CVE-2018-8955: Bitdefender GravityZone Arbitrary Code Execution 16 Oct 2018 We recently identified a vulnerability in the digitally signed Bitdefender GravityZone installer. The vulnerability allows an attacker to... Read more
DerbyCon 2018 CTF Write Up 11 Oct 2018 We have just returned from the always amazing DerbyCon 2018 conference. We competed in the 48 hour Capture the Flag... Read more
CVE-2018-5240: Symantec Management Agent (Altiris) Privilege Escalation 12 Sep 2018 During a recent red team exercise, we discovered a vulnerability within the latest versions of the Symantec Management... Read more
CVE-2018-12897: Solarwinds Dameware Mini Remote Control Local SEH Buffer... 5 Sep 2018 Dameware Mini Remote Control (MRC) is a remote administration utility allowing remote access to end user devices for... Read more
Introducing Scrounger - iOS and Android mobile application penetration... 23 Aug 2018 Scrounger is a modular tool designed to perform the routine tasks required during a mobile application security assessment. ... Read more
Extending C2 Lateral Movement – Invoke-Pbind 16 Aug 2018 Invoke-Pbind is a mini post exploitation framework written in PowerShell, which builds C2 communications over SMB named pipes... Read more
Using PoolTags to Fingerprint Hosts 8 Aug 2018 Commonly, malware will fingerprint the host it executes on, in an attempt to discover more about its environment... Read more
CVE-2018-13442: SolarWinds NPM SQL Injection 2 Aug 2018 A SQL injection vulnerability has been discovered in SolarWinds’ Network Performance Monitor (NPM). This vulnerability has been designated... Read more
CVE-2017-16245 & CVE-2017-16246: Avecto Defendpoint Multiple Vulnerabilities 30 Jul 2018 This post focuses on the “application control” aspect of Avecto. Last year I discovered two vulnerabilities in the... Read more
Python Server for PoshC2 26 Jul 2018 We are delighted to announce the release of our PoshC2 Python Server, allowing cross-platform support. Read more
Best seller New Price from Limited availability Course type Course length Dates and location x *PLEASE NOTE: Course is available in more countries, languages and dates*