• Home
Subscribe

 bestestredteam

bestestredteam

All posts in Pentest

PlexTrac for Faster Report Writing!

PlexTrac for Faster Report Writing!

Ryan Villarreal / July 15, 2019

PlexTrac is the next generation platform for cybersecurity professionals. Workflow integrations and automated reporting make PlexTrac the last cybersecurity tool you will ever need.…

Read More

Tags: CloudCybersecurityJuiceShopOWASPPentestpenetration testReportingVulnerability Scanning
Koadic

Koadic

Ryan Smith / July 08, 2019

Koadic is a COM Command & Control tool used for Windows post-exploitation.…

Read More

Tags: C2Command and ControlJavaScriptLateral MovementPentestRed TeamingScans
Bypassing Anti-CSRF with Burp Suite Session Handling

Bypassing Anti-CSRF with Burp Suite Session Handling

Ryan Villarreal / May 25, 2019

Using Burp Suite to bypass anti-CSRF protections with the built-in Session Handling and Macro recorder.…

Read More

Tags: burpsuiteweb appWeb TokenBypassCybersecurityDVWAKali ToolsOWASPPentestCSRFAnti-CSRF
eLearnSecurity's Web Application Penetration Tester Review

eLearnSecurity's Web Application Penetration Tester Review

Ryan Smith / May 16, 2019

My thoughts on eLearnSecurity's Web App Penetration Testing course.…

Read More

Tags: web appRevieweLearnSecurityburpsuitepenetration testPentestTrainingeWPT
Bow Before the All Powerful CrackMapExec!!

Bow Before the All Powerful CrackMapExec!!

Ryan Villarreal / March 13, 2019

CrackMapExec more commonly referenced as CME is a post-exploitation tool that helps automate assessing the security of Active Directory networks.…

Read More

Tags: CrackMapExecCMEbyt3bl33d3rImpacketPost ExploitationSMBLateral MovementHackingKali ToolsInformation GatheringInternal NetworkPentestPowershell
Digging into DNS

Digging into DNS

Ryan Smith / March 07, 2019

Digging into DNS: how it works, how to get information from it, and how to utilize it during a penetration test.…

Read More

Tags: Internal NetworkPentestInformation Gathering
Visualizing Scans 2 - Dataiku

Visualizing Scans 2 - Dataiku

Ryan Smith / February 26, 2019

Using Dataiku DSS to generate graphs for reporting on pen tests.…

Read More

Tags: Dockerpenetration testPentestScansReporting
Hot on the Trail of Domain Admin: Bloodhound Intro

Hot on the Trail of Domain Admin: Bloodhound Intro

Ryan Villarreal / November 20, 2018

BloodHound is a tool to analyze and understand Active Directory Trust Relationships. Utilize Bloodhound to find shortest path to Domain Admin.…

Read More

Tags: BloodhoundPentestInternal NetworkActive DirectoryDomain Adminpenetration testKali LinuxGraph TheoryNeo4jCybersecurity
Page 1 of 2 Older Posts

About bestestredteam

Two cybersecurity professionals trying to get better at all things security.

Help support server costs!

Banner Ad

Latest Posts

  • BooFuzz: Spooky HTTP Fuzzing
    October 28, 2020
  • What the Fuzz? American Fuzzy Lop
    August 25, 2020
  • ROP Emporium - 0x03 (Callme)
    May 22, 2020

Authors

  • Ryan Villarreal
  • Ryan Smith
  • Bestest RedTeam

Tags

802.11802.11ax802.1xActive DirectoryAFLAnti-CSRFAssemblyAutomateAutomationAWSBetaBettercapBGPBinaryBinary NinjaBinaryNinjaBitcoinBloodhoundBlue TeamBooFuzzBunnyburpsuitebWAPPBypassbyt3bl33d3rC ProgrammingC2CACapture The FlagCertificatesCloudClusterCMECobalt StrikeCodingCommand and ControlCommand LineContainerCORSCrackMapExecCSRFCTFCybersecurityDebugDebuggerDeep DiveDetectionDevice DriversDockerDomain AdminDomain ControllerDVWAeLearnSecurityELFelkelkstackEnumerationeWPTExecutionPolicyExploitDevFreeRADIUSFuzzingGDBghostGNUGNU RadioGoogle CloudGoPhishGraph TheoryHackingHackRFHashcatHijackingHTTPHTTP/2ImpacketInformation GatheringInternal NetworkInternet of ThingsJavaScriptJuiceShopJWTKali LinuxKali ToolsKerberosKernelLateral MovementLinuxMerlinMicrosoftMicrosoft OfficeMiningNe0nd0gNeo4jNetworkingNULL SessionOffensive SecurityOffSecopen redirectOSCEOSWPOWASPpassword crackingpenetration testPentestPhishingPHPPineapplePixel TrackingPortainerPost ExploitationPowershellProtocolsPwntoolsPythonRadio FrequencyReconRed TeamingRed-BaronRedteamingReportingReviewRFRFCROPRopemporiumRTL-SDRS3SambaScansScapyScriptingService Principal NameServicesShodanSMBSMBClientSocial EngineeringSoftware Defined RadioSPNSulleySwarmsysadminTerraformTerraformFunTrainingUser modeUUIDVulnerability Scanningwardrivingweb appWeb ApplicationWeb TokenWebAppWifiWiFuWiglewindowswirelessWPAXSS
Twitter GitHub
Opinions expressed are solely our own and do not express the views or opinions of our employers.