Find the latest Webinar content from the Sprocket Testing Team.

Blog

Stay updated with the latest offensive security news, knowledge, and resources.

Latest Resources

Adopting a Continuous Security Mindset
Aug 21, 2024 5 min read

Adopting a Continuous Security Mindset

Despite the increase of "continuous" security solutions, the fundamental issues in cybersecurity remain unresolved. The real challenge lies not in the availability of information but in how organizations use it to address systemic problems. By shifting focus from merely fixing individual vulnerabilities to refining operational security processes, companies can build a more effective, continuous security mindset that addresses root causes...
READ MORE
One Proxy to Rule Them All
Jul 15, 2024 11 min read

One Proxy to Rule Them All

Bypass WAFs with gigaproxy: an HTTP proxy that rotates IPs using mitmproxy, AWS API Gateway, and Lambda. Read the blog to learn more.
READ MORE
Exploring Modern Password Spraying: Introduction to Entra Smart Lockout
Jun 21, 2024 9 min read

Exploring Modern Password Spraying: Introduction to Entra Smart Lockout

Delve into the modern techniques and security controls surrounding password spraying. This series will explore the current techniques, tactics, and procedures (TTPs) for password spraying.
READ MORE
Pwning SPA’s With Semgrep
May 30, 2024 7 min read

Pwning SPA’s With Semgrep

Semgrep, or Semantic Grep (For Code) should be a part of your pentesting toolkit. If you think otherwise, read on to see why.
READ MORE
PCI DSS 4.0 and a Continuous Offensive Security Strategy
May 16, 2024 6 min read

PCI DSS 4.0 and a Continuous Offensive Security Strategy

In the ever-evolving landscape of cybersecurity, organizations are constantly challenged to protect their sensitive data. The Payment Card Industry Data Security Standard (PCI DSS) version 4.0 is the latest iteration of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
READ MORE
From Twitter to Exploit: The Sprocket Security Lifecycle of Exploitation
May 16, 2024 4 min read

From Twitter to Exploit: The Sprocket Security Lifecycle of Exploitation

Our approach to mass exploitation of the latest and greatest vulnerability. On the chopping block, this time around: CVE-2024-3400.
READ MORE