Buckle up! This is one of my favorite episodes.
Today I'm kicking off a two-part series that walks you through a narrative of a recent internal pentest I worked on. I was able to get to Domain Admin status and see the "crown jewels" data, so I thought this would be a fun and informative narrative to share. Below are some highlights of topics/tools/techniques discussed:
Building a pentest dropbox The timing is perfect - my pal Paul (from Project7) and Dan (from PlexTrac) have a two-part Webinar series on building your own $500 DIY Pentest Lab, but the skills learned in the Webinars translate perfectly into making a pentest dropbox. Head to our webinars page for more info.
Securing a pentest dropbox What I did with my Intel NUC pentest dropbox is build a few VMs as follows:
Scoping/approaching a pentest From what I can gather, there are (at least) two popular schools of thought as it relates to approaching a pentest:
Pentest narrative For one of the tests I worked on, here were some successes and challenges I had along the way:
Check out the show notes at 7MS.us as there's lots more good info there!