Hack Responsibly

Browse Hack Responsibly, a technical blog by The NetSPI Agents. Dive deep into the latest CVEs and vulnerabilities our team uncovers, and how we help NetSPI customers protect against the most important threats today.

Network Pentesting

Hunting SMB Shares, Again! Charts, Graphs, Passwords & LLM Magic for PowerHuntShares 2.0

Learn how to identify, understand, attack, and remediate SMB shares configured with excessive privilege in active directory environments with the help of new charts, graphs, and LLM capabilities.

Learn More
Cloud Pentesting

Filling up the DagBag: Privilege Escalation in Google Cloud Composer

Learn how attackers can escalate privileges in Cloud Composer by exploiting the dedicated Cloud Storage Bucket and the risks of default configurations.

Learn More
Mainframe Penetration Testing

Hacking CICS: 7 Ways to Defeat Mainframe Applications

Explore how modern penetration testing tools uncover vulnerabilities in mainframe applications, highlighting the need for methodical techniques and regular testing to protect these critical systems from threats.

Learn More
Cloud Pentesting

Backdooring Azure Automation Account Packages and Runtime Environments 

Azure Automation Accounts can allow an attacker to persist in the associated packages that support runbooks. Learn how attackers can maintain access to an Automation Account.

Learn More
Mainframe Penetration Testing

Mapping Mainframe Memory Made Easy

Explore how NetSPI’s own LPAR enhances pentesting efficiency through rapid tool prototyping and deployment.

Learn More
Network Pentesting

Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation 

Learn how threat actors can exploit SQL Server credential objects to escalate domain privileges and how you can detect it.

Learn More
Web Application Pentesting

CVE-2024-37888 – CKEditor 4 Open Link plugin XSS

NetSPI discovered CVE-2024-37888, a cross-site scripting (XSS) vulnerability in the CKEditor 4 Open Link plugin. Read about the nature of the vulnerability and its implications.

Learn More
Cloud Pentesting

An Introduction to GCPwn – Parts 2 and 3

Example exploit path using GCPwn covering enumeration, brute forcing secrets manager versions, and downloading data from cloud storage both through default enum_buckets and with HMAC keys.

Learn More
NetSPI Agent Updates

DEF CON 32 Recap: Insights and Experiences from The NetSPI Agents 

Explore the highlights of DEF CON 32 through the eyes of The NetSPI Agents. Discover key takeaways, expert insights, and firsthand experiences from this year’s premier hacker conference.

Learn More
Cloud Pentesting

Extracting Managed Identity Certificates from the Azure Arc Service 

The Azure Arc service is handy for bringing on-prem systems to the cloud, but it includes features that could lead to pivots from on-prem into your Azure environment.

Learn More
Cloud Pentesting

Escalating Privileges in Google Cloud via Open Groups 

Learn how attackers can abuse Open groups to potentially escalate privileges in Google Cloud and how to detect these attack paths.

Learn More
Cloud Pentesting

An Introduction to GCPwn – Part 1

GCPwn is a python-based framework for pentesting GCP environments. While individual exploit scripts exist today for GCP attack vectors, GCPwn seeks to consolidate all these scripts and manage multiple sets of credentials at once (for example, multiple service account keys) all within one framework. With the use of interactive prompts, GCPwn makes enumeration and exploitation […]

Learn More