Skip to content

Blog

Field notes from the offensive side

Practical writing on penetration testing, attack techniques, and the compliance frameworks that reference them.

LatestGuidesAug 27, 2026 · 5 min read

AWS Penetration Testing: Scope, Rules, and What Gets Tested

How AWS penetration testing works: the shared responsibility model, what you may test without permission, IAM and S3 attack paths, and how to scope an engagement.

Read the article
GuidesAug 27, 2026

AWS Penetration Testing: Rules, Scope, and What to Test

How AWS penetration testing works: what Amazon allows without approval, what's off-limits, the misconfigurations that cause real cloud breaches, and how to scope a test.

Read2 min read
GuidesAug 27, 2026

Black Box vs White Box vs Grey Box Penetration Testing

What black box, white box, and grey box penetration testing each mean, what each finds and misses, what they cost, and how to choose the right method for your goal.

Read5 min read
Red TeamingAug 27, 2026

BloodHound: Mapping Active Directory Attack Paths

What BloodHound is, how it maps hidden Active Directory attack paths to Domain Admin, what its findings reveal about your AD, and how defenders use it to close them.

Read5 min read
GuidesAug 27, 2026

Which Compliance Frameworks Require Penetration Testing?

A framework-by-framework guide to penetration testing for compliance: what SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR and NYDFS actually require, and how often.

Read5 min read
GuidesAug 27, 2026

E-Commerce & Retail Penetration Testing

Penetration testing for e-commerce and retail: PCI DSS obligations, the checkout and payment risks that matter, Magecart and API threats, and how to scope a test.

Read4 min read
Red TeamingAug 27, 2026

Evil-WinRM: Windows Remote Management for Testers

What Evil-WinRM is, how testers use it to get an interactive shell over WinRM, what its use in a report reveals about your controls, and how defenders detect it.

Read4 min read
Red TeamingAug 27, 2026

Evilginx: Phishing That Bypasses MFA

What Evilginx is, how adversary-in-the-middle phishing steals session tokens to bypass MFA, what it means for your defences, and how phishing-resistant MFA stops it.

Read5 min read
GuidesAug 27, 2026

Fintech & Financial Services Penetration Testing

Penetration testing for fintech and financial services: the regulations that require it, what to scope across APIs, apps and cloud, and how to test payment flows safely.

Read4 min read
Red TeamingAug 27, 2026

Gobuster: Directory, DNS and Vhost Brute-Forcing

What Gobuster is, how testers use it to discover hidden directories, subdomains and virtual hosts, what its findings mean for your attack surface, and how to detect it.

Read4 min read
GuidesAug 27, 2026

Healthcare Penetration Testing: A Complete Guide

Healthcare penetration testing explained: what HIPAA expects, ePHI scoping, EHR and medical device testing, and how to run an assessment without disrupting care.

Read6 min read
GuidesAug 27, 2026

How to Choose a Penetration Testing Company

What separates good penetration testing companies from bad ones: certifications, methodology, reporting, retesting, and the questions to ask before you sign.

Read6 min read
Red TeamingAug 27, 2026

Impacket: The Windows Network Attack Toolkit

What Impacket is, the key scripts testers use against Active Directory, what its findings reveal about your Windows network, and how defenders detect and stop it.

Read4 min read
GuidesAug 27, 2026

ISO 27001 Penetration Testing Requirements

Does ISO 27001 require penetration testing? What Annex A 8.8 and Clause 9 actually demand, how testing provides the evidence, scope, frequency, and what auditors expect.

Read4 min read
Red TeamingAug 27, 2026

Kerbrute: Active Directory User Enumeration Explained

What Kerbrute is, how testers use it to enumerate Active Directory users and spray passwords quietly, what its findings mean, and how defenders detect and stop it.

Read4 min read
GuidesAug 27, 2026

Penetration Testing for Law Firms

Why law firms are high-value targets, what client-confidentiality and ethics rules demand, what to scope, and how penetration testing protects privileged data.

Read4 min read
Red TeamingAug 27, 2026

Masscan: Internet-Scale Port Scanning Explained

What Masscan is, how it scans enormous IP ranges in minutes, how it differs from Nmap, what its findings mean for your external attack surface, and how to detect it.

Read4 min read
Red TeamingAug 27, 2026

msfvenom: Payload Generation Explained

What msfvenom is, how testers use it to generate and encode payloads, what its use in a report means, and how modern defences detect and stop generated payloads.

Read4 min read
Red TeamingAug 27, 2026

NetExec (nxc): The CrackMapExec Successor Explained

What NetExec is, why it replaced CrackMapExec, the protocols and modules that matter in a real engagement, and how defenders detect it.

Read5 min read
GuidesAug 27, 2026

How to Choose a Penetration Testing Company in NYC

A buyer's guide to choosing a penetration testing company in New York: what local presence actually buys you, the NYC-specific compliance angles, and how to compare firms.

Read4 min read
Application PentestingAug 27, 2026

OWASP ASVS: The Application Security Verification Standard

What the OWASP Application Security Verification Standard (ASVS) is, how its three levels work, how it differs from the Top 10, and how to use it in a pentest.

Read5 min read
GuidesAug 27, 2026

Penetration Testing as a Service (PTaaS): What It Is

What PTaaS actually means, how it differs from traditional penetration testing and automated scanning, what it costs, and when a subscription model is worth it.

Read5 min read
Red TeamingAug 27, 2026

Responder: LLMNR/NBT-NS Poisoning Explained

What Responder is, how it poisons LLMNR and NBT-NS to capture Windows credentials, what a finding means for your network, and how to shut the attack down.

Read4 min read
Red TeamingAug 27, 2026

Smishing: SMS Phishing Attacks and How to Defend

What smishing is, why SMS phishing bypasses email defences and works so well on phones, the common attack types, and how to test and defend against it.

Read5 min read
Red TeamingAug 27, 2026

Spear Phishing: Targeted Attacks and How to Defend

What spear phishing is, how it differs from ordinary phishing, the real techniques attackers use against named employees, and how testing and controls stop it.

Read5 min read
Red TeamingAug 27, 2026

Vishing: Voice Phishing Attacks and How to Defend

What vishing is, how attackers use phone calls and AI voice cloning to bypass technical defences, the real-world attacks that start with a call, and how to defend.

Read5 min read
GuidesAug 27, 2026

Vulnerability Assessment and Penetration Testing (VAPT)

What VAPT means, how vulnerability assessment differs from penetration testing, when you need each, what a combined engagement covers, and what it costs.

Read5 min read
Red TeamingJul 13, 2026

Offense in Depth in Red Team Operations

Defense in depth layers protection. Offense in depth layers attack paths so a red team still reaches its objective when one route fails. Here is how it works.

Read4 min read
Proactive SecurityJun 29, 2026

Security Between Penetration Tests

An annual pentest covers two weeks and leaves fifty uncovered. Here is how to secure the rest of the year without waiting for the next scheduled engagement.

Read4 min read
AI/ML PentestingMay 29, 2026

The Limits of AI in Penetration Testing

AI is changing penetration testing, but it will not replace human testers. Here is what it does well, where it falls short, and why judgment still wins.

Read4 min read
Proactive SecurityMay 13, 2026

The Cost Savings of Proactive Security

Proactive security looks like pure cost until you price the breach it prevents. Here is the economic case for testing early, in terms a CFO will recognize.

Read4 min read
AI/ML PentestingApr 15, 2026

Penetration Testing for AI and LLM Systems

AI applications add attack surface that traditional testing misses. See how attackers target LLMs, from prompt injection to data leakage, and how to test them.

Read4 min read
AI/ML PentestingMar 26, 2026

Indirect Prompt Injection Explained

Indirect prompt injection hides attacker instructions in content an AI later reads. Learn how the attack works, why it is dangerous, and how to defend.

Read4 min read
Red TeamingFeb 20, 2026

Is Your Organization Ready for Red Teaming?

Red teaming rewards mature security programs and overwhelms immature ones. Here is how to tell if you are ready, and how to plan a scenario worth running.

Read4 min read
RansomwareJan 31, 2026

Ransomware: How Modern Attacks Actually Work

Ransomware is no longer just encryption. Here is how modern attacks unfold, why backups are not enough, and where penetration testing breaks the kill chain.

Read4 min read
AI/ML PentestingJan 15, 2026

Planning for AI Vendor Failure

AI startups fold, get acquired, and pivot constantly. If your product depends on one, here is how to stay resilient when your AI provider disappears or changes.

Read4 min read
GuidesDec 26, 2025

Application Security Myths, Debunked

Common myths quietly undermine application security programs. Here are the most persistent ones, and what actually holds up once you test them against reality.

Read4 min read
Application PentestingNov 23, 2025

The OWASP API Security Top 10, Explained

The OWASP API Security Top 10 names the risks that break real APIs. Here is what each category means in plain terms, and why authorization dominates the list.

Read4 min read
Application PentestingOct 29, 2025

API Security Best Practices

A practical guide to API security: authentication, authorization, rate limiting, input validation, and the design habits that keep your endpoints from leaking.

Read4 min read
GuidesOct 23, 2025

Penetration Testing Cost in 2026

What drives penetration testing cost: scope, test type, and timeline, plus realistic price ranges by engagement.

Read3 min read
Red TeamingSep 16, 2025

How to Prepare for a Red Team Engagement

Is your organization ready for a red team? Signs of readiness, how objectives and scenarios are set, and what to expect from kickoff through the final readout.

Read2 min read
Red TeamingAug 24, 2025

Crafting Realistic Red Team Scenarios

A red team is only as valuable as its scenario. Learn how to design intelligence-driven, realistic scenarios modeled on the threats that actually target you.

Read4 min read
Red TeamingAug 7, 2025

Getting the Most From a Red Team

The value of a red team is in what you do after it. Here is how to turn an exercise into lasting improvement through debriefs and real follow-through.

Read4 min read
AI/ML PentestingJul 20, 2025

How Integrations Expand the LLM Attack Surface

An LLM becomes far more dangerous the moment you connect it to tools and data. Here is how integrations expand the attack surface, and how to contain the risk.

Read4 min read
GuidesJun 27, 2025

SOC 2 Pentest Requirements Explained

Does SOC 2 require a penetration test? What auditors expect, what the report should include, and when to time testing.

Read3 min read
AI/ML PentestingJun 24, 2025

The OWASP Top 10 for LLM Applications, Explained

A plain-English guide to the OWASP Top 10 for LLM Applications: what each risk means, why it matters, and how to test your AI system against it.

Read3 min read
Application PentestingMay 29, 2025

SaaS Penetration Testing: A Complete Guide

SaaS penetration testing explained: multi-tenant isolation, API and auth testing, what enterprise buyers and SOC 2 auditors expect, and how to scope an engagement.

Read4 min read
Application PentestingMay 27, 2025

Cloud Application Security: A Practical Guide

A practical guide to cloud application security: the shared responsibility model, the risks that actually cause cloud breaches, and how to test for them.

Read3 min read
Application PentestingMay 14, 2025

Shifting Security Left in the SDLC

Shift-left security moves testing earlier in the development lifecycle, where flaws are cheap to fix. Here is what it means in practice and how to do it well.

Read4 min read
AI/ML PentestingApr 10, 2025

Adversarial Machine Learning: Key Terms

A plain-English glossary of adversarial machine learning: evasion, poisoning, model inversion, extraction, and the other terms security teams need to know.

Read4 min read
Red TeamingApr 8, 2025

Defensive vs Offensive Security: The Difference

Defensive vs offensive security explained: what each approach does, how blue teams and red teams differ, and why you need both to actually stay secure.

Read3 min read
Proactive SecurityMar 18, 2025

CTEM: Continuous Threat Exposure Management

CTEM is a framework for continuously finding and reducing exposure instead of testing once a year. Here is what its five stages mean and how to put it to work.

Read4 min read
GuidesMar 18, 2025

The Ultimate Penetration Testing Checklist

A practical penetration testing checklist covering scoping, pre-engagement, testing coverage, reporting, and remediation, so your next pentest is thorough and audit-ready.

Read5 min read
Red TeamingMar 4, 2025

Red Team vs Blue Team: The Difference

Red team vs blue team explained: what each does in cyber security, how they differ, where purple teaming fits, and how red teaming compares to penetration testing.

Read3 min read
Proactive SecurityFeb 25, 2025

External Attack Surface Management (EASM), Explained

What external attack surface management (EASM) is, why your internet-facing footprint keeps growing, and how it works alongside penetration testing.

Read3 min read
GuidesFeb 24, 2025

Building a Secure Code Review Program

Secure code review finds flaws automated scanning misses, at the source. Here is how to build a program that scales without slowing your engineers down.

Read4 min read
GuidesFeb 11, 2025

PCI DSS Compliance Checklist

A practical PCI DSS compliance checklist covering all 12 requirements, scoping your cardholder data environment, and the penetration testing PCI requires.

Read4 min read
Application PentestingFeb 8, 2025

A Layered Approach to AppSec Testing

No single test secures an application. Learn how SAST, DAST, pentesting, and code review fit together into a layered application security testing strategy.

Read4 min read
GuidesJan 25, 2025

How to Scope Your First Penetration Test

A step-by-step guide to scoping your first penetration test: what to define, what to expect on a scoping call, and mistakes to avoid.

Read3 min read
GuidesJan 14, 2025

Security Risk Assessment: A Practical Guide

What a security risk assessment is, how it differs from a penetration test, the steps involved, and how it fits compliance frameworks like SOC 2, ISO 27001, and HIPAA.

Read3 min read
GuidesJan 7, 2025

IT Security Audit: What It Is and How It Works

What an IT security audit is, what it covers, how it differs from a penetration test, and how information security audit services support SOC 2, ISO 27001, and HIPAA.

Read3 min read
GuidesDec 30, 2024

Types of Penetration Testing: A Complete Guide

The main types of penetration testing by target (web, API, mobile, network, cloud, hardware, social) and by method (black, white, and grey box), and how to choose.

Read3 min read
AI/ML PentestingDec 21, 2024

Balancing LLM Security and Usability

Lock an AI assistant down too hard and it becomes useless; too loose and it becomes a liability. Here is how to find the balance between security and usability.

Read4 min read
GuidesDec 10, 2024

Cloud Security Best Practices

The cloud security best practices that actually prevent breaches: identity, data protection, configuration, monitoring, and testing, in priority order.

Read3 min read
Proactive SecurityDec 1, 2024

Proactive Security: Finding Risk First

Reactive security waits for the alarm. Proactive security finds and fixes weaknesses before attackers reach them. Here is what the shift looks like in practice.

Read4 min read
GuidesNov 19, 2024

Automated vs Manual Penetration Testing

Automated penetration testing is fast and cheap, but it misses the flaws that cause breaches. Here is what automation catches, what it cannot, and the right blend.

Read3 min read
Application PentestingNov 5, 2024

Web Application Security Testing: The Complete Guide

The types of web application security testing (SAST, DAST, IAST, SCA, and manual penetration testing), what each catches, and how to combine them effectively.

Read3 min read
Application PentestingNov 2, 2024

API Penetration Testing: A Complete Guide

What API penetration testing covers, which vulnerabilities matter most, and how to scope a test for REST, GraphQL, and internal APIs before attackers strike.

Read4 min read
GuidesOct 27, 2024

NYDFS 23 NYCRR 500: What Penetration Testing Does the Regulation Actually Require?

A practical guide to the penetration testing and vulnerability assessment requirements in New York's NYDFS Cybersecurity Regulation (23 NYCRR 500) for covered financial entities.

Read2 min read
Application PentestingOct 8, 2024

The OWASP Mobile Top 10, Explained

A plain-English guide to the OWASP Mobile Top 10: the most critical mobile app security risks for iOS and Android, and how to test your app against them.

Read3 min read
Application PentestingSep 16, 2024

The Risk of Malicious Connected Apps

OAuth connected apps can read your email and files without ever touching your password. Here is how malicious integrations work and how to limit the damage.

Read4 min read
GuidesSep 16, 2024

Penetration Testing vs Vulnerability Scanning

Penetration testing vs vulnerability scanning vs vulnerability assessment: what each one is, how they differ, and when you need which. A clear, practical comparison.

Read3 min read
GuidesAug 31, 2024

Application Security Program Maturity

How mature is your application security program? A practical checklist across five levels, from ad hoc to optimized, and how to move up to the next one.

Read4 min read
Application PentestingAug 13, 2024

The Security Risks of Vibe Coding

AI can generate working code from a prompt in seconds. It can generate insecure code just as fast. Here are the risks of vibe coding and how to ship it safely.

Read4 min read
GuidesJul 23, 2024

Getting Started with Application Security

Building an application security program from nothing is less about tools than sequence. Here is a practical first-90-days path that avoids the common traps.

Read4 min read

Put it into practice

Reading is good. Testing is better.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire?

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.