Better API Endpoint Enumeration: Testing for the #1 OWASP Security Vuln
Broken Access Controls is at the top of the OWASP Top 10. The difficulty is finding each instance to test. Learn 3 ways to enumerate API endpoints thoroughly.
Broken Access Controls is at the top of the OWASP Top 10. The difficulty is finding each instance to test. Learn 3 ways to enumerate API endpoints thoroughly.
Operational Technology pentesting is highly specialized and needs to be performed by experienced OT testers. Learn how to choose the best pentest company.
Principal Pentester Scottie Cole continues his NetExec series with nxcdb, the database that automatically stores key info like hosts and creds while you hack.
Enumerating webpages during an internal network pentest can be a large task, but GoWitness makes it easy to focus on high value webpages. Learn how it works.
Raxis will be at Black Hat USA 2026 August 4–6 at Mandalay Bay Convention Center in Las Vegas. Find us at booth 6018.
Raxis CTO Brian Tant discusses the AI portion of our annual security awareness training and how we take AI security seriously.
BloodHound’s Community Edition has everything a penetration tester needs to enumerate relationships in a domain in order to gain more access, even Domain Admin.
Now that CrackMapExec is no more, how is a pentester to rapidly test credentials, enumerate assets, spray passwords, and more? Learn the basics of NetExec here.
Ryan Chaplin wondered what it would take to bypass ChatGPT’s open-source model security restrictions to allow AI to hack his website. See how he did it here.
Jason Taylor brings highlights reptyr in our Cool Tools series, showing how to take a long-running process, like an Nmap scan, and move it to a new screen.
So you got DA on your red team or internal network penetration test. Here are the five things that Principal Penetration Tester Andrew Trexler does next.
Raxis has discovered and cracked our fair share of password hashes. Some that we have discovered may surprise you… and their bosses. Learn what not to do.
73 posts in Penetration Testing.