Cloud Penetration Testing: Our Methodology for AWS, Azure, and GCP

A working walkthrough of the cloud penetration testing methodology we run against AWS, Azure, and GCP: how we abuse IAM, hunt misconfigurations and exposed storage, pivot from SSRF to instance metadata, escalate privilege, and check whether anyone was watching.
Read more

The Web Application Penetration Testing Methodology We Use

The exact web application penetration testing methodology we run on engagements, from mapping the app to chaining low findings into a real breach and retesting the fix.
Read more