Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Bulletproof

Tech Talk: Behind the curtain - Obfuscating Linux Symbols

This is a Bulletproof Tech Talk article: original research from our red team covering issues, news, and tech that interests them. It’s more technical and in-depth that our usual blog content, but no less interesting. This blog looks at obfuscating Linux Symbols using dl_iterate_phdr with callbacks. It represents original security research from the Bulletproof Red Team.

Tech Talk: Abusing ESC13 from Linux

This is a Bulletproof Tech Talk article: research from our penetration testing team covering issues, news, and tech that interests them. It’s more technical and in-depth that our usual blog content, but no less interesting. In the complex landscape of Active Directory, ensuring secure and appropriate access is a constant challenge. Recently another "ESC" technique has been released which is known as ESC13.

Beyond Cyber Essentials: securing critical operations

The Cyber Essentials scheme has started to become a victim of its own success, with some organisations thinking it’s all they need to operate securely. Now I need to start by saying that Cyber Essentials is a great security baseline and I strongly recommend that every single organisation gets Cyber Essentials certification. It provides a valuable framework for establishing fundamental cyber security practices. But is that always enough?

Red Team vs Pen Testing - What's the Difference? | Red Team Roundtable

Red teaming is just pen testing, right? Well, wrong. There’s overlap, for sure, but red teaming and penetration testing are coming from different places doing different jobs. Find out the nitty gritty in this 90-second explainer. This is an excerpt from our full Red Team Roundtable, part of our Fireside Chats series.