惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
Jina AI
Jina AI
罗磊的独立博客
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
J
Java Code Geeks
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
腾讯CDC
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
I
InfoQ
月光博客
月光博客
博客园_首页
Vercel News
Vercel News
P
Proofpoint News Feed
GbyAI
GbyAI
Y
Y Combinator Blog

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Webcast: Pentester Tactics, Techniques, and Procedures TT...
BHIS · 2022-11-04 · via Black Hills Information Security, Inc.

, ,

Penetration Testing is often considered a dark art that’s shrouded in mystery. This unfortunate perception can hold back organizations from being more secure and keep people from an exciting career.

In this Black Hills Information Security (BHIS) webcast, join Chris Traynor (@cstraynor) as he shares the tactics, techniques, and procedures (TTPs) for a Pentester.

Chat with your fellow attendees in the Infosec Knowledge Sharing Discord server here: https://discord.gg/fr5wqbF — in the #webcast-live-chat channel.

/// Chapters 00:00 – Pentester Tactics, Techniques, and Procedures (TTPs) with Chris Traynor

00:21 – Whoami

00:56 – Agenda

02:36 – Baseline Terminology

08:12 – Reconnaissance — Tactic/Intended Effect

09:15 – Nmap — Tool/Mechanism

11:14 – Nmap — Execution

14:36 – Recon-ng – Tool/Mechanism

19:57 – Recon-ng — Execution

22:34 – Recon-ng — Cheatsheet

25:13 – Account Enumeration — Tactic/Intended Effect

26:10 – Burp Repeater — Tool/Mechanism

27:01 – Burp Repeater — Execution

33:51 – Password Spraying — Tactic/Intended Effect

39:15 – Burp Intruder — Tool/Mechanism

40:15 – Burp Intruder — Execution

44:17 – smb_login Module — Tool/Mechanism

45:51 – smb_login Module — Execution

47:56 – psexec Module — Execution

52:30 – Chris’s Other Talks

54:18 – Post-Show Questions