#tag

Pentest

20 matching posts.

All tags
PentestSep 11, 202617 min read

The Login Page Was Public. The Identity Boundary Was Somewhere Else.

A public login page is only the visible start of an identity system. External pentesting must map the issuer, callback, token policy, account binding, tenant and role conversion, and local session before testing authorization.

#pentest#external-pentest#methodology#identity-security#authentication
PentestSep 10, 202616 min read

The Service Was Observed. The Application Was Still Unknown.

Passive internet data can reveal a live service without proving its current owner, hostname, virtual host, application, or business purpose. A defensible external pentest turns that observation into a bounded application model before testing for vulnerabilities.

#pentest#external-pentest#methodology#attack-paths#web-security
PentestSep 9, 202616 min read

The Vendor Was Out of Scope. The Trust Boundary Was Not.

A third-party platform may be excluded from testing while the customer-controlled trust decisions around it remain assessable: identity claims, callbacks, webhooks, custom domains, delivery paths, and data flows.

#pentest#external-pentest#methodology#identity-security#cloud-security
PentestSep 8, 202614 min read

The Domain Resolved. Ownership Was Still a Hypothesis.

A defensible external pentest does not turn company names, CT records, shared IPs, or acquisition news into targets. It separates association, current control, and written scope—then records the evidence for each decision.

#pentest#external-pentest#methodology
PentestSep 3, 202612 min read

One ATM Was Contained. The Fleet Trust Path Was Not.

The final ATM assessment chapter: test remote support, software deployment, segmentation, monitoring, transaction integrity, containment, and reconciliation as fleet-wide control planes.

#pentest#atm-security#methodology#access-control#resilience
PentestSep 2, 202612 min read

The Device API Was Standard. Authorization Was Assumed.

Part four of the ATM assessment series: test XFS-style middleware, caller identity, service providers, peripheral state, PIN boundaries, and transaction context with emulators and denied requests—not live device effects.

#pentest#atm-security#methodology#access-control#resilience
PentestSep 1, 202612 min read

The Desktop Was Hidden. The Execution Boundary Was Not.

Part three of the ATM assessment series: validate kiosk containment, application control, service identities, maintenance states, secrets, updates, and off-host telemetry without turning UI escape testing into a payload exercise.

#pentest#atm-security#methodology#access-control#resilience
PentestAug 31, 202617 min read

The BIOS Had a Password. The Boot Chain Still Needed Trust.

Part two of the ATM assessment series: an evidence-driven method for validating firmware recovery, Secure Boot, measured boot, disk-unlock policy, update integrity, and off-host detection without publishing a hardware-bypass playbook.

#pentest#atm-security#methodology#resilience#access-control
PentestAug 30, 202615 min read

The ATM Was Locked Down. The Transaction Path Was Not.

An evidence-driven methodology for authorized ATM security assessments: test the trust boundaries between the kiosk, operating system, device middleware, EPP, service network, monitoring plane, and transaction switch without turning the engagement into a cash-out exercise.

#pentest#atm-security#methodology#resilience#access-control
PentestAug 30, 202618 min read

The Red Team Reached Domain Admin. The Exercise Still Failed.

Domain Admin is a capability, not a business objective. This field methodology turns an authorized red team operation into a testable chain of objective, runtime authority, technical action, defender signal, response decision, evidence, and verified recovery.

#red-team#pentest#attack-paths#detection#resilience
PentestAug 29, 202614 min read

The External Perimeter Is a Graph. The Port List Is Only One View.

Modern external pentesting starts by proving how domains, companies, certificates, identity systems, cloud services, and third parties relate. Active scanning then verifies the small part of that graph that is both relevant and authorized.

#pentest#external-pentest#methodology#cloud-security#identity-security
PentestAug 24, 202622 min read

AI Vulnerability Discovery: One Frontier Model or Three Specialists?

A reproducible benchmark design for the decision security teams actually face: spend the same research budget on repeated runs of one strong model, or on a diverse model team—and count only vulnerabilities that survive root-cause review, reproduction, and a fixed-version negative control.

#ai-security#methodology#pentest
PentestAug 23, 202616 min read

The Model Proposed the Action. The Broker Decided Whether It Could Exist.

A practical architecture for AI-assisted pentest execution: resolve scope outside the model, classify side effects, issue short-lived capabilities, deny high-impact authority, and preserve a decision record that can be independently verified.

#ai-security#pentest#methodology#access-control#attack-paths
PentestAug 21, 202618 min read

The Model Found the Vulnerability. The Tool Call Became the Incident.

A balanced operating model for AI-assisted pentesting: where models improve coverage and evidence work, where excessive agency turns a valid test into a destructive action, and how to keep cloud, shell, and Domain Admin authority outside the model.

#ai-security#pentest#methodology#access-control#active-directory
PentestAug 13, 202618 min read

The Handshake Was Captured. The Network Was Not.

A Wi-Fi assessment methodology that separates radio visibility, network identity, authentication, client trust, and post-association access before calling a wireless test successful.

#wireless-security#authentication#access-control#pentest#methodology
PentestJul 9, 202618 min read

The Model Is Not the Target. The Pipeline Is.

A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.

#methodology#pentest#attack-paths#cloud-security#ai-security
PentestFeb 26, 202618 min read

Android App Links: The Link Was Verified. The Action Was Not.

A field methodology for Android App Links that separates domain ownership, route validation, application state, and server-side authorization before calling a deep link secure.

#mobile-security#access-control#authentication#pentest#methodology
PentestNov 7, 20257 min read

They Do Not Break In. They Log In.

Part one of testing the ransomware playbook: the initial access an affiliate needs is almost always a valid credential against a reachable endpoint — and that finding is usually already in a report somewhere, marked medium.

#ransomware#authentication#access-control#pentest
PentestSep 11, 20257 min read

SMB Signing Is On. That Closed One Edge, Not the Graph.

Signing is a per-protocol control, and NTLM over HTTP cannot be signed at all. The useful question is never whether signing is enabled — it is which relay edges are still open.

#active-directory#identity-security#access-control#pentest
PentestFeb 13, 20257 min read

Kerberoasting Triage: Most Service Tickets Are a Waste of Your Time

Requesting every SPN in the domain is easy. Knowing which twelve tickets are worth cracking — and which ones will burn a week of GPU time for nothing — is the actual skill.

#active-directory#identity-security#methodology#pentest