Posts

Showing posts with the label Inc.

Black Hills InfoSec - The Art of the Badge: A Hard Truth About Physical Security

Image
He walked into the lobby with a fake badge clipped to his shirt. He had bought it online the week before. It was not perfect, and it did not need to be. From a few feet away, it looked close enough: a logo, a name, a photo, and a lanyard. The kind of thing most people glance at for half a second before their brain decides, “Looks fine.” The post The Art of the Badge: A Hard Truth About Physical Security appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/the-art-of-the-badge/

Black Hills InfoSec - Bad Habits: An ANTISOC Operation

Image
ANTISOC uses a mix of techniques from traditional penetration tests like red teams, cloud, web applications, externals, internals, and, of course, social engineering. We combine this mix of techniques with a wide-open scope, with the goal of going beyond what a typical pentest can discover. The post Bad Habits: An ANTISOC Operation appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/antisoc-operation/

Black Hills InfoSec - Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other

Image
There is a certain kind of conversation that doesn’t get written up in a post-mortem, doesn’t generate a ticket, and never makes it into an end-of-quarter report. It happens on the margins—at a conference, in a hallway, or, in this case, at 30,000 feet above sea level. It’s the conversation where two people who are solving the same problem from opposite ends of the table finally sit down next to each other. The post Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/same-problem-different-angles/

Black Hills InfoSec - How to Identify and Exploit New Vulnerabilities

Image
In the ever-evolving world of cybersecurity, staying ahead of the curve is not just a goal—it’s a necessity. As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they become public? Let’s dive into the fascinating world of vulnerability identification and see how the magic happens. The post How to Identify and Exploit New Vulnerabilities appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/how-to-identify-and-exploit-new-vulnerabilities/

Black Hills InfoSec - Swapper – A Pure Regex Match/Replace Burp Extension

Image
To get a valid session token to use with Burp Suite tools, I ended up writing a small Python extension (110 lines of code, but who’s counting?) that obtained a new session token for each request, allowing items like Intruder to work as intended. Cool, I was able to use it during the test, but I would like this to be repeatable. So, this blog is releasing Swapper, a regex pattern-based match/replace Burp Suite extension. The post Swapper – A Pure Regex Match/Replace Burp Extension appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/swapper/

Black Hills InfoSec - Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 2: Copilot

Image
A common use case for LLMs is rapid software development. One of the first ways I used AI in my penetration testing methodology was for payload generation. The post Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 2: Copilot appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/penetration-testing-with-ai-part-2/

Black Hills InfoSec - Offline Memory Forensics With Volatility

Image
Volatility is a memory forensics tool that can pull SAM hashes from a vmem file. These hashes can be used to escalate from a local user or no user to a domain user leading to further compromise. The post Offline Memory Forensics With Volatility appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/offline-memory-forensics-with-volatility/

Black Hills InfoSec - Getting Started with AI Hacking: Part 1

Image
You may have read some of our previous blog posts on Artificial Intelligence (AI). We discussed things like using PyRIT to help automate attacks. We also covered the dangers of […] The post Getting Started with AI Hacking: Part 1 appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/getting-started-with-ai-hacking-part-1/

Black Hills InfoSec - Go-Spoof: A Tool for Cyber Deception

Image
Go-Spoof brings an old tool to a new language. The Golang rewrite [of Portspoof] provides similar efficiency and all the same features of the previous tool but with easier setup and useability. The post Go-Spoof: A Tool for Cyber Deception appeared first on Black Hills Information Security, Inc. . from Black Hills Information Security, Inc. https://www.blackhillsinfosec.com/go-spoof-a-tool-for-cyber-deception/