Black Hills Information Security, Inc.
RSS
  • All Services
    • Complete Service Guide
    • Active SOC
    • AI Security Assessments
    • Blockchain Security
    • Blue Team Services
    • Continuous Penetration Testing
    • High-Profile Risk Assessments
    • Incident Response
    • Penetration Testing
  • Contact Us
    • Contact Us
    • Email Sign-Up
  • About Us
    • Security Consultants
    • Admin Team
    • Active SOC Team
    • Antisyphon Training
    • BHIS Tribe of Companies
  • Free Resources
    • Blogs
    • Free Cybersecurity Tools
    • Free Cybersecurity Webcasts
    • Podcasts
    • RITA
  • Training
    • BHIS & Antisyphon Training
    • WWHF Conference
  • Community
    • Discord
    • LinkedIn
    • YouTube
    • Bluesky
    • Twitter/X
    • Upcoming Events
  • Fun Stuff
    • Backdoors & Breaches
    • Merch, Zines & More
    • PROMPT# Zine
    • REKCAH
    • Books
Screen Shot 2017-01-06 at 10.00.27 AM

Author, John Strand, Red Team, Webcasts bypassing AV, Sacred Cash Cow Tipping

WEBCAST: Sacred Cash Cow Tipping 2016

John Strand with BHIS testers // Yes, we did this in 2017, but it’s reflecting work done in 2016.

Read the entire post here
00157_01052017_BypassAntiVirusToRunMimikatz

Red Team, Red Team Tools All the AVs, anti-virus, bypassing AV, Carrie Roberts, mimikatz, Windows Defender

How to Bypass Anti-Virus to Run Mimikatz

Carrie Roberts // * Would you like to run Mimikatz without Anti-Virus (AV) detecting it? Recently I attempted running the PowerShell script “Invoke-Mimikatz” from PowerSploit on my machine but it was […]

Read the entire post here
phishing_license

Author, C2, David Fletcher, Red Team Apple, Install, Mac, Malware, phishing

How to Phish for Geniuses

David Fletcher // Recently we were involved in an engagement where we expected to see a large number of Macs in the target environment. As an element of the engagement […]

Read the entire post here
Malicious Outlook Rule without an EXE

C2, Red Team exploit, malicious outlook rules, Outlook, Sacred Cash Cow Tipping

Malicious Outlook Rule without an EXE

 Carrie Roberts // My current favorite exploit is creating malicious outlook rules as described here. The rule is configured to download an executable file with an EXE extension (.exe) when an […]

Read the entire post here
old_phone

Phishing, Red Team con artistry, Marketing, pen-testing, penetration testing, Pentesting, phishing, social engineering

A Marketer’s Lessons in Con Artistry for Good & Learning

Sierra Ward* // Normally I am hidden in the back rooms at BHIS, chipping away at 10 million marketing tasks.  I show up occasionally in webcasts, lurking again in the shadows, […]

Read the entire post here
Screen Shot 2016-12-15 at 10.40.28 AM

Blue Team, Blue Team Tools, Webcasts Domain Password Audit Tool, DPAT, webcast

WEBCAST: Demo of Domain Password Audit Tool

Check out Carrie’s demo of her DPAT, and if you missed her blog, check that out here.

Read the entire post here
baby-with-ipad-640x480

InfoSec 101 ebooks, electronic text, Millineals, reading online, reading with children, reading with kids, tiny people

Bite the Pages of an Ebook: Tiny People Need to See You Get Excited about Electronic Text

 Gail Menius // We avoid tasks that are too hard. When we avoid them (consciously or unconsciously) the things we do instead are called “avoidance behaviors.” Adults and teachers alike […]

Read the entire post here
00151_12122016_PowerShellLoggingForTheBlueTeam

Author, Blue Team, Blue Team Tools, Joff Thyer Blue Team, Joff Thyer, PowerShell

PowerShell Logging for the Blue Team

Joff Thyer //   It is no secret that PowerShell is increasingly being used as an offensive tool for attack purposes by both Red Teamers and Criminals alike. Thanks to […]

Read the entire post here
b-day-gifts-squarer

Fun & Games christmas, gifts, holidays, infosecker, presents

BHIS’s Annual Infosecker’s* Gift-List

Sierra Ward & Staff // Buying gifts can be tough, especially for your family members who are totally mystified by your profession. “Don’t you hack the stuff with the things?” […]

Read the entire post here
«‹ 64 65 66 67›»

Looking For Something?

Browse by category

Recent Posts

  • Proxy execution via WebView2 bannerSigned, Trusted, and Abused: Proxy Execution via WebView2
    An offensive security perspective on Microsoft Edge
  • Getting Started in PentestingGetting Started In Pentesting – Advice From The BHIS Pentest Lead
    Advice about getting started in pentesting from the
  • Tips and Resources for Securing the CloudCloud Security: Tips and Resources for Securing the Cloud
    This overview of the basics of Cloud Security includes

Browse by topic

Active Directory ADHD AI anti-virus Attack Tactics AV Beau Bullock BHIS Blue Team C2 Carrie Roberts cloud Cyber Deception hacking infosec Infosec for Beginners InfoSec Survival Guide Joff Thyer john strand Jordan Drysdale Kent Ickler Kerberos Linux MailSniper Malware Microsoft Nessus Nmap passwords password spraying pen-testing penetration testing pentest Pentesting phishing PowerShell Python Red Team red teaming RITA Sysmon tools webcast webcasts Windows

Archives

Back to top
Black Hills Information Security, Inc.

890 Lazelle Street, Sturgis, SD 57785-1611 | 701-484-BHIS (2447)
© 2008


About Us | BHIS Tribe of Companies | Privacy Policy | Contact

Links
Search the site