PentestMag Library

Articles

Practical security research, tutorials and analysis from PentestMag.

105 articles found · Showing 97–105

Membership

Building Intuition into Monitoring for OT/ICS Security

by Danielle Jablanski The current state of operational technology and industrial control systems cybersecurity is turning a corner. It has progressed from decades of admiring hypothetical scenarios, to realizing the significance of very real threats and vulnerabilities that exist across critical infrastructure all over the globe. Recent revelations from Indu

Bruno Zwierz

Membership

WiFi Pentesting with Airodump-ng

by Juan Morales Free Internet! Well, not really……The purpose of this article is to demonstrate different forms of Wi-Fi network attacks (with permission of course!) using none other than the Aircrack Suite. We will cover a slew of different attacks and capabilities of the Aircrack Suite. For the purposes of demonstration, I will be using an Alfa AWUS036ACH W

Bruno Zwierz

Membership

ETW vs Sysmon Against C2 Servers

by Damon Mohammedbeger In this article, I want to talk about my research about ETW and Sysmon and how I can use these events for detection against C2 servers like Cobalt Strike, PoshC2, Sliver and, as always, Metasploit. So, as a pentester and security researcher, I tried to work on the Blue-Team side (defensive approach) with my own offensive experience, et

Bruno Zwierz

Membership

Understanding Microsoft Office Trusted Locations Workflow and How It Can Be Exploited

by Adam Maraziti Ronald Reagan once said, “Trust, but verify”. That holds true even for Cybersecurity. We are long past the days of relying on software companies to implement default settings with a security first focus. It is on organizations to review administrative guides, default settings and various best practices to securely configure new and existing

Bruno Zwierz

Membership

Introduction to Internal Penetration Tests

by Dimitris Pallis Connectivity Basics Before jumping on to exploitation tools and techniques, the most important step is to connect to the client's network. This can be done in two ways, either remotely or on-site by going to client's offices. On-site visits would require your own dedicated space and access to the client's network through wired ethernet or

Dimitri

Membership

Play to Earn or Insecure to Play?

by Marlon Fabiano of CySource The success of the game Axie Infinity sparked a massive wave of Play to Earn or "play to win" that has reached most of us. Until now, the term NFT, or non-fungible token, was only related to images of famous artists like Beeple, or to the sought-out collection of cryptopunks. The privilege of making money playing video games was

Marlon Fabiano

Membership

Cybersecurity Compliance on Cloud

by Almu Gómez Sánchez-Paulete When we talk about cybersecurity, the image of a person with a hood in front of black screens and white lines (or green, which are cooler) comes to mind, and we don’t always take into account that cybersecurity encompasses much more than knowing how to attack a system (Red Team). It is also important to design a secure architect

Almu

Membership

Wide-area Packet Capture with PacketStreamer

by Owen Garrett, Deepfence PacketStreamer is an open source project from Deepfence. It performs distributed packet capture (tcpdump-like) and aggregates the pcap data in a single pcap file. PacketStreamer supports a wide range of environments, including Kubernetes nodes, Docker hosts, Fargate instances and, of course, virtual and bare-metal servers. Network

Owen Garrett

Membership

Android Application Pentest

by Gabrielle Botbol About the author Gabrielle Botbol is a pentester, cyber security blogger, and podcaster CS by GB - Cybersecurity By Gabrielle B She created a self study program to become a pentester. Gabrielle Botbol focuses her efforts on democratizing information security for all. She is a board member of Ecole Cyber in Montreal. She was honored for he

Gabrielle B.