πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 17 Jul 2023 13:35:46 GMT
βββββββββββββββ
βοΈTitle: Enabled Sign Up on Jenkins leading to Groovy Script Remote Code Execution Vulnerability
βββββββββββββββ
πLink: https://medium.com/p/6d345f5dba0d
βββββββββββββββ
Tags: #groovy_script #external_pentesting #jenkins #rce
βββββββββββββββ
πDate: Mon, 17 Jul 2023 13:35:46 GMT
βββββββββββββββ
βοΈTitle: Enabled Sign Up on Jenkins leading to Groovy Script Remote Code Execution Vulnerability
βββββββββββββββ
πLink: https://medium.com/p/6d345f5dba0d
βββββββββββββββ
Tags: #groovy_script #external_pentesting #jenkins #rce
Medium
Enabled Sign Up on Jenkins leading to Groovy Script Remote Code Execution Vulnerability
Summary : Found a Jenkins instance with Signup enabled , bypass the restrictions by signing up with corporate email account as there wasβ¦
β€· Title: Gone Phishing: Installing GoPhish and Creating a Campaign
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 13 Feb 2025 16:50:07 +0000
ββββββββββββββββββββββββ
β Tags: #External/Internal #How_To #Informational #Nick Caswell #Phishing #Red Team #Red Team Tools #Social Engineering #GoPhish #Mail Security #Phishing Campaign
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 13 Feb 2025 16:50:07 +0000
ββββββββββββββββββββββββ
β Tags: #External/Internal #How_To #Informational #Nick Caswell #Phishing #Red Team #Red Team Tools #Social Engineering #GoPhish #Mail Security #Phishing Campaign
Black Hills Information Security, Inc.
Gone Phishing: Installing GoPhish and Creating a Campaign - Black Hills Information Security, Inc.
GoPhish provides a nice platform for creating and running phishing campaigns. This blog will guide you through installing GoPhish and creating a campaign.
β€· Title: Why Your Org Needs a Penetration Test Program
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 10 Mar 2025 15:30:05 +0000
ββββββββββββββββββββββββ
β Tags: #Corey Ham #External/Internal #GRC #Red Team #Webcast Wrap_Up #Kelli Tarala #penetration testing #pentest
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 10 Mar 2025 15:30:05 +0000
ββββββββββββββββββββββββ
β Tags: #Corey Ham #External/Internal #GRC #Red Team #Webcast Wrap_Up #Kelli Tarala #penetration testing #pentest
Black Hills Information Security, Inc.
Why Your Org Needs a Penetration Test Program - Black Hills Information Security, Inc.
This webcast originally aired on February 27, 2025. Join us for a very special free one-hour Black Hills Information Security webcast with Corey Ham & Kelli Tarala on why your [β¦]
β€· Title: Introducing Orbit
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 13 Mar 2025 14:00:22 +0000
ββββββββββββββββββββββββ
β Tags: #External/Internal #Informational #Ralph May #Recon #Red Team #Red Team Tools #CPT #External Attack Surface #Nuclei #Orbit #Scanning
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 13 Mar 2025 14:00:22 +0000
ββββββββββββββββββββββββ
β Tags: #External/Internal #Informational #Ralph May #Recon #Red Team #Red Team Tools #CPT #External Attack Surface #Nuclei #Orbit #Scanning
Black Hills Information Security
Introducing Orbit - Black Hills Information Security
When I set out to build Orbit, I knew that the interface had to be intuitive and accessible, but more importantly, the application had to solve a real problem. And hereβs the challenge we faced...
β€· Title: Configuring Azure AD as a Key Manager in WSO2 API Manager
ββββββββββββββββββββββββ
πͺ Author: Dilan Lasantha
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 17 Mar 2025 15:05:00 GMT
ββββββββββββββββββββββββ
β Tags: #external_key_manager #api_security #azure_active_directory #wso2 #wso2_api_manager
ββββββββββββββββββββββββ
πͺ Author: Dilan Lasantha
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 17 Mar 2025 15:05:00 GMT
ββββββββββββββββββββββββ
β Tags: #external_key_manager #api_security #azure_active_directory #wso2 #wso2_api_manager
Medium
Configuring Azure AD as a Key Manager in WSO2 API Manager
Integrating Azure Active Directory (Azure AD) as a Key Manager in WSO2 API Manager (WSO2 APIM) allows organizations to utilize Microsoftβsβ¦
β€· Title: The Hidden Cyber Threats Lurking in Your Digital FootprintβββHow External Attack Surfaceβ¦
ββββββββββββββββββββββββ
πͺ Author: Cytrusst
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 27 Mar 2025 09:37:52 GMT
ββββββββββββββββββββββββ
β Tags: #external_attack_surface #attack_surface_management #cyber_security_solutions #asm #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Cytrusst
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 27 Mar 2025 09:37:52 GMT
ββββββββββββββββββββββββ
β Tags: #external_attack_surface #attack_surface_management #cyber_security_solutions #asm #cybersecurity
Medium
The Hidden Cyber Threats Lurking in Your Digital Footprint β How External Attack Surface Management Can Save Your Business
A cybersecurity insiderβs guide to protecting your digital ecosystem with Cytrusst the Breach You Never Saw Coming
β€· Title: Go-Spoof: A Tool for Cyber Deception
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 27 Mar 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Ben Bowman #Blue Team #Blue Team Tools #External/Internal #Web App #Cyber Deception #Deceptive Tooling #Go_Spoof
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 27 Mar 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Ben Bowman #Blue Team #Blue Team Tools #External/Internal #Web App #Cyber Deception #Deceptive Tooling #Go_Spoof
Black Hills Information Security, Inc.
Go-Spoof: A Tool for Cyber Deception - Black Hills Information Security, Inc.
Go-Spoof brings an old tool to a new language. The Golang rewrite [of Portspoof] provides similar efficiency and all the same features of the previous tool but with easier setup and useability.
β€1
β€· Title: What is External Penetration Testing?
ββββββββββββββββββββββββ
πͺ Author: Craw Cyber Security
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 24 Apr 2025 10:35:31 GMT
ββββββββββββββββββββββββ
β Tags: #what_external_penetration #penetration_testing #penetration_testing_firm #external_penetration_test #penetration_testing_guide
ββββββββββββββββββββββββ
πͺ Author: Craw Cyber Security
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 24 Apr 2025 10:35:31 GMT
ββββββββββββββββββββββββ
β Tags: #what_external_penetration #penetration_testing #penetration_testing_firm #external_penetration_test #penetration_testing_guide
Medium
What is External Penetration Testing?
In todayβs interconnected world, your organizationβs digital presence extends far beyond the walls of your physical office. Websites, cloudβ¦
β€· Title: Apple Overhauls EU App Store Policy: New Fees & Open External Purchases After β¬500M Fine
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 27 Jun 2025 08:06:23 +0000
ββββββββββββββββββββββββ
β Tags: #Technology #App Store #Apple #Core Technology Fee #CTC #ctf #Developer Policy #Digital Markets Act #DMA #EU #European Union #External Purchases #Fees
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 27 Jun 2025 08:06:23 +0000
ββββββββββββββββββββββββ
β Tags: #Technology #App Store #Apple #Core Technology Fee #CTC #ctf #Developer Policy #Digital Markets Act #DMA #EU #European Union #External Purchases #Fees
Daily CyberSecurity
Apple Overhauls EU App Store Policy: New Fees & Open External Purchases After β¬500M Fine
Apple revised EU App Store policies, allowing external purchases and new fees (initial acquisition, service, CTC) after a β¬500M fine. Developers can now direct users to outside payment channels.
β€· Title: Getting Started with NetExec: Streamlining Network Discovery and Access
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 09 Jul 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Dale Hobbs #External/Internal #How_To #Informational #Password Spray #Red Team #Red Team Tools #Active Directory Enumeration #Authentication Testing #Blue Team Defense #CrackMapExec Alternative #Credential Spraying #Lateral Movement #Netexec #Network Discovery #NTLM Authentication #Pass_the_Hash (PTH) #Pass_the_Ticket (PTT) #SMB Enumeration
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 09 Jul 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Dale Hobbs #External/Internal #How_To #Informational #Password Spray #Red Team #Red Team Tools #Active Directory Enumeration #Authentication Testing #Blue Team Defense #CrackMapExec Alternative #Credential Spraying #Lateral Movement #Netexec #Network Discovery #NTLM Authentication #Pass_the_Hash (PTH) #Pass_the_Ticket (PTT) #SMB Enumeration
Black Hills Information Security, Inc.
Getting Started with NetExec: Streamlining Network Discovery and Access - Black Hills Information Security, Inc.
One tool that I can't live without when performing a penetration test in an Active Directory environment is called NetExec. Being able to efficiently authenticate against multiple systems in the network is crucial, and NetExec is an incredibly powerful toolβ¦
β€· Title: Abusing Active Directory Certificate Services (Part 2)
ββββββββββββββββββββββββ
πͺ Author: Kassie Kimball
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 12 Oct 2023 15:44:18 +0000
ββββββββββββββββββββββββ
β Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
ββββββββββββββββββββββββ
πͺ Author: Kassie Kimball
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 12 Oct 2023 15:44:18 +0000
ββββββββββββββββββββββββ
β Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 2) - Black Hills Information Security, Inc.
Misconfigurations in Active Directory Certificate Services (ADCS) can introduce critical vulnerabilities into an Enterprise Active Directory environment, such as paths of escalation from low privileged accounts to domain administrator.
β€· Title: Abusing Active Directory Certificate Services (Part 1)
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Oct 2023 16:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Oct 2023 16:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 1) - Black Hills Information Security, Inc.
Active Directory Certificate Services (ADCS) is used for public key infrastructure in an Active Directory environment. ADCS is widely used in enterprise Active Directory environments for managing certificates for systems, users, applications, and more.
β€· Title: Detecting ADCS Privilege Escalation
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 23 Jul 2025 13:31:22 +0000
ββββββββββββββββββββββββ
β Tags: #Alyssa Snow #Blue Team #Blue Team Tools #External/Internal #How_To #Informational #Active Directory #ADCS
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 23 Jul 2025 13:31:22 +0000
ββββββββββββββββββββββββ
β Tags: #Alyssa Snow #Blue Team #Blue Team Tools #External/Internal #How_To #Informational #Active Directory #ADCS
Black Hills Information Security, Inc.
Detecting ADCS Privilege Escalation - Black Hills Information Security, Inc.
Active Directory Certificate Services (ADCS) is used to manage certificates for systems, users, applications, and more in an enterprise environment. Misconfigurations in ADCS can introduce critical vulnerabilities into an enterprise Active Directory environment.
β€· Title: Apple Leverages Supreme Court Ruling to Fight App Store External Payment Links Mandate
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 25 Jul 2025 07:00:42 +0000
ββββββββββββββββββββββββ
β Tags: #Technology #Antitrust #App Store #Apple #Developers #Epic Games #External Payments #ios #Lawsuit #monopoly #Supreme Court
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 25 Jul 2025 07:00:42 +0000
ββββββββββββββββββββββββ
β Tags: #Technology #Antitrust #App Store #Apple #Developers #Epic Games #External Payments #ios #Lawsuit #monopoly #Supreme Court
Daily CyberSecurity
Apple Leverages Supreme Court Ruling to Fight App Store External Payment Links Mandate
Apple is challenging a court order to allow external App Store payment links, citing a recent Supreme Court ruling to argue judicial overreach in its ongoing battle with Epic Games.
β€· Title: GoSpoof β Turning Attacks into Intel
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 29 Oct 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Blue Team #Blue Team Tools #External/Internal #Informational #Intern #Web App #Cyber Deception #Deceptive Tooling #GoSpoof
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 29 Oct 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #Blue Team #Blue Team Tools #External/Internal #Informational #Intern #Web App #Cyber Deception #Deceptive Tooling #GoSpoof
Black Hills Information Security, Inc.
GoSpoof β Turning Attacks into Intel - Black Hills Information Security, Inc.
Imagine this: Youβre an attacker ready to get their hands on valuable data that you can sell to afford going on a sweet vacation. You do your research, your recon, everything, ensuring that thereβs no way this can go wrong. The day of the attack, you brewβ¦
β€· Title: Why You Got Hacked β 2025 Super Edition
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 19 Nov 2025 17:50:39 +0000
ββββββββββββββββββββββββ
β Tags: #C2 #External/Internal #Finding #Informational #Jordan Drysdale #Web App #analysis #Report Findings
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 19 Nov 2025 17:50:39 +0000
ββββββββββββββββββββββββ
β Tags: #C2 #External/Internal #Finding #Informational #Jordan Drysdale #Web App #analysis #Report Findings
Black Hills Information Security, Inc.
Why You Got Hacked - 2025 Super Edition - Black Hills Information Security, Inc.
This article was written to provide readers with an overview of a selection of our pentest results from the last 15 months. This data was gathered toward the end of September 2025. Shockingly, the data does not differ much from our prior analyses conductedβ¦
β€· Title: The Android Toll: Google to Charge $2.85 Per Install for External App Links
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 23 Dec 2025 02:41:08 +0000
ββββββββββββββββββββββββ
β Tags: #Technology #android #Antitrust #App Store Fees #Digital Markets Act #Epic Games #External Billing #Google Play Store #Judge James Donato #Mobile Gaming #Sideloading
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 23 Dec 2025 02:41:08 +0000
ββββββββββββββββββββββββ
β Tags: #Technology #android #Antitrust #App Store Fees #Digital Markets Act #Epic Games #External Billing #Google Play Store #Judge James Donato #Mobile Gaming #Sideloading
Daily CyberSecurity
The Android Toll: Google to Charge $2.85 Per Install for External App Links
In the legal dispute between Epic and Google, U.S. judges have signaled a clear inclination to require Google to alter its existing Google Play Store bundled billing model. In essence, Google woulβ¦
β€· Title: PNPT External Penetration Testing Cheat Sheet
ββββββββββββββββββββββββ
πͺ Author: jaejun835
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Mar 2026 03:21:58 GMT
ββββββββββββββββββββββββ
β Tags: #external_penetration #pnpt #cheatsheet #cybersecurity #hacking
ββββββββββββββββββββββββ
πͺ Author: jaejun835
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Mar 2026 03:21:58 GMT
ββββββββββββββββββββββββ
β Tags: #external_penetration #pnpt #cheatsheet #cybersecurity #hacking
Medium
PNPT External Penetration Testing Cheat Sheet
This is a cheat sheet for external penetration testing techniques used in TCM Security's PNPT (Practical Network Penetration Tester)β¦
β€· Title: Windows Privilege Escalation Skills Assessment β Part I
ββββββββββββββββββββββββ
πͺ Author: Psychopath-Traveler
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 12 Apr 2026 09:34:38 GMT
ββββββββββββββββββββββββ
β Tags: #juicy_potato #windows_privilege_esc #windows_server_2016 #external_internal #ethical_hacking
ββββββββββββββββββββββββ
πͺ Author: Psychopath-Traveler
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 12 Apr 2026 09:34:38 GMT
ββββββββββββββββββββββββ
β Tags: #juicy_potato #windows_privilege_esc #windows_server_2016 #external_internal #ethical_hacking
Medium
Windows Privilege Escalation Skills Assessment β Part I
During a penetration test against the INLANEFREIGHT organization, you encounter a non-domain joined Windows server host that suffers fromβ¦
β€· Title: Beyond Email: Attackers Hijack Microsoft Teams External Access to Launch Deep Network Compromise
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 21 May 2026 06:18:18 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #CVE_2023_36036 #Cyber Security #Dumpit #External Access Configuration #Incident Response #infosec #Kerberoasting #LSASS Memory Dump #Microsoft Teams phishing #Rapid7 Labs #social engineering
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 21 May 2026 06:18:18 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #CVE_2023_36036 #Cyber Security #Dumpit #External Access Configuration #Incident Response #infosec #Kerberoasting #LSASS Memory Dump #Microsoft Teams phishing #Rapid7 Labs #social engineering
Daily CyberSecurity
Beyond Email: Attackers Hijack Microsoft Teams External Access to Launch Deep Network Compromise
Rapid7 Labs exposes how attackers are abusing Microsoft Teams external access and Dumpit memory scrapers to breach corporate networks. Protect your team!