Penetration testing

The top 5 pentesting tools you will ever need [updated 2021]

A penetration test or “pentest” is a human-driven assessment of an organization’s security. One or more pentesters will be engaged by an organization to iden

Using Merlin agents to evade detection

Introduction While penetration testing and Red Teaming are crucial to check a system’s security and to validate potential entry-points in the infrastructure

Fuzzing introduction: Definition, types and tools for cybersecurity pros

Fuzzing is a black-box software testing technique and consists of finding implementation flaws and bugs by using malformed/semi-malformed payloads via automa

Important SQLMap commands

The SQLMap tool can be found in every penetration tester's toolbox. It is one of the most popular and powerful tools when it comes to exploiting SQL injectio

Zero-day Sophos XG firewall vulnerability: an exploit guide for pentesters

The Sophos XG firewall vulnerability The Sophos XG Firewall recently had a publicly-reported zero-day vulnerability. The vulnerability in question was an SQ

What are black box, grey box, and white box penetration testing? [Updated 2020]

Pentesters are apparently huge fans of colors. Different roles within pentesting assignments are designated as Red Team, Blue Team, Purple Team and others. G

Rules of engagement in pentesting

When you create a software product or build a service or create a platform, it’s a good idea to make sure it is secure. The data we generate is feeding the c

MITRE ATT&CK: Screen capture

Introduction  There is an old saying that goes “a picture is worth a thousand words.” In many ways, this saying is true: you can learn a great deal about a p

The future of Red Team operations

Introduction The Red Team assessment is an increasingly popular method for an organization to get a realistic feel for their overall security. Organizations’

Red Team Operations: Providing recommendations

The importance of recommendations The Red Team’s final report is the most valuable part of the entire exercise for the client. In many cases, a Red Team is s