Other content in this Stream

Schellman Principal, Matt Wilgus addresses one of the biggest challenges frequently seen in planning penetration tests—timing

Considering Portswigger's new Burp Suite Certified Practitioner certification? Read a senior pen tester's experience to understand what to expect.

Using MacOS within your corporate environment? Our team tested the latest Apple M1 Silicon - here are our security findings regarding vulnerabilities Mac users face.

Testing a mobile application and frustrated watching some traffic slip away from your settings? Learn about a technique that can help stop that from happening so you can capture everything every time.

Working with Burp and finding that you need a workaround? Learn how to build your own extension and potentially solve your problem.

Making AppSec penetration testing assessments more streamlined through application mapping

For those interested in OSEP certification, Schellman Penetration Tester, Wes Dorman provides an overview of the recently released PEN-300 course Overview Offensive Security has released se

Schellman expands services and becomes Payment Card Industry (PCI) Approved Scanning Vendor (ASV)

Schellman Penetration Tester Wes Dorman shares techniques for slowing down an adversary's attacks with active directory hardening

Schellman's John Bullinger shares his experiences and best practices for conducting penetration testing from both sides of the coin: as that of a CSO and as a penetration tester.

For seasoned penetration testers who want to become a true web app exploit guru, OSWE certification delivers. Schellman's Nathan Rague provides an exam guide to help aspiring candidates prepare.

For any penetration testing engagement, internet-facing services are an important part, and there are multiple ways to obtain information before determining if they are vulnerable to exploitation.

What are the common reasons CSPs fail to achieve a FedRAMP Authority to Operate ATO in a timely manner?

Many organizations provide Application Program Interfaces (APIs) to allow their clients and business partners to enter and retrieve data. We primarily see REST based APIs, but also GraphQL and SOAP.

This has been the most rewarding and engaging work and continues to be my dream job, and yet, the transition from full-stack web application developer to penetration tester was daunting.

When it comes to cybersecurity, it’s the things we don’t know that can be the scariest.

Please, join Matt Wilgus and Josh Tomkiel from Schellman's Threat and Vulnerability Assessment team, as they cover the ins and outs of performing a penetration test of cloud based services.

EC-Council brings a new range of real world challenges that will not only test your Pen-testing skills but guarantees you an experience that is not built for the weak hearted.

As a Third Party Assessment Organization (3PAO), Schellman regularly conducts FedRAMP assessments for Cloud Service Providers (CSPs). Included during these assessments is a penetration...