PowerUpSQL• SysInternals• Donut• Chisel• Powermad• Burpsuite• Metasploit• Powershell-Suite• Rubeus• Fuzzdb• gobuster• Acunetix• Nessus• Cobalt Strike• PowerSploit• Impacket• PingCastle• Process Hacker• Hashcat• John the Ripper• Hydra• Aircrack-ng• Burpsuite• Metasploit•Lair – Reactive attack collaboration framework and web application built with meteor.•Pentest Collaboration Framework (PCF) – Open source, cross-platform, and portable toolkit for automating routine pentest processes with a team.•peda –… Continue reading Important Pentest Tools You must Check
Category: PenTesting
Web Application Penetration Testing – Training
Web Application Penetration Testing Phase 1 – History History of Internet – https://www.youtube.com/watch?v=9hIQjrMHTv4 Phase 2 – Web and Server Technology Basic concepts of web applications, how they work and the HTTP protocol – https://www.youtube.com/watch?v=RsQ1tFLwldY&t=7s HTML basics part 1 – https://www.youtube.com/watch?v=p6fRBGI_BY0 HTML basics part 2 – https://www.youtube.com/watch?v=Zs6lzuBVK2w Difference between static and dynamic website – https://www.youtube.com/watch?v=hlg6q6OFoxQ… Continue reading Web Application Penetration Testing – Training
OSINT and Ephemeral exposures
OSINT and Ephemeral Cloud Native exposures Tools Attack Surface Mapper – https://www.blackhat.com/us-19/arsenal/schedule/index.html#attack-surface-mapper-automate-and-simplify-the-osint-process-16713 Public Cloud Security – https://cloudsploit.com/github https://sysdig.com/ https://www.twistlock.com/ Upguard – https://www.itnews.com.au/news/data-from-nokias-interception-kit-for-russian-telcos-exposed-531186
Penetration Testing
Penetration Testing Advice on how to get the most from penetration testing https://www.ncsc.gov.uk/guidance/penetration-testing Penetration testing is a core tool for analysing the security of IT systems, but it’s not a magic bullet. This guidance will help you understand the proper commissioning and use of penetration tests. It will also help you to plan your routine… Continue reading Penetration Testing
OSCP Intro Letter
OSCP Intro Letter Dear Applicant,Thank you for your interest in Penetration Testing with Kali Linux. Please read this entire email carefully as it contains very important information. Course Prerequisites To be successful, you must have basic Linux skills – meaning you need to be able to navigate through the Linux filesystem, run simple commands,… Continue reading OSCP Intro Letter
Bug Bounties
Bug Bounties HackerOne Bugcrowd https://yeswehack.com/programs https://www.vulnmachines.com/ Vulnerability Lab Fire Bounty https://www.hackthebox.eu/ https://tryhackme.com/signup Bug Bounty Methodologies https://www.linkedin.com/posts/hackingarticles_bug-hunting-methodology-activity-6731105184459571201-1qJB Targets Web/API Mobile App/API Tools Selenium Testing http://webbreaker.io/ Automation https://www.jhaddix.com/post/the-secrets-of-automation-kings-in-bug-bounty Companies Microsoft – https://msrc-blog.microsoft.com/2019/08/05/azure-security-lab-a-new-space-for-azure-research-and-collaboration/ DOD – Apple Spotify
PenTesting / Scanning Cached/Load Balanced Targets
PenTesting / Scanning Cached/Load Balanced Targets As part of the PCI Certification process, external facing application that are in scope of the PCI environment require a PCI ASV scan. If these external facing applications are using load balancing and/or caching, please be aware of the following; (Examples of Load Balancers include; F5 LTM, AWS… Continue reading PenTesting / Scanning Cached/Load Balanced Targets
Mailware analysis
Mailware analysis Debuggers – gdb, WinDBG, OllyDBG Operating System Primer – https://www.slideshare.net/saumilshah/operating-systems-a-primer How functions work – https://www.slideshare.net/saumilshah/how-functions-work-7776073 Introduction to Debuggers – https://www.slideshare.net/saumilshah/introduction-to-debuggers Return Oriented Programming – https://www.slideshare.net/saumilshah/dive-into-rop-a-quick-introduction-to-return-oriented-programming https://www.winitor.com/ RawDisk – https://www.eldos.com/rawdisk/ Cuckoo – https://cuckoosandbox.org/
PenTesting Methodology
PenTesting Methodology F3EAD Model Find: essentially ‘picking up the scent’ of the opponent, with the classic “Who, What, When, Where, Why” questions being used within this phase to identify a candidate target Fix: verification of the target(s) identified within the previous phase, which typically involves multiple triangulation points. This phase effectively transforms the intelligence gained within the… Continue reading PenTesting Methodology
Kali Cheatsheet
Kali Cheatsheet The following is a list of improvements to the Kali distro to turbo charge your Pen Test tool kit.. Kali VM Username and Password: kali/kali Fresh Install Setup Kali on AWS – https://www.alienvault.com/blogs/security-essentials/configuring-kali-linux-on-amazon-aws-cloud-for-free Use Generation 1 in Hyper-V Install VM Guest Tools https://www.kali.org/docs/virtualization/install-vmware-guest-tools/ sudo su sudo apt-get install asciinema asciinema rec / exit lsb_release… Continue reading Kali Cheatsheet