⤷ Title: Gone Phishing: Installing GoPhish and Creating a Campaign
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 13 Feb 2025 16:50:07 +0000
════════════════════════
⌗ Tags: #External/Internal #How_To #Informational #Nick Caswell #Phishing #Red Team #Red Team Tools #Social Engineering #GoPhish #Mail Security #Phishing Campaign
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 13 Feb 2025 16:50:07 +0000
════════════════════════
⌗ Tags: #External/Internal #How_To #Informational #Nick Caswell #Phishing #Red Team #Red Team Tools #Social Engineering #GoPhish #Mail Security #Phishing Campaign
Black Hills Information Security, Inc.
Gone Phishing: Installing GoPhish and Creating a Campaign - Black Hills Information Security, Inc.
GoPhish provides a nice platform for creating and running phishing campaigns. This blog will guide you through installing GoPhish and creating a campaign.
⤷ Title: Why Your Org Needs a Penetration Test Program
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Mon, 10 Mar 2025 15:30:05 +0000
════════════════════════
⌗ Tags: #Corey Ham #External/Internal #GRC #Red Team #Webcast Wrap_Up #Kelli Tarala #penetration testing #pentest
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Mon, 10 Mar 2025 15:30:05 +0000
════════════════════════
⌗ Tags: #Corey Ham #External/Internal #GRC #Red Team #Webcast Wrap_Up #Kelli Tarala #penetration testing #pentest
Black Hills Information Security, Inc.
Why Your Org Needs a Penetration Test Program - Black Hills Information Security, Inc.
This webcast originally aired on February 27, 2025. Join us for a very special free one-hour Black Hills Information Security webcast with Corey Ham & Kelli Tarala on why your […]
⤷ Title: Introducing Orbit
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 13 Mar 2025 14:00:22 +0000
════════════════════════
⌗ Tags: #External/Internal #Informational #Ralph May #Recon #Red Team #Red Team Tools #CPT #External Attack Surface #Nuclei #Orbit #Scanning
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 13 Mar 2025 14:00:22 +0000
════════════════════════
⌗ Tags: #External/Internal #Informational #Ralph May #Recon #Red Team #Red Team Tools #CPT #External Attack Surface #Nuclei #Orbit #Scanning
Black Hills Information Security
Introducing Orbit - Black Hills Information Security
When I set out to build Orbit, I knew that the interface had to be intuitive and accessible, but more importantly, the application had to solve a real problem. And here’s the challenge we faced...
⤷ Title: Go-Spoof: A Tool for Cyber Deception
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 27 Mar 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Ben Bowman #Blue Team #Blue Team Tools #External/Internal #Web App #Cyber Deception #Deceptive Tooling #Go_Spoof
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 27 Mar 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Ben Bowman #Blue Team #Blue Team Tools #External/Internal #Web App #Cyber Deception #Deceptive Tooling #Go_Spoof
Black Hills Information Security, Inc.
Go-Spoof: A Tool for Cyber Deception - Black Hills Information Security, Inc.
Go-Spoof brings an old tool to a new language. The Golang rewrite [of Portspoof] provides similar efficiency and all the same features of the previous tool but with easier setup and useability.
❤1
⤷ Title: Getting Started with NetExec: Streamlining Network Discovery and Access
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Dale Hobbs #External/Internal #How_To #Informational #Password Spray #Red Team #Red Team Tools #Active Directory Enumeration #Authentication Testing #Blue Team Defense #CrackMapExec Alternative #Credential Spraying #Lateral Movement #Netexec #Network Discovery #NTLM Authentication #Pass_the_Hash (PTH) #Pass_the_Ticket (PTT) #SMB Enumeration
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Dale Hobbs #External/Internal #How_To #Informational #Password Spray #Red Team #Red Team Tools #Active Directory Enumeration #Authentication Testing #Blue Team Defense #CrackMapExec Alternative #Credential Spraying #Lateral Movement #Netexec #Network Discovery #NTLM Authentication #Pass_the_Hash (PTH) #Pass_the_Ticket (PTT) #SMB Enumeration
Black Hills Information Security, Inc.
Getting Started with NetExec: Streamlining Network Discovery and Access - Black Hills Information Security, Inc.
One tool that I can't live without when performing a penetration test in an Active Directory environment is called NetExec. Being able to efficiently authenticate against multiple systems in the network is crucial, and NetExec is an incredibly powerful tool…
⤷ Title: Abusing Active Directory Certificate Services (Part 2)
════════════════════════
𐀪 Author: Kassie Kimball
════════════════════════
ⴵ Time: Thu, 12 Oct 2023 15:44:18 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
════════════════════════
𐀪 Author: Kassie Kimball
════════════════════════
ⴵ Time: Thu, 12 Oct 2023 15:44:18 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 2) - Black Hills Information Security, Inc.
Misconfigurations in Active Directory Certificate Services (ADCS) can introduce critical vulnerabilities into an Enterprise Active Directory environment, such as paths of escalation from low privileged accounts to domain administrator.
⤷ Title: Abusing Active Directory Certificate Services (Part 1)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 05 Oct 2023 16:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 05 Oct 2023 16:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 1) - Black Hills Information Security, Inc.
Active Directory Certificate Services (ADCS) is used for public key infrastructure in an Active Directory environment. ADCS is widely used in enterprise Active Directory environments for managing certificates for systems, users, applications, and more.
⤷ Title: Detecting ADCS Privilege Escalation
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 13:31:22 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #Blue Team Tools #External/Internal #How_To #Informational #Active Directory #ADCS
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 13:31:22 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #Blue Team Tools #External/Internal #How_To #Informational #Active Directory #ADCS
Black Hills Information Security, Inc.
Detecting ADCS Privilege Escalation - Black Hills Information Security, Inc.
Active Directory Certificate Services (ADCS) is used to manage certificates for systems, users, applications, and more in an enterprise environment. Misconfigurations in ADCS can introduce critical vulnerabilities into an enterprise Active Directory environment.
⤷ Title: GoSpoof – Turning Attacks into Intel
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team #Blue Team Tools #External/Internal #Informational #Intern #Web App #Cyber Deception #Deceptive Tooling #GoSpoof
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team #Blue Team Tools #External/Internal #Informational #Intern #Web App #Cyber Deception #Deceptive Tooling #GoSpoof
Black Hills Information Security, Inc.
GoSpoof – Turning Attacks into Intel - Black Hills Information Security, Inc.
Imagine this: You’re an attacker ready to get their hands on valuable data that you can sell to afford going on a sweet vacation. You do your research, your recon, everything, ensuring that there’s no way this can go wrong. The day of the attack, you brew…
⤷ Title: Why You Got Hacked – 2025 Super Edition
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 17:50:39 +0000
════════════════════════
⌗ Tags: #C2 #External/Internal #Finding #Informational #Jordan Drysdale #Web App #analysis #Report Findings
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 17:50:39 +0000
════════════════════════
⌗ Tags: #C2 #External/Internal #Finding #Informational #Jordan Drysdale #Web App #analysis #Report Findings
Black Hills Information Security, Inc.
Why You Got Hacked - 2025 Super Edition - Black Hills Information Security, Inc.
This article was written to provide readers with an overview of a selection of our pentest results from the last 15 months. This data was gathered toward the end of September 2025. Shockingly, the data does not differ much from our prior analyses conducted…