Resources
Latest Research Resources
Recent InfoSec Talks, Defcon 32 Demo Labs - Farming n-days with GreyNoise
In this series the service delivery team writes about an outstanding talk they saw at a conference and implementing those lessons at scale.
Read moreOne Proxy to Rule Them All
Bypass WAFs with gigaproxy: an HTTP proxy that rotates IPs using mitmproxy, AWS API Gateway, and Lambda. Read the blog to learn more. read more →
I Love Lucee: Building Lucee Extensions for Remote Code Execution
During the past few assessments, Sprocket has encountered improperly configured instances of Lucee 5 and 4. This blog post will detail a straightforward method to execute remote code after acquiring administrative… read more →
Directory Brute-forcing at Scale
Tools such as dirbuster, gobuster, feroxbuster, dirb, and ffuf have been instrumental in uncovering hidden content on websites. These tools and wordlists designed to discover files and directories have become staples in… read more →
How to introduce security testing to your web app deployments during QA
Fixing these vulnerabilities in production is more expensive than finding and fixing them earlier in the SDLC. One way that organizations can drive down the cost of vulnerability management is by integrating security… read more →
Surfacing the Invisible: A Guide to Web Application Attack Surface Management
The top five web application-specific attack surface management opportunities Sprocket Security sees regularly. read more →
What is the Difference Between Vulnerability Scanning and Penetration Testing?
In cybersecurity, various tools and strategies are at organizations' disposal to enhance their overall security posture. Among these, two frequently misunderstood strategies are vulnerability scanning and penetration… read more →
2023 Ransomware Examples
Ransomware has emerged as one of the most common and damaging malware threats in recent years. In fact, the volume and expense of ransomware attacks have caused some insurers to exclude them from cybersecurity coverage.… read more →
What is attack surface management?
Attack surface management is a security solution that provides vulnerability monitoring across your digital and physical assets. read more →
Artificial Intelligence in Cyber Security
AI will almost certainly become a central part of the SOC of the future. However, it’s important to ensure that this AI is well-trained and to address the potential for attacks specifically targeting these AI systems. read more →
The Best Penetration Testing Tools & Learning Resources for 2022
Learn penetration testing best practices from industry pros to prevent breaches, reduce exposure, and keep your digital assets secure. read more →
The Top 7 Most Exploitable CVEs in 2022
Vulnerability management can be an overwhelming task with so many new vulnerabilities identified each year. Learn about the top vulnerabilities of 2022, which should be at the top of your patch priority list. read more →
Continuous Human & Automated Security
The Expert-Driven Offensive
Security Platform
Continuously monitor your attack surface with advanced change detection. Upon change, testers and systems perform security testing. You are alerted and assisted in remediation efforts all contained in a single security application, the Sprocket Platform.
Expert-Driven Offensive Security Platform
- Attack Surface Management
- Continuous Penetration Testing
- Adversary Simulations