CMS vulnerability scanners logo

CMS Vulnerability Scanners for WordPress, Joomla, Drupal, Moodle, Typo3..

In this article we will look on 12 free and open-source vulnerability scanners for CMS (Content Management System) such as WordPress, Joomla, Drupal, Moodle, Typo3 and similar publishing platforms. We will look on Droopescan, CMSmap, CMSeeK, WPXF, WPScan, WPSeku, WPForce, ...
Windows Privilege Escalation – Local Admin Bruteforcer localbrute.ps1 logo

Windows Local Admin Brute Force Attack Tool (LocalBrute.ps1)

In this post, we will be introducing a new minimalistic tool for local privilege escalation attacks in Microsoft Windows systems. The tool is called localbrute.ps1 and it is a simple local Windows account brute force tool written in pure PowerShell ...
PowerShell commands for pentesters logo

PowerShell Commands for Pentesters

This article contains a list of PowerShell commands collected from various corners of the Internet which could be helpful during penetration tests or red team exercises. The list includes various post-exploitation one-liners in pure PowerShell without requiring any offensive (= ...
Metasploit post exploitation modules logo

Post Exploitation Metasploit Modules (Reference)

Did you know that there are over 350 post exploitation modules in the current Metasploit Framework version that comes pre-installed on the Kali Linux? How many of them do you use during your penetration testing activities? If you are like ...
Microsoft Azure cloud top 20 vulnerabilities and misconfigurations logo

Top 20 Microsoft Azure Vulnerabilities and Misconfigurations

In this article, we will look on the top 20 vulnerabilities and misconfigurations of the Microsoft Azure cloud that are commonly found during credentialed security audits and architecture reviews. Information in this post can hopefully aid security architects, auditors and ...