Skip to main content

Penetration Testing

Showing posts tagged with "Penetration Testing".

How Do "Pass-the-Hash" Attacks Work?

Pass the Hash Mitre ATT&CK Technique ID Use Alternate Authentication Material: Pass the Hash T1550.002 What is it? Passing the hash is a technique…

Read more

How to Compromise AWS Using the Metadata Service

Mitre ATT&CK Technique ID Unsecured Credentials: Cloud Instance Metadata API T1552.005 The AWS Metadata service facilitates information access for…

Read more

How to Use ScoutSuite for AWS Security Baselining

ScoutSuite Introduction ScoutSuite is a multi-cloud security auditing tool written by the wonderful folks over at NCC group. We use it heavily here at…

Read more

API Hacking: Exploring Web Vulnerabilities Under the Hood

In modern web applications, almost all functionality offered to users is handled by an Application Programming Interface or API for short. To help vis…

Read more

Certification Experience: OSCP and PWKv2

Strategy recommendations, pitfalls to avoid, and why you should just write the lab report for crying out loud. There’s a reason why this certification…

Read more

Productive Hacking: 5 Indicators of a Quality Penetration Test

Key elements of penetration tests that actually work for you. Everyone seems to have a different idea of what a penetration test is. Does it involve p…

Read more

Webinar: Pentest Engagement Types: A Guide to Understanding Simulated Attack Types

This webinar will define and explain common penetration test offerings in detail, outline the key differences and benefits, and help you decide which …

Read more

The Road To Better Password Cracking (Part 2)

The part where hashcat does a ton of heavy lifting. In the last post, I discussed how some simple character conversion and inferences about human beha…

Read more

A Red Teamer’s Trip to the Doctor

The things that go through a security professional’s head during a regular doctor's visit, why they matter to the healthcare industry, and why they sh…

Read more

The Road to Better Password Cracking (Part 1)

Or: how I learned to stop worrying and love AWS GPU clusters. Passwords are terrible.

Read more

Sudo: Its History and How to Abuse It

A quick explanation of one of the most influential and misconfigured computing utilities.

Read more

So, you got a pentest. Now what?

How to progress toward a truly secure organization and infrastructure after penetration testing. You did it – you paid for penetration testing service…

Read more

Tags

See all