
Living off the land and why it’s so hard to pick up good hackers
Posted on 2020-02-11by mattin Offensive security

Posted on 2020-02-11by mattin Offensive security


Posted on 2020-01-29by alexeiin Business Security
Nothing grinds my gears more than seeing companies flog cheap, crappy scans as penetration tests. It insults penetration testers like myself, but worse than that, it exploits the unsuspecting clients that genuinely want to improve their security.

Posted on 2020-01-21by mattin Business Security
Every year there’s a guy who comes out and tests my smoke alarm. The smoke alarm guy visually inspects the alarm, runs the internal test, and then uses a small device that, in my head, I ignorantly name “the smoke gun” to trigger the alarm. It’s a simple process that makes sure that the alarm still works.

Posted on 2020-01-15by mattin Social Engineering
When performing social engineering attacks, physical intrusion attacks, or red teams we have to be particularly careful. At all times we have to be aware that we’re not dealing with emotionless systems here, but with real people who are often just trying to do their jobs. What’s more, the people on the other end can feel mislead, manipulated, and betrayed. Perhaps the hardest challenge of designing an effective user awareness programme is getting the desired outcome of increased security when you’re dealing with real people. People who have emotions and potentially unpredictable behaviours.

Posted on 2020-01-07by alexeiin Tools of the trade
Let’s face it, security in an organisation can be expensive. You need corporate antivirus, firewalls, a SIEM, a Vulnerability Management solution and of course, that NextGen Threat Analytics and Attack Simulating Toaster (NGTAAST™). Congratulations, you’ve just racked up over a million dollars’ worth of gear. If you are a large corporation with large security budgets, that’s great! Chances are, these controls are legitimately useful for you and help with your day-to-day defence. However, if you are a smaller company, the reality is that you have very finite resources to stop the exact same adversaries that threaten large corporations.

Posted on 2019-12-23by mattin Business Security
In the beginnings of my career in security, I spent a long time on the technical side as a penetration tester. I was a hacker, tasked with breaking into their websites and networks, trying to test their security. Although sometimes that job can be like banging your head against a brick wall, when you get in there is definitely a rush that comes with it. When something you try works, there’s a feeling of exhilaration and victory.

Posted on 2019-12-04by Volkisin Volkis News
Welcome to our new Volkis website!