Black Hills Information Security, Inc.
RSS
  • All Services
    • Penetration Testing
    • Continuous Penetration Testing
    • Web Application Testing
    • Active SOC
    • AI Security Assessments
    • Incident Response
    • Blue Team Services
    • Blockchain Security
    • High-Profile Risk Assessments
    • Complete Service Guide
  • Contact Us
    • Contact Us
    • Email Sign-Up
  • About Us
    • Security Consultants
    • Admin Team
    • Active SOC Team
    • Antisyphon Training
    • BHIS Tribe of Companies
  • Free Resources
    • Blogs
    • Free Cybersecurity Tools
    • Free Cybersecurity Webcasts
    • Podcasts
    • RITA
  • Training
    • BHIS & Antisyphon Training
    • WWHF Conference
  • Community
    • Discord
    • LinkedIn
    • YouTube
    • Bluesky
    • Twitter/X
    • Upcoming Events
  • Fun Stuff
    • Backdoors & Breaches
    • Merch, Zines & More
    • PROMPT# Zine
    • REKCAH
    • Books
badge_header

Guest Author, Informational, InfoSec 101, Physical, Social Engineering Badge Security, Infosec for Beginners, Physical Security, Robert Boettger

The Art of the Badge: A Hard Truth About Physical Security

He walked into the lobby with a fake badge clipped to his shirt. He had bought it online the week before. It was not perfect, and it did not need to be. From a few feet away, it looked close enough: a logo, a name, a photo, and a lanyard. The kind of thing most people glance at for half a second before their brain decides, “Looks fine.”

Read the entire post here
cicd_header (1)

Blue Team Tools, External/Internal, InfoSec 301, Recon, Red Team, Red Team Tools attacking, cicd, Defending, devops, GitLab, gogatoz, Phil Miller

Auditing GitLab: The CI/CD Kill Chain

Welcome to GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain along with everything those one-off scripts did and then some.

Read the entire post here
antisocop_header

Corey Ham, Fun & Games, Informational ANTISOC, Continuous Penetration Testing, PROMPT#

Bad Habits: An ANTISOC Operation

ANTISOC uses a mix of techniques from traditional penetration tests like red teams, cloud, web applications, externals, internals, and, of course, social engineering. We combine this mix of techniques with a wide-open scope, with the goal of going beyond what a typical pentest can discover.

Read the entire post here
redblue_header

Active SOC, Blue Team, Informational, Red Team BHISinterviews, Melissa Lauro, purple teaming, Security Operations, SOC

Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other

There is a certain kind of conversation that doesn’t get written up in a post-mortem, doesn’t generate a ticket, and never makes it into an end-of-quarter report. It happens on the margins—at a conference, in a hallway, or, in this case, at 30,000 feet above sea level. It’s the conversation where two people who are solving the same problem from opposite ends of the table finally sit down next to each other.

Read the entire post here
unmasking_header (1)

Informational, InfoSec 101, Matthew Eidelberg, Red Team, Red Team Tools ANTISOC, Exploits, Infosec for Beginners, PROMPT#, Zine

How to Identify and Exploit New Vulnerabilities

In the ever-evolving world of cybersecurity, staying ahead of the curve is not just a goal—it’s a necessity. As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they become public? Let’s dive into the fascinating world of vulnerability identification and see how the magic happens.

Read the entire post here
swapper_header

Dave Blandford, How-To, Informational, Mobile, Web App Burp extensions, Desktop App Testing, Mobile App Testing, Regex, Web App Testing

Swapper – A Pure Regex Match/Replace Burp Extension

To get a valid session token to use with Burp Suite tools, I ended up writing a small Python extension (110 lines of code, but who’s counting?) that obtained a new session token for each request, allowing items like Intruder to work as intended. Cool, I was able to use it during the test, but I would like this to be repeatable. So, this blog is releasing Swapper, a regex pattern-based match/replace Burp Suite extension.

Read the entire post here
bloodhound_header

Alyssa Snow, Blue Team, Blue Team Tools, General InfoSec Tips & Tricks, How-To, Informational, Red Team, Red Team Tools Active Directory, bloodhound

A Practical Guide to BloodHound Data Collection

This blog will not dive too deeply into BloodHound itself; instead, we will focus on various methods to collect AD data to provide BloodHound as input.

Read the entire post here
networking_header

Informational

Network Engineering Basics

The computer networking field is broad, encompassing many focus areas similar to cybersecurity. If you’re new to the field or just interested in networking, knowing where to start can be challenging. Searching for a network engineer position on any job listing site will yield thousands of results, and no two job descriptions will be the same.

Read the entire post here
Proxy execution via WebView2 banner

C2, How-To, Matthew Eidelberg, Red Team DLL sideloading, initial access

Signed, Trusted, and Abused: Proxy Execution via WebView2

An offensive security perspective on Microsoft Edge WebView2 Runtime, including architectural weaknesses, existing vulnerabilities, and exploitation methods.

Read the entire post here
1 2 3 4›»

Looking For Something?

Browse by category

Recent Posts

  • badge_headerThe Art of the Badge: A Hard Truth About Physical Security
    He walked into the lobby with a fake badge clipped to
  • cicd_header (1)Auditing GitLab: The CI/CD Kill Chain
    Welcome to GoGatoZ — a purpose-built Go tool for
  • antisocop_headerBad Habits: An ANTISOC Operation
    ANTISOC uses a mix of techniques from traditional

Browse by topic

Active Directory ADHD AI anti-virus Attack Tactics AV Beau Bullock BHIS Blue Team C2 Carrie Roberts cloud Cyber Deception hacking infosec Infosec for Beginners InfoSec Survival Guide Joff Thyer john strand Jordan Drysdale Kent Ickler Kerberos Linux MailSniper Malware Microsoft Nessus Nmap passwords password spraying pen-testing penetration testing pentest Pentesting phishing PowerShell Python Red Team red teaming RITA Sysmon tools webcast webcasts Windows

Archives

Back to top
Black Hills Information Security, Inc.

890 Lazelle Street, Sturgis, SD 57785-1611 | 701-484-BHIS (2447)
© 2008


About Us | BHIS Tribe of Companies | Privacy Policy | Contact

Links
Search the site