SMB Relay Attacks and How to Prevent Them in Active Directory

SMB Relay Attacks and How to Prevent Them in Active Directory

0. Overview Many organizational networks rely on Active Directory (AD) to streamline administrative tasks and enhance efficiency. However, some of its default configurations are vulnerable to attackers. The SMB (Server Message Block) protocols stand out as...
Should a Company Provide Credentials for Their Penetration Test?

Should a Company Provide Credentials for Their Penetration Test?

On occasion, we get clients who are concerned about some of the stereotypes that they may read about or hear when it comes to a penetration test. While a penetration test may be us attacking your infrastructure, we are not your adversaries. Your company made the...
Security Testing Requirements for PCI-DSS

Security Testing Requirements for PCI-DSS

Overview Organizations handling credit card data must adhere to the Payment Card Industry Data Security Standard (PCI DSS). Understanding the specifications and what an organization must do specifically to comply with the standard can be challenging. This article will...
So You Want to Be a Hacker: 2023 Edition

So You Want to Be a Hacker: 2023 Edition

Video Version: Introduction The past two years, we’ve posted blogs on how to become an ethical hacker. Given that these blogs have been well received, we have brought back yet another edition. So, without further ado, let’s chat about how you can break...
Security Teams Need to Think Like Pentesters

Security Teams Need to Think Like Pentesters

We conduct a wide variety of assessments for a wide range of clients. We provide assessment services for universities, health care companies, law firms, telecommunication providers, and many more. Some of our clients have mature infrastructures, while others are still...