Penetration Testing
Resources Blog

Penetration Testing

Keep up to date with the latest offensive security news, knowledge, and resources.
Hook, Line, and Server
Apr 23, 2026

Hook, Line, and Server

MFA doesn't stop session cookie replay. Endpoint detection doesn't catch fileless malware without behavioral analysis. Here's the full post-phishing kill chain and what actually stops it.
Cracking NTLMv1 SSP With Rainbow Tables
Apr 21, 2026

Cracking NTLMv1 SSP With Rainbow Tables

Step-by-step walkthrough of cracking NTLMv1-SSP hashes with rainbow tables, including how to coerce auth, disable ESS, recover NT hashes, and remediate.
Vulnerability Hunting a Retired App Part 2 - From File Write to SYSTEM
Apr 16, 2026

Vulnerability Hunting a Retired App Part 2 - From File Write to SYSTEM

Discover how an unsanitized file write endpoint in Omega Enterprise Gateway escalates to SYSTEM-level code execution and what dead code reveals about real-world security bugs.
Penetration Testing Strategies for Legacy Healthcare Systems
Mar 26, 2026

Penetration Testing Strategies for Legacy Healthcare Systems

Legacy healthcare systems can’t be patched but they can’t be ignored. Learn how to pentest around clinical assets without disrupting patient care.
Popping Printers: How Your MFPs Are Handing Attackers Domain Admin
Mar 23, 2026

Popping Printers: How Your MFPs Are Handing Attackers Domain Admin

Multifunction printers silently store domain credentials, expose unauthenticated management interfaces, and sit on flat networks. Learn how attackers exploit MFPs to achieve domain admin in minutes.
Starting Strong: Successful Onboarding with Sprocket Security
Mar 19, 2026

Starting Strong: Successful Onboarding with Sprocket Security

The fastest path from kickoff to testing starts with alignment, preparation, and the right people in the room.
1 2 3 4 5