• Home
Subscribe

 bestestredteam

bestestredteam

All posts in penetration test

Container Escaper

Container Escaper

Ryan Smith / September 17, 2019

A look at a few possible misconfigurations in Docker which allow you to execute commands on the host.…

Read More

Tags: Dockerpenetration testPost Exploitation
PlexTrac for Faster Report Writing!

PlexTrac for Faster Report Writing!

Ryan Villarreal / July 15, 2019

PlexTrac is the next generation platform for cybersecurity professionals. Workflow integrations and automated reporting make PlexTrac the last cybersecurity tool you will ever need.…

Read More

Tags: CloudCybersecurityJuiceShopOWASPPentestpenetration testReportingVulnerability Scanning
eLearnSecurity's Web Application Penetration Tester Review

eLearnSecurity's Web Application Penetration Tester Review

Ryan Smith / May 16, 2019

My thoughts on eLearnSecurity's Web App Penetration Testing course.…

Read More

Tags: web appRevieweLearnSecurityburpsuitepenetration testPentestTrainingeWPT
Cobalt Strike!

Cobalt Strike!

Ryan Smith / May 09, 2019

A beginner's guide to the tool used for adversary simulations and Red Team operations: Cobalt Strike.…

Read More

Tags: Red Teamingpenetration testC2Command and ControlKali ToolsPost ExploitationReportingCobalt Strike
7 Tools For Malicious Document Creation

7 Tools For Malicious Document Creation

Ryan Smith / March 19, 2019

Quick coverage of seven different tools that can be used to generate malicious macro payloads. They can then be embedded into Office documents and used for phishing.…

Read More

Tags: penetration testSocial EngineeringPhishing
Using SMBClient to Enumerate Shares

Using SMBClient to Enumerate Shares

Ryan Villarreal / March 14, 2019

This blog post seeks to demonstrate the vulnerabilities of SMB NULL sessions, and how to test them with smbclient.…

Read More

Tags: SMBSambapenetration testInternal NetworkEnumerationSMBClientNULL SessionKali LinuxLinuxwindows
Fork Sparta, Join The Legion

Fork Sparta, Join The Legion

Ryan Smith / March 11, 2019

A look at the tool "Legion" which is a fork of "Sparta" with some improved features.…

Read More

Tags: ReconInformation Gatheringpenetration testAutomation
Visualizing Scans 2 - Dataiku

Visualizing Scans 2 - Dataiku

Ryan Smith / February 26, 2019

Using Dataiku DSS to generate graphs for reporting on pen tests.…

Read More

Tags: Dockerpenetration testPentestScansReporting
Page 1 of 3 Older Posts

About bestestredteam

Two cybersecurity professionals trying to get better at all things security.

Help support server costs!

Banner Ad

Latest Posts

  • BooFuzz: Spooky HTTP Fuzzing
    October 28, 2020
  • What the Fuzz? American Fuzzy Lop
    August 25, 2020
  • ROP Emporium - 0x03 (Callme)
    May 22, 2020

Authors

  • Ryan Villarreal
  • Ryan Smith
  • Bestest RedTeam

Tags

802.11802.11ax802.1xActive DirectoryAFLAnti-CSRFAssemblyAutomateAutomationAWSBetaBettercapBGPBinaryBinary NinjaBinaryNinjaBitcoinBloodhoundBlue TeamBooFuzzBunnyburpsuitebWAPPBypassbyt3bl33d3rC ProgrammingC2CACapture The FlagCertificatesCloudClusterCMECobalt StrikeCodingCommand and ControlCommand LineContainerCORSCrackMapExecCSRFCTFCybersecurityDebugDebuggerDeep DiveDetectionDevice DriversDockerDomain AdminDomain ControllerDVWAeLearnSecurityELFelkelkstackEnumerationeWPTExecutionPolicyExploitDevFreeRADIUSFuzzingGDBghostGNUGNU RadioGoogle CloudGoPhishGraph TheoryHackingHackRFHashcatHijackingHTTPHTTP/2ImpacketInformation GatheringInternal NetworkInternet of ThingsJavaScriptJuiceShopJWTKali LinuxKali ToolsKerberosKernelLateral MovementLinuxMerlinMicrosoftMicrosoft OfficeMiningNe0nd0gNeo4jNetworkingNULL SessionOffensive SecurityOffSecopen redirectOSCEOSWPOWASPpassword crackingpenetration testPentestPhishingPHPPineapplePixel TrackingPortainerPost ExploitationPowershellProtocolsPwntoolsPythonRadio FrequencyReconRed TeamingRed-BaronRedteamingReportingReviewRFRFCROPRopemporiumRTL-SDRS3SambaScansScapyScriptingService Principal NameServicesShodanSMBSMBClientSocial EngineeringSoftware Defined RadioSPNSulleySwarmsysadminTerraformTerraformFunTrainingUser modeUUIDVulnerability Scanningwardrivingweb appWeb ApplicationWeb TokenWebAppWifiWiFuWiglewindowswirelessWPAXSS
Twitter GitHub
Opinions expressed are solely our own and do not express the views or opinions of our employers.