Posts

Showing posts with the label Black Hills Information Security

Black Hills InfoSec - The Art of the Badge: A Hard Truth About Physical Security

Image
He walked into the lobby with a fake badge clipped to his shirt. He had bought it online the week before. It was not perfect, and it did not need to be. From a few feet away, it looked close enough: a logo, a name, a photo, and a lanyard. The kind of thing most people glance at for half a second before their brain decides, “Looks fine.” The post The Art of the Badge: A Hard Truth About Physical Security appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/the-art-of-the-badge/

Black Hills InfoSec - Bad Habits: An ANTISOC Operation

Image
ANTISOC uses a mix of techniques from traditional penetration tests like red teams, cloud, web applications, externals, internals, and, of course, social engineering. We combine this mix of techniques with a wide-open scope, with the goal of going beyond what a typical pentest can discover. The post Bad Habits: An ANTISOC Operation appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/antisoc-operation/

Black Hills InfoSec - Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other

Image
There is a certain kind of conversation that doesn’t get written up in a post-mortem, doesn’t generate a ticket, and never makes it into an end-of-quarter report. It happens on the margins—at a conference, in a hallway, or, in this case, at 30,000 feet above sea level. It’s the conversation where two people who are solving the same problem from opposite ends of the table finally sit down next to each other. The post Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/same-problem-different-angles/

Black Hills InfoSec - How to Identify and Exploit New Vulnerabilities

Image
In the ever-evolving world of cybersecurity, staying ahead of the curve is not just a goal—it’s a necessity. As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they become public? Let’s dive into the fascinating world of vulnerability identification and see how the magic happens. The post How to Identify and Exploit New Vulnerabilities appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/how-to-identify-and-exploit-new-vulnerabilities/

Black Hills InfoSec - Swapper – A Pure Regex Match/Replace Burp Extension

Image
To get a valid session token to use with Burp Suite tools, I ended up writing a small Python extension (110 lines of code, but who’s counting?) that obtained a new session token for each request, allowing items like Intruder to work as intended. Cool, I was able to use it during the test, but I would like this to be repeatable. So, this blog is releasing Swapper, a regex pattern-based match/replace Burp Suite extension. The post Swapper – A Pure Regex Match/Replace Burp Extension appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/swapper/

Black Hills InfoSec - A Practical Guide to BloodHound Data Collection

Image
This blog will not dive too deeply into BloodHound itself; instead, we will focus on various methods to collect AD data to provide BloodHound as input. The post A Practical Guide to BloodHound Data Collection appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/bloodhound-data-collection/

Black Hills InfoSec - Signed, Trusted, and Abused: Proxy Execution via WebView2

Image
An offensive security perspective on Microsoft Edge WebView2 Runtime, including architectural weaknesses, existing vulnerabilities, and exploitation methods. The post Signed, Trusted, and Abused: Proxy Execution via WebView2 appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/proxy-execution-via-webview2/

Black Hills InfoSec - Getting Started In Pentesting – Advice From The BHIS Pentest Lead

Image
Advice about getting started in pentesting from the BHIS pentest lead, including a learning path and why you should go all in on offensive security skills. The post Getting Started In Pentesting – Advice From The BHIS Pentest Lead appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/getting-started-in-pentesting/

Black Hills InfoSec - Cloud Security: Tips and Resources for Securing the Cloud

Image
This overview of the basics of Cloud Security includes some tips and resources for getting started in defending the cloud. The post Cloud Security: Tips and Resources for Securing the Cloud appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/cloud-security-tips-and-resources-for-securing-the-cloud/

Black Hills InfoSec - Lessons From A Chatbot Incident

Image
Real-world account of how insecure databases and an AI chatbot left customer data exposed and how it could have been prevented. The post Lessons From A Chatbot Incident appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/lessons-from-a-chatbot-incident/

Black Hills InfoSec - How to Lead Effective Tabletops

Image
Learn how to transform boring, meeting-style security tabletop exercises into engaging real-world scenario simulations. The post How to Lead Effective Tabletops appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/how-to-lead-effective-cybersecurity-tabletops/

Black Hills InfoSec - Understanding GRC: How to Navigate Risks and Compliance Standards

Image
“GRC” isn’t all witchcraft and administrative nonsense — it’s the core that drives security initiatives, connects security spend to business outcomes, and powers a well-functioning security team. The post Understanding GRC: How to Navigate Risks and Compliance Standards appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/understanding-grc/

Black Hills InfoSec - The “P” in PAM is for Persistence: Linux Persistence Technique

Image
Learn about a pentesting tool using the Pluggable Authentication Module for privilege escalation, lateral movement, and persistence in Linux. The post The “P” in PAM is for Persistence: Linux Persistence Technique appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/the-p-in-pam-is-for-persistence-linux-persistence-technique/

Black Hills InfoSec - Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions  Copy

Image
This scenario simultaneously tests identity confirmation tooling (SSPR, MFA, Conditional Access), how users act under pressure, and the organization's ability to detect and follow-up on social engineering attacks. The post Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions  Copy appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/social-engineering-and-microsoft-sspr-2/

Black Hills InfoSec - OSINT: How to Find, Use, and Control Open-Source Intelligence

Image
OSINT stands for open-source intelligence, and it refers to all publicly available information on the open internet which has been obtained without any special requirements (paywalls, invitations, etc.). The post OSINT: How to Find, Use, and Control Open-Source Intelligence appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/osint-how-to-find-use-and-control-open-source-intelligence/

Black Hills InfoSec - What to Do with Your First Home Lab

Image
Having assembled fundamental lab components, you now get to play! However, the ocean of potential projects can be intimidating. Where does one even start? The post What to Do with Your First Home Lab appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/what-to-do-with-your-first-home-lab/

Black Hills InfoSec - Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions 

Image
This scenario simultaneously tests identity confirmation tooling (SSPR, MFA, Conditional Access), how users act under pressure, and the organization's ability to detect and follow-up on social engineering attacks. The post Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions  appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/social-engineering-and-microsoft-sspr/

Black Hills InfoSec - Six Tips for Managing Penetration Test Data Copy

Image
John Malone // Introduction Information is power. This sentiment also holds true when discussing the creation of a supporting archive. A supporting archive is something that we put together to […] The post Six Tips for Managing Penetration Test Data Copy appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/six-tips-for-managing-penetration-test-data-2/

Black Hills InfoSec - Common Cyber Threats

Image
In today’s interconnected digital world, information security has become a critical concern for individuals, businesses, and governments alike. Cyber threats, which encompass a wide range of malicious activities targeting information systems, pose significant risks to the confidentiality, integrity, and availability of data. The post Common Cyber Threats appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/common-cyber-threats/

Black Hills InfoSec - Finding the Right Penetration Testing Company

Image
This blog is for anyone who is interested in finding a good penetration testing company. The post Finding the Right Penetration Testing Company appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/finding-the-right-penetration-testing-company/