basis. The system event logs, network flow data, and application logs that would establish the attacker's timeline have a natural expiration — accelerated by any remediation activity that increases write operations on the affected system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Deleted file artifacts&lt;/strong&gt; When files are deleted, they are not immediately gone — they are marked as available space. File system artifacts, metadata, and partial file contents remain until overwritten by new data. Every hour of normal system operation brings those artifacts closer to permanent loss.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Network traffic data&lt;/strong&gt; Unless network taps or PCAP captures were running at the time of the incident, real-time network traffic is gone the moment the connection closes. Post-incident reconstruction of network activity depends on flow logs and proxy records — which have their own retention windows.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Before an examiner touches a device or exports an account, counsel and the forensic team should identify likely evidence sources and agree on a collection plan. Each source type imposes different preservation windows, export capabilities, authentication needs, and chain-of-custody requirements.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What Courts and Insurers Actually Need
&lt;/h2&gt;

&lt;p&gt;There is an important distinction between a forensic investigation that produces findings and one that produces findings that hold up.&lt;/p&gt;

&lt;p&gt;The difference is chain of custody — the documented, unbroken record of how evidence was collected, who handled it, how it was stored, and what processes were applied to it at each stage. Chain of custody in cyber forensics is the chronological, written record of evidence handling, from seizure to courtroom presentation. It proves digital evidence remains authentic, unaltered, and reliable. A broken chain can make evidence inadmissible, jeopardizing investigations.&lt;/p&gt;

&lt;p&gt;In practical terms, chain of custody for digital evidence means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Forensic imaging before analysis&lt;/strong&gt; — creating a bit-for-bit copy of storage media using write-blocking hardware, verified with cryptographic hash values (MD5, SHA-256) to prove the copy matches the original&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Documentation of every action&lt;/strong&gt; — timestamped records of who accessed the evidence, what tools were used, what processes were run, and what findings were produced&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Secure, access-controlled storage&lt;/strong&gt; — original evidence and forensic images stored in environments where unauthorized access is logged and access events are documented&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Qualified examiner testimony&lt;/strong&gt; — findings produced by certified forensic examiners (GCFE, GCFA, EnCE, CCE) carry significantly more weight in legal proceedings than investigations run by general IT staff&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For cyber insurance claims specifically, most policies require a forensic investigation conducted by a qualified firm to substantiate the breach scope, confirm the cause, and establish the timeline of unauthorized access. An investigation that cannot document its methodology produces findings the insurer may decline to accept — leaving the organization without coverage for a covered event.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Digital forensic services are not an incident response afterthought. They are the function that determines whether the response to an incident produces evidence or destroys it — whether an insurance claim is paid or disputed — whether a legal proceeding has admissible findings or a degraded record that opposing counsel will dismantle.&lt;/p&gt;

&lt;p&gt;The organizations that engage forensic services early — ideally before remediation begins on affected systems — recover more evidence, establish cleaner timelines, and produce defensible findings. The ones that call after the IT team has already "handled it" are frequently working with what survived the response rather than what the incident actually left behind.&lt;/p&gt;

&lt;p&gt;The evidence window is real. It closes faster than most incident timelines allow. And the investigation that starts the moment the breach does is the one that has the most to work with when the findings matter most.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>forensic</category>
    </item>
    <item>
      <title>Confirmed vs. Potential Vulnerabilities: How to Act on Each Without Creating Alert Fatigue</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Tue, 22 Sep 2026 11:12:14 +0000</pubDate>
      <link>https://dev.to/whotarusharora/confirmed-vs-potential-vulnerabilitieshow-to-act-on-each-without-creating-alertfatigue-3g9p</link>
      <guid>https://dev.to/whotarusharora/confirmed-vs-potential-vulnerabilitieshow-to-act-on-each-without-creating-alertfatigue-3g9p</guid>
      <description>&lt;p&gt;Confirmed vulnerabilities are security flaws a scanner has actively verified as present — through direct proof, not inference. Potential vulnerabilities are conditions that suggest a weakness may exist but require manual investigation or authenticated scanning to confirm. The distinction determines your response workflow: confirmed findings trigger immediate remediation; potential findings trigger investigation first.&lt;/p&gt;

&lt;p&gt;The difference sounds straightforward. The operational reality is not. When every alert requires manual verification, response times slow down, the process becomes a formality, and critical vulnerabilities get lost in the noise. Most vulnerability management failures trace back not to missing confirmed findings — but to teams treating potential vulnerabilities incorrectly: either ignoring them and missing real risks, or chasing every one and burning out before the confirmed ones get fixed.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The National Vulnerability Database recorded over 30,000 new CVEs in 2025 — more than 80 per day. The median time-to-exploit has dropped to five days, and &lt;a href="https://www.vectra.ai/topics/vulnerability-scanning" rel="noopener noreferrer"&gt;28.96% of entries &lt;/a&gt;in CISA's Known Exploited Vulnerabilities catalog were exploited on or before the day the CVE was published. &lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;At that exploitation pace, "we'll investigate the potential ones later" is no longer a viable triage philosophy. &lt;/p&gt;

&lt;h2&gt;
  
  
  Why the Distinction Exists in the First Place
&lt;/h2&gt;

&lt;p&gt;To understand the difference between confirmed and potential vulnerabilities, you need to understand why scanners surface potential findings at all — rather than simply confirming or excluding everything.&lt;/p&gt;

&lt;p&gt;The answer is backported patches.&lt;/p&gt;

&lt;p&gt;Linux distributions — Red Hat Enterprise Linux, Ubuntu LTS, Debian, and others — routinely backport security fixes to older software versions without changing he version number. A system running OpenSSL 3.0.2 on RHEL 9 may have the vulnerability from CVE-2023-XXXX fully patched, but because the version string still reads "3.0.2" rather than the upstream-fixed "3.0.7," an unauthenticated scanner performing banner grabbing will flag it as potentially vulnerable.&lt;/p&gt;

&lt;p&gt;False positives typically occur when a scanner detects a software version number without accounting for vendor-backported patches, custom builds, or compensating controls. This is not a scanner failure — it is a deliberate design choice. The scanner is being honest: it sees a version associated with a known vulnerability, it cannot verify whether the patch was applied, so it marks the finding as potential rather than confirmed.&lt;/p&gt;

&lt;p&gt;This technical context matters because it defines the investigation path. A potential vulnerability finding is not necessarily a false positive. It is an unresolved question — and your workflow determines whether that question gets answered accurately or gets dismissed by default.&lt;/p&gt;

&lt;h2&gt;
  
  
  Confirmed Vulnerabilities: What They Are and How to Handle Them
&lt;/h2&gt;

&lt;p&gt;A confirmed vulnerability is one the scanner has verified through direct evidence — not version inference. The scanner ran a safe check, read actual file contents, observed system behavior, or obtained authenticated patch status. It has proof the flaw is present.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What confirmation looks like in practice:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The scanner read a configuration file and confirmed a weak cipher suite is enabled&lt;/li&gt;
&lt;li&gt;Authenticated credentials allowed the scanner to verify that a specific patch is absent from the package manifest&lt;/li&gt;
&lt;li&gt;A safe, non-destructive probe triggered a response that only a vulnerable system would produce&lt;/li&gt;
&lt;li&gt;The scanner read the actual software binary and confirmed the unpatched code path exists&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In tools like Qualys, Tenable Nessus, and Rapid7 InsightVM, confirmed findings appear at high confidence levels — often color-coded red — and carry explicit scanner notes indicating how the confirmation was obtained.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The response workflow for confirmed vulnerabilities is clear:&lt;/strong&gt; Validate that the affected asset is correctly identified, assess the criticality of the asset and the severity of the CVE, and remediate according to your SLA. Only 54% of vulnerable devices were fully remediated within the year, with a median of 32 days to patch — confirmed findings sitting unaddressed past your SLA are where real breach risk lives.&lt;/p&gt;

&lt;h2&gt;
  
  
  Potential Vulnerabilities: What They Are and How to Handle Them
&lt;/h2&gt;

&lt;p&gt;A potential vulnerability is a scanner's informed guess. The finding exists because the scanner observed a condition — typically a version number — associated with a known vulnerability, but could not verify whether the vulnerability is actually exploitable on this specific system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What potential findings look like in practice:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Banner grabbing identified a software version within the affected range of a CVE&lt;/li&gt;
&lt;li&gt;The scan was unauthenticated, so the scanner could not check patch status&lt;/li&gt;
&lt;li&gt;A version string hasn't been updated despite a backported patch being applied&lt;/li&gt;
&lt;li&gt;The vulnerable component exists in the codebase but may not be reachable from a network path
In reporting tools, these appear at lower confidence — often yellow-coded — with explicit language indicating the finding is inferred rather than proven.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The response workflow for potential vulnerabilities requires a decision step before remediation:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Determine your scan type&lt;/strong&gt; — was this an authenticated or unauthenticated scan? Unauthenticated scans produce far more potential findings because they lack access to verify patch status. If you are running unauthenticated scans on critical assets, the first step is upgrading to authenticated scanning on those assets.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Check for backported patches&lt;/strong&gt; — query the system's package manager directly: on RHEL or on Debian/Ubuntu will show the actual installed version including patch revision, which the scanner may not have been able to read.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Assess asset criticality before investing investigation time&lt;/strong&gt; — a test server with a high CVSS score may look worse than a production server on paper, even if the test server is isolated and contains no sensitive data. A lower-scored system tied to customer authentication may deserve immediate attention. Apply investigation effort proportionally to asset risk, not scanner severity alone.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Document your conclusion&lt;/strong&gt; — whether you confirm or rule out the vulnerability, document the investigation in your tracking system. Undocumented decisions create the same finding again in the next scan cycle.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The Alert Fatigue Problem: Why Your Triage Model Determines Your Security Posture
&lt;/h2&gt;

&lt;p&gt;Tools with high false-positive rates inevitably lead to alert fatigue. When every alert requires manual verification, the process becomes a mere formality, and critical vulnerabilities get lost in the noise.&lt;/p&gt;

&lt;p&gt;The triage model that fails most consistently is binary: treat everything as equally urgent, or treat potential findings as noise until someone has time. Neither works.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The model that works:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzqwg7nuxi3pdwpsyv6d3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzqwg7nuxi3pdwpsyv6d3.png" alt="Model that Works" width="800" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;The confirmed vs. potential distinction is not a scanner technicality to understand and file away. It is the foundation of a functional vulnerability triage model. Scanner output should trigger investigation, not automatic panic. Confirmed findings tell you where the risk is&lt;br&gt;
proven. Potential findings tell you where it might be — and where your scanning coverage has gaps.&lt;/p&gt;

&lt;p&gt;Both matter. The teams that handle them well treat each type with the workflow it requires: immediate, prioritized remediation for confirmed findings; structured, documented investigation for potential ones; and consistent escalation logic when asset criticality or KEV status changes the urgency calculation.&lt;/p&gt;

&lt;p&gt;The teams that do not handle them well have the same experience every scan cycle — more alerts than time, the same findings reappearing, and a growing suspicion that the scanning program is producing noise rather than insight.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>testing</category>
      <category>vulnerabilities</category>
    </item>
    <item>
      <title>Why Hire a Virtual CISO: Strategic Security Leadership Without the Executive Price Tag</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Sun, 20 Sep 2026 09:38:44 +0000</pubDate>
      <link>https://dev.to/whotarusharora/why-hire-a-virtual-ciso-strategic-security-leadershipwithout-the-executive-price-tag-5d5d</link>
      <guid>https://dev.to/whotarusharora/why-hire-a-virtual-ciso-strategic-security-leadershipwithout-the-executive-price-tag-5d5d</guid>
      <description>&lt;p&gt;Hiring a Virtual CISO (vCISO) gives your organization senior security leadership — strategy, compliance, incident response, and board-level communication — on a part-time or contract basis, at a fraction of what a full-time Chief Information Security Officer costs. It is the right model for companies that have outgrown DIY security but are not yet at the scale where a $350,000+ executive hire is justified.&lt;/p&gt;

&lt;p&gt;That last sentence is the one most vCISO explainers skip. Not every company needs to hire one. But there is a specific stage in company growth — typically 50 to 500 employees, often triggered by an enterprise sales requirement, a compliance audit, a funding round, or a near-miss security incident — where the gap between "we handle security ourselves" and "we have a dedicated security executive" becomes a genuine business liability. A vCISO closes that gap.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Specific Moment a Virtual CISO Makes Sense
&lt;/h2&gt;

&lt;p&gt;Most security advice is written for companies already committed to a path — either "we're building out a security team" or "we're outsourcing everything." The vCISO conversation happens earlier, at a more ambiguous moment, and it is worth being precise about what that moment looks like.&lt;/p&gt;

&lt;p&gt;You probably need a vCISO when at least one of the following is true:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A prospective enterprise customer has asked for your SOC 2 report, your security policy documentation, or a completed security questionnaire — and you don't have these&lt;/li&gt;
&lt;li&gt;An investor, board member, or auditor has asked who is accountable for cybersecurity at the leadership level — and the honest answer is "our IT manager, sort of"&lt;/li&gt;
&lt;li&gt;You have experienced a security incident — a phishing compromise, a data exposure, a ransomware attempt — and the response was reactive and uncoordinated&lt;/li&gt;
&lt;li&gt;You are in a regulated industry (fintech, healthtech, legal) where compliance requirements have grown faster than your internal security capacity&lt;/li&gt;
&lt;li&gt;Your full-time security headcount is growing but there is no one setting the overall strategy, defining risk tolerance, or making architecture decisions&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of these scenarios requires a $400,000 executive. All of them require someone with CISO-level experience and authority. That is the gap a vCISO fills.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a Virtual CISO Actually Does
&lt;/h2&gt;

&lt;p&gt;A vCISO provides security leadership — not security execution. The distinction matters because it determines what you still need internally and what the engagement actually delivers.&lt;/p&gt;

&lt;p&gt;In practical terms, a vCISO engagement typically includes:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security strategy and roadmap&lt;/strong&gt; Assessing your current security posture, identifying the highest-risk gaps, and building a prioritized roadmap that aligns security investments with business risk — not just technical best practice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance program ownership&lt;/strong&gt; Managing the path to SOC 2, ISO 27001, HIPAA, PCI DSS, or other applicable frameworks. This includes scoping, evidence collection, vendor selection, and audit readiness — the work that consumes significant time from engineering and operations teams when it isn't owned by someone with compliance experience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Board and executive communication&lt;/strong&gt; Translating security risk into business language. Boards and investors do not want to hear about CVE scores and patch cycles. They want to understand exposure, liability, and what the company is doing about it. A vCISO who has done this in multiple organizations produces clearer, more credible security communication than an internal IT manager asked to present to the board for the first time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Incident response planning and oversight&lt;/strong&gt; Building and testing the incident response plan before an incident happens. When something does go wrong, the vCISO leads the response — coordinating internal teams, managing&lt;br&gt;
external communication, and ensuring the breach notification obligations are met correctly and on time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Vendor and tool assessment&lt;/strong&gt; Evaluating the security tools and vendors the company is using or considering — without the vendor bias that comes from a team that selected those tools themselves.&lt;/p&gt;

&lt;h2&gt;
  
  
  vCISO vs. Full-Time CISO: The Cost Math
&lt;/h2&gt;

&lt;p&gt;The cost comparison depends on scope and hours, but the directional math is consistent:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo72lgad5qqtvxbn05vuv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo72lgad5qqtvxbn05vuv.png" alt="Virtual CISO vs Full-Time CISO" width="800" height="336"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The vCISO model does not scale indefinitely. When your security team grows beyond 5–10 people, when regulatory complexity demands full-time executive oversight, or when your board requires a named CISO in the organizational&lt;br&gt;
structure, a full-time hire becomes necessary. The vCISO is not a permanent substitute — it is the right model for the stage where the full-time hire isn't yet justified but the function cannot remain unled.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;The Virtual CISO exists because the security leadership gap is real and the full-time executive solution is often disproportionate to the stage. Cost savings and flexibility are the benefits most often cited — and they are real. But the more honest argument for a vCISO is this: security strategy without a strategist is not strategy. It is a collection of tools, policies, and responses that nobody is accountable for connecting into a coherent posture.&lt;br&gt;
A vCISO provides that accountability. For companies at the right stage, it is the most efficient way to get it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions (FAQs)
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Q1: What does a Virtual CISO do?
&lt;/h3&gt;

&lt;p&gt;A Virtual CISO provides part-time or contract-based security leadership — including security strategy and roadmap development, compliance program management (SOC 2, ISO 27001, HIPAA, PCI DSS), incident response planning,&lt;br&gt;
board-level security communication, and vendor and tool assessment. A vCISO leads and directs security activity; execution is typically handled by internal IT staff or managed security service providers. The engagement is scoped by hours or deliverables rather than a full-time employment relationship.&lt;/p&gt;

&lt;h3&gt;
  
  
  Q2: When should a company move from a Virtual CISO to a full-time CISO hire?
&lt;/h3&gt;

&lt;p&gt;The transition typically becomes necessary when your internal security team grows to 5–10 people and requires full time executive oversight, when your regulatory environment demands a named CISO in the organizational structure (common in financial services and healthcare at certain revenue thresholds), when board or investor requirements specify a full-time security executive, or when the volume and complexity of security decisions exceeds what part-time engagement can address. A vCISO can help define and time this transition — often assisting in the hiring process for their own full-time replacement.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>productivity</category>
    </item>
    <item>
      <title>Benefits of Penetration Testing as a Service(PTaaS)</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Fri, 18 Sep 2026 07:34:30 +0000</pubDate>
      <link>https://dev.to/whotarusharora/benefits-of-penetration-testing-as-a-serviceptaas-37ca</link>
      <guid>https://dev.to/whotarusharora/benefits-of-penetration-testing-as-a-serviceptaas-37ca</guid>
      <description>&lt;p&gt;Penetration Testing as a Service (PTaaS) delivers continuous, on-demand security testing through a subscription model, replacing the annual point-in-time pen test with ongoing vulnerability discovery, real-time reporting, and faster remediation cycles. &lt;br&gt;
The core benefits are cost predictability, continuous coverage, access to broader security expertise, and compliance support without the scheduling friction of traditional engagements.&lt;/p&gt;

&lt;p&gt;Annual penetration tests were designed for a threat environment that no longer exists. Applications ship weekly. Infrastructure changes monthly. A test completed in January says nothing about the attack surface in September. PTaaS was built to close that gap.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is Penetration Testing as a Service?
&lt;/h2&gt;

&lt;p&gt;PTaaS is a subscription-based model where organizations access penetration testing continuously  and not as a one-time annual engagement — through a platform that combines automated scanning, human-led testing, real-time vulnerability reporting, and direct access to security researchers.&lt;/p&gt;

&lt;p&gt;Traditional pen testing produces a PDF report 2–4 weeks after the engagement ends. PTaaS produces findings in real time, allows remediation to happen during the test, and enables retesting without scheduling a new engagement. &lt;br&gt;
The delivery model is the differentiator but the the underlying methodology (manual exploitation, social engineering, network&lt;br&gt;
reconnaissance) remains the same.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Are the Key Benefits of PTaaS?
&lt;/h2&gt;

&lt;p&gt;The primary benefits of Penetration Testing as a Service are: continuous security coverage instead of annual snapshots, real-time findings with remediation guidance, cost predictability through subscription pricing, faster remediation cycles enabled by collaborative platforms, and scalable access to specialized security expertise on demand.&lt;/p&gt;

&lt;p&gt;Here is what each benefit means in operational terms:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Continuous coverage, not point-in-time snapshots&lt;/strong&gt; Traditional pen tests give you a picture of your security posture on one day per year. PTaaS runs continuously — catching vulnerabilities introduced by new code deployments, infrastructure changes, or third-party integrations between annual testing cycles. &lt;br&gt;
For organizations releasing software frequently, this is the difference between testing what ships and hoping nothing breaks between tests.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Real-time findings and collaborative remediation&lt;/strong&gt; In a traditional engagement, developers receive a final report weeks after testing ends —when the code context has already changed. PTaaS platforms surface findings as they are discovered, with remediation guidance developers can act on immediately. &lt;br&gt;
Some platforms allow security teams and developers to communicate directly with testers within the platform, reducing the back-and-forth that delays fixes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cost predictability&lt;/strong&gt; Traditional pen testing is priced per engagement — scope, duration, and day rates that vary by tester. PTaaS converts that variable cost into a predictable subscription, making security budgeting more straightforward and eliminating the negotiation cycle each time testing is needed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Scalable access to security expertise&lt;/strong&gt; A single vendor engagement gives you the expertise of the team assigned to your project. A PTaaS platform gives you access to a broader pool of security researchers — often with specializations across web applications, APIs, mobile, cloud infrastructure, and social engineering — matched to the specific assets being tested.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Compliance support built into the workflow&lt;/strong&gt; PCI DSS, SOC 2, HIPAA, and ISO 27001 all require regular penetration testing. PTaaS platforms typically produce audit-ready reports mapped to compliance frameworks, reducing the documentation overhead that comes with converting a pen test report into evidence for an auditor.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkqozhiidr1resq29ljlb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkqozhiidr1resq29ljlb.png" alt="PTaaS vs Traditional Penetration Testing" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;The annual pen test was never a security strategy — it was a compliance exercise. PTaaS is what continuous security testing looks like when the delivery model catches up to the threat environment. &lt;/p&gt;

&lt;p&gt;Continuous coverage, real-time findings, subscription pricing, and compliance ready reporting make PTaaS the more operationally honest answer to the question every security team faces: how do we know our defenses hold against what attackers are doing today, not what they were doing last January?&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>testing</category>
    </item>
    <item>
      <title>The Real Risk of Ignoring API Security (And What the Data Actually Shows)</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Thu, 17 Sep 2026 07:11:10 +0000</pubDate>
      <link>https://dev.to/whotarusharora/the-real-risk-of-ignoring-api-security-and-what-the-data-actually-shows-2oj0</link>
      <guid>https://dev.to/whotarusharora/the-real-risk-of-ignoring-api-security-and-what-the-data-actually-shows-2oj0</guid>
      <description>&lt;p&gt;Every minor security gap is an opportunity for an attacker. And when you ignore API security, it leaves a critical gap in an organization’s defenses, because APIs are the primary attack surface for modern applications. &lt;/p&gt;

&lt;p&gt;They act as a direct pipeline to backend systems and data. So, neglecting them leads to the same operational, financial, and legal fallout as any major security failure – just faster, and with less warning. &lt;/p&gt;

&lt;p&gt;The scale of API attacks is so high, that &lt;a href="https://salt.security/press-releases/salt-labs-state-of-api-security-report-reveals-99-of-respondents-experienced-api-security-issues-in-past-12-months" rel="noopener noreferrer"&gt;99% of organization reported an API-related security incident &lt;/a&gt;in the past 12 months. &lt;/p&gt;

&lt;p&gt;Also, the risks fall into three categories – data breaches and exposure, system vulnerabilities and abuse, and business/compliance fallout. And here, each one is mapped to the OWASP API Security Top 10. &lt;/p&gt;

&lt;h2&gt;
  
  
  1: Data Breached and Exposure
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Excessive Data Exposure (OWASP API3)
&lt;/h3&gt;

&lt;p&gt;Many APIs return the full backend object and rely on the frontend to filter what a user actually sees. Call the API directly and you can often pull the raw, unfiltered data, such as PII, financial details, credentials. And these was never meant to reach the client. OWASP folded this into API3 in its 2023 update, alongside mass assignment. &lt;/p&gt;

&lt;h3&gt;
  
  
  Broken Object-Level Authorization (BOLA) (OWASP API1 — #1 on the list)
&lt;/h3&gt;

&lt;p&gt;An attacker changes an ID in a request, such as an order ID, an account number, a user ID and pulls back someone else's private data, because the API never checked whether this caller was allowed to access that specific object. It requires no advanced tooling, which is exactly why it remains the most exploited API flaw year after year. &lt;/p&gt;

&lt;h2&gt;
  
  
  2: System Vulnerabilities and Abuse
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Broken Authentication / Account Takeover (OWASP API2)
&lt;/h3&gt;

&lt;p&gt;Weak or misconfigured tokens, such as reused API keys, long-lived JWTs, loosely configured OAuth flows let attackers hijack real sessions or forge new ones. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;52% of 60 major API breaches analyzed in 2025 traced back to broken authentication &lt;/li&gt;
&lt;li&gt;59% of known API vulnerabilities require no authentication at all to exploit &lt;/li&gt;
&lt;li&gt;Only 21% of security teams say they can reliably detect an attack at the API layer (&lt;a href="https://hubspot.wallarm.com/hubfs/Wallarm%20API%20ThreatStatTM%20Report-2026.pdf" rel="noopener noreferrer"&gt;Wallarm, 2025–2026&lt;/a&gt;) &lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Resource Exhaustion / DDoS (OWASP API4: Unrestricted Resource Consumption)
&lt;/h3&gt;

&lt;p&gt;Without rate limiting, scripted requests can overwhelm servers, causing downtime or a runaway cloud bill. This risk climbed from the 7th-ranked API threat in 2024 to 4th in 2025, driven by automated scraping and enumeration attacks that are now far easier to run at scale.&lt;/p&gt;

&lt;h3&gt;
  
  
  Injection Attacks (now folded into OWASP API10: Unsafe Consumption of APIs)
&lt;/h3&gt;

&lt;p&gt;Unvalidated input lets attackers inject SQL or script payloads to manipulate the backend directly, or run unauthorized commands. OWASP moved this under API10 because injected input increasingly travels through a chain of trusted API calls rather than a single form field. &lt;/p&gt;

&lt;h3&gt;
  
  
  Shadow / Zombie APIs (OWASP API9: Improper Inventory Management)
&lt;/h3&gt;

&lt;p&gt;It’s the risk most other blogs underweight Old, undocumented, or "temporary" endpoints stay live in production after a newer version ships, skipping every security review the documented APIs went through. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Typically, 30–40% of an organization's total API footprint &lt;/li&gt;
&lt;li&gt;
&lt;a href="https://appsecsanta.com/research/api-security-statistics" rel="noopener noreferrer"&gt;Only 15% of organizations &lt;/a&gt;report strong confidence in their own API inventory&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  3: Business and Compliance Fallout
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Regulatory Fines
&lt;/h3&gt;

&lt;p&gt;A breach traced to a neglected API can violate GDPR, HIPAA, PCI DSS, or sector-specific rules and regulators treat an exposed API the same as any other data-handling failure. &lt;/p&gt;

&lt;p&gt;The cost backs this up: the global average data breach now runs 4.99 million in the U.S., which is an all-time high, driven partly by regulatory penalties and slower detection (&lt;a href="https://www.ibm.com/reports/data-breach" rel="noopener noreferrer"&gt;IBM&lt;/a&gt;).&lt;/p&gt;

&lt;h3&gt;
  
  
  Supply Chain / Third-Party API Risk
&lt;/h3&gt;

&lt;p&gt;Payment gateways, analytics SDKs, map providers, AI model endpoints. A compromise anywhere in that chain becomes your incident if the integration wasn't security-reviewed. &lt;/p&gt;

&lt;p&gt;This is a bigger driver than most teams assume: 27% of 2025 API breaches were caused by unsafe consumption of third-party APIs, the second largest root cause after broken authentication.&lt;/p&gt;

&lt;h3&gt;
  
  
  Reputational Loss
&lt;/h3&gt;

&lt;p&gt;Trust, once broken by a data leak, is slow and expensive to rebuild but often costing years and a real share of the customer base, regardless of how fast the technical fix lands. It's harder to pin to a single stat, but it consistently shows up in breach cost research as a compounding, long-tail cost that outlasts the incident itself&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;Every risk above traces back to one root cause: a lack of continuous visibility into what APIs exist, who's calling them, and whether each call is actually authorized. Closing the gap takes three things: &lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Continuous API discovery, including the undocumented, shadow ones.&lt;/li&gt;
&lt;li&gt;Authentication-first hardening, since broken auth alone accounts for over half of major breaches.&lt;/li&gt;
&lt;li&gt;Behaviour-based monitoring to catch misuse, not just malformed traffic. &lt;/li&gt;
&lt;/ol&gt;

</description>
      <category>security</category>
      <category>api</category>
      <category>testing</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>What is .NET Development</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Thu, 23 Jan 2025 08:03:21 +0000</pubDate>
      <link>https://dev.to/whotarusharora/what-is-net-development-2ebb</link>
      <guid>https://dev.to/whotarusharora/what-is-net-development-2ebb</guid>
      <description>&lt;p&gt;.NET is the most popular development technology, created, distributed, owned and maintained by Microsoft. It’s one of the highest utilized cross-platform compatible and open-source platforms, that aids in leveraging the C#, F# and VB (Visual Basic) capabilities.&lt;/p&gt;

&lt;p&gt;In addition, .NET is more than a platform. It’s an ecosystem under which numerous other technologies reside, such as ASP.NET, .NET Core, .NET Entity Framework, .NET MAUI, and more. &lt;/p&gt;

&lt;p&gt;Mainly, the .NET platform is designed to focus on four primary factors, namely Performance, Security, Productivity, and Reliability. To gain all these advantages and improve business operations, most small, medium, and large-scale organizations choose .NET for their software projects. Also, it has some extraordinary design points, as listed below, that must be known by a developer, a .NET learner, and an organization looking to avail of a .NET development service. &lt;/p&gt;

&lt;h2&gt;
  
  
  .NET Design Points
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;It’s a full-stack development technology comprising frameworks, libraries, programming languages, and tools.&lt;/li&gt;
&lt;li&gt;The code structure used to curate .NET applications aligns with industry standards, ensuring a secure code for the extended run.&lt;/li&gt;
&lt;li&gt;Developers can write a .NET application using both static and dynamic code within minimal time.&lt;/li&gt;
&lt;li&gt;The .NET code is highly portable, ensuring to run it across operating systems and digital platforms, such as Windows, Linux, Unix and macOS.&lt;/li&gt;
&lt;li&gt;The .NET code can be deployed on all significant architectures, such as Cloud, Microservices, Monolithic, Client-Server, Layered, and Peer-to-Peer.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Furthermore, Microsoft develops, distributes, and maintains multiple .NET variants, namely .NET, Mono, and .NET (Core). Some professionals also consider them as the primary .NET implementation rather than categorizing them as variants.&lt;/p&gt;

&lt;h2&gt;
  
  
  .NET Variants and Implementations
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;.NET&lt;/strong&gt;&lt;br&gt;
The .NET is the first variant, which was developed only for building Windows-based applications. Still, it can be used only for Windows desktop and server apps, and it’s highly preferred for this requirement.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Mono&lt;/strong&gt;&lt;br&gt;
Mono is mainly for mobile devices based on iOS and Android operating systems. Microsoft made it a cross-platform compatible technology, so that time, effort, and cost can be reduced.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;.NET Core&lt;/strong&gt;&lt;br&gt;
Now comes the most used variant in today’s digital environment. It’s the most graceful .NET implementation with cross-platform compatibility, robust security features and active support. It can be used to create all kind of applications, whether its web-app, website, desktop software or any other. &lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

</description>
      <category>dotnet</category>
      <category>webdev</category>
      <category>programming</category>
      <category>development</category>
    </item>
    <item>
      <title>What are Private Offers on Azure Marketplace?</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Sat, 31 Aug 2024 13:51:29 +0000</pubDate>
      <link>https://dev.to/whotarusharora/what-are-private-offers-on-azure-marketplace-a91</link>
      <guid>https://dev.to/whotarusharora/what-are-private-offers-on-azure-marketplace-a91</guid>
      <description>&lt;p&gt;In the ever-evolving landscape of cloud computing, finding the right solutions for your business needs can be complex. However, Azure Marketplace offers numerous cloud applications and services to streamline this process.&lt;/p&gt;

&lt;p&gt;Further, among the many features of Azure Marketplace, Private Offers stand out as a particularly useful tool for organizations seeking customized solutions. But what exactly are Private Offers, and how can they benefit your organization? &lt;/p&gt;

&lt;p&gt;To know, let's get started.&lt;/p&gt;

&lt;h2&gt;
  
  
  Azure Marketplace Private Offers: A Quick Overview
&lt;/h2&gt;

&lt;p&gt;When the software providers on Azure marketplace offer you a custom deal, including tailored terms and conditions, and pricing, it's known as a private offer. For every customer, a private offer is different based on their requirements and the deal confirmed with the software author.&lt;/p&gt;

&lt;p&gt;In addition, when you avail of the private offers on the Azure marketplace, all its details are only visible to you. It's completely opposite of the public offers, that are displayed to everyone utilizing the platform.&lt;/p&gt;

&lt;p&gt;Let's look at an example for a detailed perspective.&lt;/p&gt;

&lt;p&gt;Suppose, you see data security software on the Azure marketplace available for 100 US dollars per month. This price is displayed as a public offer and anyone can avail of the software at this cost. But, you thought of moving ahead with a private offer approach. To do so, you proposed your offer of 80 US dollars per month and some custom agreement.&lt;/p&gt;

&lt;p&gt;Furthermore, the software provider accepted your offer and provided you with the software at the price you demanded. You will utilize the software at 80 US dollars per month, which is your private offer and it will only be displayed to you. On the other hand, the 100 US dollar will be displayed to others on the platform.&lt;/p&gt;

&lt;p&gt;Similarly, any other organization can avail the same software even at some more discount. The private offer entirely depends on the discussion and negotiation with the software provider.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why are Private Offers Preferred?
&lt;/h2&gt;

&lt;p&gt;Every standardized IT firm considers the private offer approach, due to the following reasons:&lt;/p&gt;

&lt;h3&gt;
  
  
  #1: Custom Policies, But All Existing Services
&lt;/h3&gt;

&lt;p&gt;In a private offer, you are able to access all the features listed in a public offer, but the terms and conditions are tailored to your requirements. In addition, you can also negotiate some additional benefits from the software provider to stay ahead of competitors.&lt;/p&gt;

&lt;h3&gt;
  
  
  #2: Lowers the Cost
&lt;/h3&gt;

&lt;p&gt;Affordable or discounted price of software is one of the main leverages of a private offer. It helps you save overall investment on an application for a maximum of three years. Moreover, the negotiated price can also be applied to your previous subscriptions and purchases from the same software vendor.&lt;/p&gt;

&lt;h3&gt;
  
  
  #3: Builds Long-Term Relationship
&lt;/h3&gt;

&lt;p&gt;The software vendors are more responsible towards the customers with private offers. They tend to always cater to such clients with the best-in-class services to foster a long-term relationship. Due to this, you always avail of a stable, well-integrated, and optimized solution for your business and technical needs.&lt;/p&gt;

&lt;h3&gt;
  
  
  #4: Dedicated Support
&lt;/h3&gt;

&lt;p&gt;With an Azure marketplace private offer, you are on the priority list of the software vendor. They will provide you with dedicated support to resolve your queries and troubleshoot the system promptly. It will ensure you of maximum availability, and stability of the solution while catering to your stakeholder needs.&lt;/p&gt;

&lt;h3&gt;
  
  
  #5: Streamlined Procurement Operations
&lt;/h3&gt;

&lt;p&gt;The private offers help you put all custom terms and conditions together and get the right package for your business. It means that you can combine two or more public plans in a single private offer transaction. Due to this, you save time and streamline contract management.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wrapping Up
&lt;/h2&gt;

&lt;p&gt;Private offers on the Azure marketplace are a boon for your business. It aids you more in every aspect, as you save costs, easily maintain procurement, build relationships, and even get dedicated support. Additionally, private offers help you affordably expand your cloud infrastructure and build a stable virtual realm for your business operations.&lt;/p&gt;

&lt;p&gt;If you also need such specialized and tailored offers, you need experienced Azure negotiators. We help you avail of the perfect private offer, that any software vendor will accept in the first go. Thus, to save money and leverage the best applications, by proposing the private offers. &lt;/p&gt;

</description>
      <category>webdev</category>
      <category>azure</category>
      <category>microsoft</category>
      <category>learning</category>
    </item>
    <item>
      <title>What are Non-Deterministic Programs: Exploring Python Example</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Sun, 04 Aug 2024 08:01:53 +0000</pubDate>
      <link>https://dev.to/whotarusharora/what-are-non-deterministic-programs-exploring-python-example-5gj5</link>
      <guid>https://dev.to/whotarusharora/what-are-non-deterministic-programs-exploring-python-example-5gj5</guid>
      <description>&lt;p&gt;Level: Beginner  &lt;/p&gt;

&lt;p&gt;Regardless of the programming language, whenever we write a computer program, we expect a particular output for a given input. For instance, if you input two number, 10 and 5 for an addition program, you expect 15 as the total answer. You can run the program as many times you want, and whenever these two values will be inputted, output will remain same. &lt;/p&gt;

&lt;p&gt;When the output is constant for a particular input, the program processing it is known as deterministic. In addition, such program also follows the same set of commands every time to process each input. &lt;br&gt;
But, when random values are provided as output, even after going through same set of commands, the program is called as non-deterministic. These kind of programs mostly offer pseudorandom numbers as output. &lt;/p&gt;

&lt;p&gt;Further, determinism is considered as a good thing, as output is stable. But, in some cases, such for gaming applications, random outputs are required. And for such purposes, you need non-deterministic programs. &lt;/p&gt;
&lt;h2&gt;
  
  
  Python example for Non-Deterministic Programs
&lt;/h2&gt;

&lt;p&gt;To create a non-deterministic program, we’ll be using Python programming language and in-built function called *&lt;em&gt;“random()”. *&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;random()&lt;/strong&gt; function is configured to provide random values between 0.0 and 1.0. Whenever this function is called, a list of values is provided as output. We are going to use a for-loop to output only the ten values. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Code:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;import random

for i in range(10):
    x = random.random()
    print(x)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Run the program multiple times and analyze the output. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Output #1:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpug5tpnxe7g67vzyj11l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpug5tpnxe7g67vzyj11l.png" alt="Output 1" width="720" height="292"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Output #2:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9y4roltws04438sz3vgj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9y4roltws04438sz3vgj.png" alt="Output 2" width="544" height="291"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Output #3:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1xdk1d2drcg7qj8yf1n2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1xdk1d2drcg7qj8yf1n2.png" alt="Output 3" width="572" height="292"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>python</category>
      <category>programming</category>
      <category>beginners</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Why Businesses Choose .NET Cross Platform Development?</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Sun, 28 Jul 2024 16:30:50 +0000</pubDate>
      <link>https://dev.to/whotarusharora/why-businesses-choose-net-cross-platform-development-17op</link>
      <guid>https://dev.to/whotarusharora/why-businesses-choose-net-cross-platform-development-17op</guid>
      <description>&lt;p&gt;In an era where agility and efficiency are paramount, .NET cross-platform development is emerging as a top choice for businesses aiming to streamline their software solutions. By enabling developers to build applications that run seamlessly across Windows, macOS, and Linux from a single codebase, .NET simplifies development while boosting performance and scalability. &lt;/p&gt;

&lt;p&gt;This blog helps you explore how .NET is becoming the go-to framework for modern businesses, highlighting its leverages and some must to know characteristics. &lt;/p&gt;

&lt;h2&gt;
  
  
  What Does Business Gain with Cross Platform Development?
&lt;/h2&gt;

&lt;p&gt;When any organizations opts for a cross-platform app development, it benefits from the following: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;They save on resources required to develop native applications. &lt;/li&gt;
&lt;li&gt;They save on time, as a software compatible with all operating system gets developed in the same time, required for a native app development. &lt;/li&gt;
&lt;li&gt;They save on efforts and cost to hire the different development teams. &lt;/li&gt;
&lt;li&gt;They reduce the efforts to maintain different codebases and upgrade the application in future. &lt;/li&gt;
&lt;li&gt;They find it a quick to focus on core business operations, as cross-compatible app development resolves the issue for all stakeholders at once. &lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How Microsoft .NET Cross Platform Development Supports Organizations?
&lt;/h2&gt;

&lt;p&gt;Following are the top five reasons, why businesses consider .NET for developing cross-platform compatible applications. &lt;/p&gt;

&lt;h3&gt;
  
  
  #1: Saves Money and Time
&lt;/h3&gt;

&lt;p&gt;For any of the organization, cost and time are the two most important factors to consider, while developing a software. By choosing .NET as the development technology, they avail advantages of both. It helps them to save time with code reusability and pre-built templates. &lt;/p&gt;

&lt;p&gt;Further, it leads the developers to efficiently collaborate and complete work within minimal efforts. In addition, .NET cross platform compatible apps minimizes the resources usage, due to which cost is saved at a greater extent. &lt;/p&gt;

&lt;p&gt;Besides it, you can hire .NET developers for as low as $18/hour and an experienced one for $50/hour. And that’s how cross-platform development becomes seamless with dotnet. &lt;/p&gt;

&lt;h3&gt;
  
  
  #2: Seamless Learning Curve and Resource Availability
&lt;/h3&gt;

&lt;p&gt;There’s no end to resources available for .NET technology. Whether its .NET framework, .NET Core, ASP.NET, .NET MAUI, or any other tech under dotnet umbrella, every one of it has hundreds of compatible libraries, APIs, SDKs, databases, and other third-party components.&lt;/p&gt;

&lt;p&gt;In addition, the human resources or the .NET development team can be effortlessly hired at an affordable price. You can go for outsourcing the .NET developer to save money through any of the preffered model: onshore, nearshore and offshore. &lt;/p&gt;

&lt;p&gt;Furthermore, there are hundreds of experienced as well as aspiring dotnet developers. So, your .NET cross platform application is always going to be supported, maintained and upgraded. Besides, in case you think of changing the team, you can do it without a second thought. Any experienced .NET developer can easily learn about the structure and continue working on it. &lt;/p&gt;

&lt;h3&gt;
  
  
  #3: Compatibility at its Peak
&lt;/h3&gt;

&lt;p&gt;As we discussed in the above section, there’s no end to .NET compatible technologies. But, in this section, we are mainly focusing on .NET Core and .NET MUAI. Both these are dotnet-based techs, that are utilized for building cross-platform applications. &lt;/p&gt;

&lt;p&gt;Any of the database, cloud service, SDK, and API associated with these techs is also compatible with all major operating systems. Organizations prefer them over any other development stack. In addition, if you want real-time or data-critical apps, they also support them. &lt;/p&gt;

&lt;p&gt;Furthermore, with the help of .NET Core, you can connect with other technologies to leverage the data being processed by them. For instance, you can establish a continuous communication with a Python or Java software and use its data or services through an API. &lt;/p&gt;

&lt;h3&gt;
  
  
  #4: Minimizes Efforts in the Long Run
&lt;/h3&gt;

&lt;p&gt;When an organization selects a development technology, it do determine its long run cost. And when it comes to .NET, it quite low as compared to Python, Java, Kotlin or any other tech. It’s because, you don’t have to pay any fee for using it, and Microsoft supports its tech for free. &lt;/p&gt;

&lt;p&gt;In addition, if any vulnerability gets discovered in the framework, Microsoft provides the update. You save the efforts on building and rolling out the patch. In addition, you also avail of the benefit to move to a newer .NET version without any additional complications and cost. &lt;/p&gt;

&lt;p&gt;Thus, .NET makes win-win situation today and in the future too. &lt;/p&gt;

&lt;h3&gt;
  
  
  #5: Fulfills All Necessary Criteria
&lt;/h3&gt;

&lt;p&gt;Let’s not get into the details for this, but .NET assures you with the following across all compatible platforms: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Top-notch performance &lt;/li&gt;
&lt;li&gt;Robust data security &lt;/li&gt;
&lt;li&gt;Seamless integrations &lt;/li&gt;
&lt;li&gt;High-end productivity &lt;/li&gt;
&lt;li&gt;Increased ROI &lt;/li&gt;
&lt;li&gt;Better collaboration &lt;/li&gt;
&lt;li&gt;Application stability, even in high traffic and load hours &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Besides it, whether its Windows, Android, Linux, macOS or any other platform, .NET runs as a supercar of your dreams. And maybe the flying cars are not reality yet, but a development technology (.NET) that rockets up in every factor is. &lt;/p&gt;

&lt;h2&gt;
  
  
  Concluding Up
&lt;/h2&gt;

&lt;p&gt;Overall, businesses choose .NET cross-platform development for its combination of unified development experiences, performance, modern architecture support, and strong community and corporate backing, all of which contribute to more efficient and effective application development and deployment. &lt;/p&gt;

</description>
      <category>dotnet</category>
      <category>webdev</category>
      <category>productivity</category>
      <category>development</category>
    </item>
    <item>
      <title>Dockerizing Microservices: Untangling Scaling and Deployment</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Thu, 11 Jul 2024 08:46:10 +0000</pubDate>
      <link>https://dev.to/whotarusharora/dockerizing-microservices-untangling-scaling-and-deployment-202d</link>
      <guid>https://dev.to/whotarusharora/dockerizing-microservices-untangling-scaling-and-deployment-202d</guid>
      <description>&lt;p&gt;In today's rapidly evolving software landscape, the need for applications that are scalable, reliable, and easy to deploy has never been more critical. Microservices architecture, paired with containerization technologies like Docker, provides a powerful solution to these challenges. &lt;/p&gt;

&lt;p&gt;In this blog, we will explore the advantages of dockerizing microservices and how this approach can streamline deployment and scaling. &lt;/p&gt;

&lt;h2&gt;
  
  
  The Combine Leverage of Docker and Microservices
&lt;/h2&gt;

&lt;p&gt;By using docker in microservices, you can avail of the following benefits. &lt;/p&gt;

&lt;h3&gt;
  
  
  #1: Stable and Standardized Environment
&lt;/h3&gt;

&lt;p&gt;Docker technology helps you to create different containers for each application service. Every container that you create contains the required libraries, dependencies, and all other components. In addition, all the containers are isolated from each other. &lt;/p&gt;

&lt;p&gt;Due to this, any change outside the container doesn’t impact the service running inside it. Moreover, regardless of the software development lifecycle stage, the container runs seamlessly according to the defined logic and protocols. &lt;/p&gt;

&lt;h3&gt;
  
  
  #2: Consistent Workflow
&lt;/h3&gt;

&lt;p&gt;Each container based on docker in microservices has its own processing power, storage and operating system. In addition, all other dependencies are also packed inside it, which helps the services to run smoothly. Because of this, the issue of “it runs only on this machine” gets eliminated. &lt;/p&gt;

&lt;p&gt;You can easily transfer the container from one machine to another and it’ll maintain its state. Additionally, it’ll support you during the migration procedures with minimal errors and deployment issues. &lt;/p&gt;

&lt;h3&gt;
  
  
  #3: Quick and Rapid Scaling
&lt;/h3&gt;

&lt;p&gt;Professionals use microservices, because it helps them to achieve scalability. But, when docker comes with microservices architecture, it increase the ability to scale horizontally. You can utilize it to configure as many container instances you want. It’ll help you support the clients in peak hours, while maintaining data security, and service availability. &lt;/p&gt;

&lt;p&gt;Furthermore, you will improve your customer satisfaction rate, as docker scales per user requirements. Moreover, it also supports you scale your agile model without any additional efforts. &lt;/p&gt;

&lt;h3&gt;
  
  
  #4: Improved Portability
&lt;/h3&gt;

&lt;p&gt;Nowadays, requirements are quite dynamic, due to which you need to explicitly use different platforms and operating systems. With the traditional software architectures, porting from one platform to another can create issues. But, with docker and microservices combination, you can move apps between different ecosystems. &lt;/p&gt;

&lt;p&gt;In addition, there’ll be no additional issues, as all significant operating systems support docker technology. Moreover, the underlying infrastructure of your machine will not create any fuss and nuances. &lt;/p&gt;

&lt;h3&gt;
  
  
  #5: Minimized Resource Wastage
&lt;/h3&gt;

&lt;p&gt;When you utilize only microservices architecture, sometime it utilizes more than required resources. Due to this, the cost to avail those resources gets increased and ROI is reduced. But, when you dockerize the microservices, your application uses minimal resources.&lt;/p&gt;

&lt;p&gt;The main reason behind such reduced usage by docker is its lightweight architecture. In addition, all the docker containers efficiently share the underlying resources and manage them. Therefore, all these factors contribute to minimal resource wastage. &lt;/p&gt;

&lt;h3&gt;
  
  
  #6: Streamlined Microservices Management
&lt;/h3&gt;

&lt;p&gt;Docker offers a simplified tool, known as Docker Compose. You can utilize this tool to manage all the containers in your microservices environment. It provides numerous avant-garde features and benefits, such as: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;It helps in composing the files, defining services, volumes and networks associated with the application. &lt;/li&gt;
&lt;li&gt;It aids in configuration of stable network, which enables the containers to communicate and share data securely and smoothly. &lt;/li&gt;
&lt;li&gt;It also provides the support of environment variable substitution, leading to modify Compose file accordingly.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  #7: Enhanced Isolation
&lt;/h3&gt;

&lt;p&gt;In the docker environment, every microservice gets packed in an individual container. All such containers have their own ecosystems and assigned resources. In addition, they cannot communicate, until or unless the network is manually established between them. &lt;/p&gt;

&lt;p&gt;Due to this feature, you can be assured of complete isolation of microservices. This docker feature helps you during app updation and upgradation operations. When a single microservice gets modified, others are not impacted and there are zero conflicts between dependencies. &lt;/p&gt;

&lt;h3&gt;
  
  
  #8: Better DevOps Practices
&lt;/h3&gt;

&lt;p&gt;Even with multiple advanced tools, using microservices with DevOps development model is still considered a task. But, with docker, it’s a piece of cake. Docker seamlessly gets integrated within the CI/CD pipeline and helps you fasten the software development and deployment process. &lt;/p&gt;

&lt;p&gt;Furthermore, you can configure as many docker images you want and run “n” number of microservices. Moreover, in case you need to improve the application security, it can also align with DevSecOps methodology. &lt;/p&gt;

&lt;h2&gt;
  
  
  How To Implement Docker in Microservices?
&lt;/h2&gt;

&lt;p&gt;Below is a high-level overview of the procedure to implement docker with microservices architecture. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1:&lt;/strong&gt; You need to generate the docker images and pack it into the container, holding the microservice, application code and associated dependencies. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2:&lt;/strong&gt; You should use the docker management tool, such as Kubernetes or Docker Compose  to deploy, manage and scale the containers. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 3:&lt;/strong&gt; Now, you have to configure the network between containers, so that microservices can communicate. In addition, proper security controls should also be implemented to maintain data integrity and confidentiality. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 4:&lt;/strong&gt; Once the containers are deployed, use a monitoring and logging tool to consistently analyze their performance. Kibana, Logstash, and Elasticsearch are some reliable and highly considerable tools for this purpose.  &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 5:&lt;/strong&gt; If you feel the need, integrate your CI/CD pipeline with Docker for faster development, deployment and management of the application. In addition, it’ll also ease your troubleshooting and bug fixing operations. &lt;/p&gt;

&lt;h2&gt;
  
  
  Concluding Up
&lt;/h2&gt;

&lt;p&gt;Dockerizing microservices revolutionizes the way we deploy and scale applications, offering a robust, efficient, and flexible approach to modern software development. In addition, by leveraging the power of Docker and microservices, you can build applications that are easier to manage, deploy, and scale. Moreover, it embraces these technologies to stay ahead in the ever-evolving tech landscape, and helps you enjoy the benefits of a more agile and resilient software architecture. &lt;/p&gt;

</description>
      <category>docker</category>
      <category>microservices</category>
      <category>webdev</category>
      <category>devops</category>
    </item>
    <item>
      <title>Exploring the Latest Features and Enhancements in .NET 8</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Mon, 08 Jul 2024 12:59:24 +0000</pubDate>
      <link>https://dev.to/whotarusharora/exploring-the-latest-features-and-enhancements-in-net-8-23jc</link>
      <guid>https://dev.to/whotarusharora/exploring-the-latest-features-and-enhancements-in-net-8-23jc</guid>
      <description>&lt;p&gt;As a .NET developer, a .NET development company or a development enthusiast, we all know that Microsoft has released the new dotnet version. This time, we have the .NET 8 in the market, which seems to be quite advanced, high in performance, and a complete package of avant-garde features. &lt;/p&gt;

&lt;p&gt;However, it's a new technology, and that's why everyone takes a step back before utilizing it. Due to this, here I have listed the top five features and enhancements that make it a considerable development technology. In addition, undergoing the enhancements will also help you gain insight and understand Microsoft .NET 8 in a better way. &lt;/p&gt;

&lt;p&gt;So, let’s get started. &lt;/p&gt;

&lt;h2&gt;
  
  
  The Top Features and Enhancements of .NET 8
&lt;/h2&gt;

&lt;p&gt;Following are the top five features and enhancements of .NET 8 that make dotnet a better choice in 2024 and until the next .NET release. &lt;/p&gt;

&lt;h3&gt;
  
  
  #1: Better Performance and Scalability
&lt;/h3&gt;

&lt;p&gt;Whenever a new .NET version is released, you are going to experience better performance than previous ones. This factor is consistently focused by Microsoft so that .NET applications run faster and smoother than ever.&lt;/p&gt;

&lt;p&gt;In addition, to improve the performance of .NET 8, Microsoft focused on garbage collection, JIT, and support for ARM64. All these mechanisms together contributed to improving the app's performance. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The GC (Garbage Collector) was tuned to minimize latency, better the throughput, and maintain memory in high-traffic hours. &lt;/li&gt;
&lt;li&gt;The new JIT in .NET 8 helps in faster execution and conversion of intermediate to machine code. Due to this, both server and client-side benefits and app loading are also reduced. &lt;/li&gt;
&lt;li&gt;With the updates to support ARM64, .NET 8 makes you capable of creating high-performing applications compatible with this platform. &lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  #2: Improved Blazor Functionalities
&lt;/h3&gt;

&lt;p&gt;Blazor is an integral component of the .NET ecosystem. You can utilize it for curating intuitive interfaces using the C# programming language. With the release of .NET 8, it has also received some exclusive improvements, such as: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The update provided to WebAssembly of Blazor has made it faster, which is helping the developers to reduce the loading time. Mainly, the tools utilized at runtime are improved so that the interface can function well with the backend logic. &lt;/li&gt;
&lt;li&gt;You will find a new era of Blazor with .NET 8, as it introduces the Blazor Hybrid. It enables you to combine the benefits of Blazor server and WebAssembly. Because of this, you unlock the potential to leverage the utmost flexibility and performance to handle millions of users with ease. &lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  #3: Additional Robustness To ASP.NET Core
&lt;/h3&gt;

&lt;p&gt;In the realm of the .NET ecosystem, ASP.NET Core is always going to be in your discussions. In Microsoft dotnet 8, it has got some really amazing improvements. The main advancements in ASP.NET Core are minimal APIs, rate-limiting middleware, and SignalR enhancement.&lt;/p&gt;

&lt;p&gt;In addition, due to minimal APIs, the developers are able to build lightweight .NET applications. As a result, less boilerplate code is analyzed, leading to the easy and quick maintenance of the software. Further, with the help of rate-limiting middleware, you will be able to secure APIs from abuse and ensure their relevant and fair utilization. &lt;/p&gt;

&lt;p&gt;Lastly, the advancement in SignalR helps to optimize real-time communication. It has fastened the data processing capability, leading organizations to offer updates with zero to minimal delays. &lt;/p&gt;

&lt;h3&gt;
  
  
  #4: gRPC Enhancements
&lt;/h3&gt;

&lt;p&gt;In .NET applications, gRPC helps to enable bidirectional communication with the servers. It ensures that all the transactions are completed simultaneously and that the user device and server are communicating seamlessly. &lt;/p&gt;

&lt;p&gt;In addition, its performance and stability have a major impact on the application. Due to this, in .NET 8, gRPC is highly modified, which makes the usage of protocol buffers more efficient. Moreover, it has received some new tooling, enabling developers to effectively build, test, and debug the gRPC service. &lt;/p&gt;

&lt;p&gt;Furthermore, now you can also integrate with the Visual Studio IDE and configure its operation from your coding platform.&lt;/p&gt;

&lt;h3&gt;
  
  
  #5: New-Age Security and Compliance
&lt;/h3&gt;

&lt;p&gt;From the initial release of .NET, Microsoft has always focused on data security and compliance. And from the very beginning dotnet has provided all the relevant mechanisms in the form of default settings and updates to maintain data integrity. &lt;/p&gt;

&lt;p&gt;This time, with the release of .NET 8, the following three main security and compliance updates are provided: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;New cryptographic algorithms are added to the .NET suite, which will help you prevent attackers, and ensure data confidentiality and integrity. &lt;/li&gt;
&lt;li&gt;You can configure multi-factor authentication using the built-in components and the OpenID Connect and OAuth 2.0 protocols. &lt;/li&gt;
&lt;li&gt;The tools provided with the .NET 8 package can aid you in ensuring that the application aligns with relevant standards, such as GDPR, PCI-DSS, and HIPAA. In addition, guidelines to align with other regulatory compliance frameworks are also offered. &lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Concluding Up
&lt;/h2&gt;

&lt;p&gt;From all the above aspects, we can conclude that .NET 8 has mainly focused on performance, data security, compliance, Blazor, .NET Core, and gRPC. You can use all these features to build highly stable, secure, and scalable applications that can exceptionally boost productivity. &lt;/p&gt;

&lt;p&gt;.NET is a feature-rich technology, and you can’t ignore it with the dotnet 8 version or beyond. And once you utilize it, you’ll get to know about its potential.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>dotnet</category>
      <category>performance</category>
      <category>vscode</category>
    </item>
    <item>
      <title>The GUI Way of Using Linux (How To Use Cockpit on CentOS)</title>
      <dc:creator>Tarush Arora</dc:creator>
      <pubDate>Mon, 24 Jun 2024 14:40:52 +0000</pubDate>
      <link>https://dev.to/whotarusharora/the-gui-way-of-using-linux-how-to-use-cockpit-on-centos-lp</link>
      <guid>https://dev.to/whotarusharora/the-gui-way-of-using-linux-how-to-use-cockpit-on-centos-lp</guid>
      <description>&lt;p&gt;Have you every thought of executing Linux operations without the command line? Maybe not. But, now there’s a way to do that. You can use the Cockpit package for this purpose, which is extremely helpful for system administrators and server monitoring and maintenance teams. &lt;/p&gt;

&lt;p&gt;You can get the info about &lt;a href="https://cockpit-project.org" rel="noopener noreferrer"&gt;cockpit &lt;/a&gt; on the official website. But, the most convenient way to configure it is here in this blog. So, without wasting any second, let’s start with the practical. &lt;/p&gt;

&lt;h2&gt;
  
  
  The Cockpit Configuration Procedure
&lt;/h2&gt;

&lt;p&gt;We are going to perform this practical on CentOS operating system, a distribution of the Linux, developed  by RedHat enterprises. In numerous enterprise networks, it gets utilized as the primary server OS. So, it’s going to be beneficial for sure. &lt;/p&gt;

&lt;p&gt;Additionally, the entire procedure is divided into three phases. The first phase deals with download and installation of the cockpit package. Further, the phase two and three deals with the configuration and accessing the GUI-based Linux interface. &lt;/p&gt;

&lt;p&gt;So, let’s get started. &lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 1: Cockpit Download and Installation
&lt;/h3&gt;

&lt;p&gt;Before, we dive into the practical, ensure to look at the snippets simultaneously for better understanding. &lt;/p&gt;

&lt;p&gt;We are going to configure cockpit as a root server. So, we have ensured that, system is accessed as root by using the command &lt;code&gt;whoami&lt;/code&gt;. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F61gt45gafyrm5kpt4qtr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F61gt45gafyrm5kpt4qtr.png" alt="whoami" width="799" height="258"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There can be a possibility that cockpit service package is already installed on your CentOS system. To find it out, use the command &lt;code&gt;rpm -qa | grep cockpit&lt;/code&gt;. If the package would be available, you’ll see it in the list. &lt;/p&gt;

&lt;p&gt;In our case, it’s not available. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foni8u566a9vkn5jnppq8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foni8u566a9vkn5jnppq8.png" alt="Checking package availability" width="800" height="293"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;To install the cockpit package, use the command: &lt;code&gt;yum install cockpit -y&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The command will start the download and installation of the cockpit package on your CentOS operating system. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foa9tw6rcg1wtm9hvwfxh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foa9tw6rcg1wtm9hvwfxh.png" alt="Installing cockpit" width="800" height="93"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After the successful installation, you will see a output as below.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fi5cypzblo4jaxz3r7u3w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fi5cypzblo4jaxz3r7u3w.png" alt="Installed" width="800" height="541"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now, again check the cockpit package availability to verify its installation &lt;/p&gt;

&lt;p&gt;Run the command: &lt;code&gt;rpm -qa | grep cockpit&lt;/code&gt; &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Faa2tnz9wgmx3a48q8ufa.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Faa2tnz9wgmx3a48q8ufa.png" alt="Installation Verification" width="800" height="251"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Here, the first phase ends. Now, move to the second one. &lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 2: Enabling the Cockpit Service
&lt;/h3&gt;

&lt;p&gt;You have to use the classic method to enable the cockpit service, which is using the &lt;code&gt;systemctl&lt;/code&gt;. &lt;/p&gt;

&lt;p&gt;Firstly, check the status of the services through command: &lt;code&gt;systemctl status cockpit&lt;/code&gt; &lt;/p&gt;

&lt;p&gt;As you can see, currently the service is inactive.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwxz0q4nceqp6cyk8n9he.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwxz0q4nceqp6cyk8n9he.png" alt="Cockpit state" width="800" height="193"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;To make the service active, run command: &lt;code&gt;systemctl start cockpit&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;However, if you want this service to run automatically with every boot, use the command: &lt;code&gt;systemctl enable cockpit&lt;/code&gt; &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwn3qktwemd7afxfha89a.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwn3qktwemd7afxfha89a.png" alt="Cockpit enable" width="794" height="57"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After starting the service, check the status: &lt;code&gt;systemctl status cockpit&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;As you can see, this time the service is running on our Linux machine. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyezhnbcal94mu1u3t2dz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyezhnbcal94mu1u3t2dz.png" alt="Cockpit running" width="800" height="366"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Here, our second phase ends. Move to the third one now. &lt;/p&gt;

&lt;h3&gt;
  
  
  Phase 3: Accessing the Linux System (GUI-based)
&lt;/h3&gt;

&lt;p&gt;Before you access the GUI-based interface, you should know about the URL for accessing Linux machine through cockpit.&lt;/p&gt;

&lt;p&gt;URL: &lt;code&gt;http:// IP of your machine:9090&lt;/code&gt; &lt;/p&gt;

&lt;p&gt;So, to fulfil the demand of the URL, run the &lt;code&gt;ifconfig&lt;/code&gt; command to view your IP address. In our case, it’s &lt;code&gt;192.168.1.6&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fub6mwstscrrl3ax5dkh2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fub6mwstscrrl3ax5dkh2.png" alt="IP" width="799" height="423"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now, go to your web browser and use the URL, just like the snippet below. Enter the URL and hit enter. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwi0m01xjztqkv02hhp3b.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwi0m01xjztqkv02hhp3b.png" alt="Browser" width="798" height="140"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Once you hit enter, a warning can be showed to you. You have to accept the risk and move forward to view the following login interface. &lt;/p&gt;

&lt;p&gt;However, if even after accepting the risk, you didn’t view the interface, go to Linux machine and disable the firewall using command: &lt;code&gt;systemctl disable firewalld&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;(Note: Do not disable firewall in production environment)&lt;/p&gt;

&lt;p&gt;Following it, again enter the URL and this time you’ll absolutely see the interface. Now, put your username and password of the Linux machine and hit the Log in button.  &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fw8i41pq9gi6poywbvuq4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fw8i41pq9gi6poywbvuq4.png" alt="Login Interface" width="800" height="444"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;As a result, you will see the cockpit interface or the GUI-interface of your Linux machine. Now, you can execute all core operations without commands with utmost convenience. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpiqx8qtuxehyjxbf8p7x.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpiqx8qtuxehyjxbf8p7x.png" alt="Final Interface" width="800" height="342"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Here, the third phase ends and also the practical procedure. Explore the interface and have fun with Linux GUI. &lt;/p&gt;

&lt;h2&gt;
  
  
  Concluding Up
&lt;/h2&gt;

&lt;p&gt;Nothing much to write here, as you already know how to use cockpit. For any further query or question, you can write a comment and expect me to get back to you within a week. Also, you can suggest topics and I would try to provide you the desired content on them. &lt;/p&gt;

&lt;p&gt;Keep supporting. &lt;/p&gt;

</description>
      <category>linux</category>
      <category>webdev</category>
      <category>beginners</category>
      <category>productivity</category>
    </item>
  </channel>
</rss>
