The NaviSec blog.
Written by practitioners, not marketers — pentesting guides, compliance explainers, and analysis of the threats we see in the field.
The Reverse Shell Reference Every Pentester Keeps Open
A free reverse shell reference sheet covering Bash, Python, PHP, PowerShell, Netcat, Ruby, and NodeJS techniques, built by NaviSec practitioners from real engagements.
Read →CVE-2025-21293 – Privilege Escalation Vulnerability and Mitigation
CVE-2025-21293 is a privilege escalation vulnerability in Microsoft Active Directory Domain Services that allows attackers to gain SYSTEM-level privileges.
Read →European Union's (EU) Radio Equipment Directive (RED) Summarized
A summary of the EU's Radio Equipment Directive (RED) cybersecurity requirements for radio equipment manufacturers, effective August 1, 2025.
Read →The Tea Application Breach: A Valuable Key in Why You Need to Audit Apps
The Tea dating application exposed roughly 72,000 personal photos and government-issued IDs through a basic Firebase misconfiguration, highlighting why app audits matter.
Read →Ransomware Prevention and Protection
Ransomware Prevention and Protection for your organization in 2025 with penetration testing, phishing simulations, and AI-powered endpoint protection.
Read →Why Q3 Is the Ideal Time to Schedule Your Q4 Penetration Test
Why forward-looking teams schedule and prepare their Q4 penetration test during Q3 to avoid vendor availability crunches and compressed remediation timelines.
Read →How Are Passwords Cracked? Understanding Motives and Defense
The motives behind password cracking, from financial gain to corporate espionage, and defense strategies to protect yourself or your company's assets.
Read →How Are Passwords Cracked? Understanding Methods and Tools
An overview of common password cracking methods (brute force, dictionary, rainbow table attacks) and the tools attackers use, like Hashcat, John the Ripper, and Hydra.
Read →Best Practices for Using Public Wi-Fi
Practical best practices for staying safe on public Wi-Fi, including using a VPN, avoiding sensitive transactions, sticking to HTTPS sites, and keeping software updated.
Read →The Risks of Using Public Wi-Fi and why you should avoid it?
An overview of the risks of using public Wi-Fi, including data theft, man-in-the-middle attacks, malware distribution, network spoofing, and lack of encryption.
Read →Six Types of Multi-Factor Authentication (MFA) to Enhance Your Security
An overview of six types of Multi-Factor Authentication, including SMS, email, authenticator apps, hardware tokens, biometrics, and behavioral biometrics, with their benefits and drawbacks.
Read →Ten Essential Rules for Creating Strong Passwords
Ten essential rules for creating strong passwords, covering password length, uniqueness, multi-factor authentication, password managers, and phishing awareness.
Read →Eight Effective Tips to Optimize Your Cybersecurity Budget
Eight actionable tips for optimizing your cybersecurity budget, from conducting a risk assessment to investing in threat intelligence and employee training.
Read →Common cybersecurity myths debunked
Debunking common cybersecurity myths, from the idea that only large companies are targeted to the belief that password protection alone is enough to keep data secure.
Read →Tech Alert | Windows crashes related to Falcon Sensor | 2024-07-19
Technical alert and step-by-step remediation guidance for Windows host crashes related to a CrowdStrike Falcon Sensor content deployment issue.
Read →Press Release: NaviSec Named to MSSP Alert's 2023 List of Top 250 MSSPs
NaviSec is named to MSSP Alert's 2023 List of Top 250 Global MSSPs, marking the sixth consecutive year the company has earned a spot on the list.
Read →Social Engineering Testing: Safeguard Your Organization with Proactive and Effective Strategies
An overview of social engineering testing, why it matters for your cybersecurity posture, and how to integrate it into your security program.
Read →NIST Cybersecurity Framework: 6 Common Questions
A rundown of what the NIST Cybersecurity Framework is, why organizations adopt it, and how to streamline implementation.
Read →State and Local Government Cyber Security
Why state and local government agencies are frequent cyberattack targets, the compliance mandates that apply, and why penetration testing is essential for the public sector.
Read →CIRCIA 2022: 11 Things You Need To Know
An overview of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) 2022 - who it covers, reporting timelines, protections, and how to prepare.
Read →Penetration Testing for Energy and Utility Companies: Illuminating the Relevancy
Why energy and utility companies are frequent cyberattack targets, the benefits of penetration testing for this sector, and what to look for in a testing provider.
Read →Should your organization be concerned with CTPAT Cyber Security? 6 steps you can take
What CTPAT cyber security requires, the regulations that align with the program, and where to find the official CTPAT Minimum Security Criteria.
Read →NaviSec Named for 5th time to MSSP Alert Top 250 MSSPs List for 2022
MSSP Alert, a CyberRisk Alliance resource, has named NaviSec for the 5th time to the Top 250 MSSPs list for 2022.
Read →Why should you choose third-party penetration testing services?
Why outsourcing penetration testing to a third-party provider is more credible, less biased, and often more cost-effective than relying on an internal team.
Read →When do you need a penetration test?
A guide to the situations that call for a penetration test, from annual security checkups and regulatory compliance to new product launches and post-breach response.
Read →The auto dealership industry and GLBA PenTesting
GLBA compliance requirements for auto dealerships and how GLBA penetration testing and vulnerability assessments help dealers meet the amended safeguards rule.
Read →Insurance Compliance – How does NaviSec help you meet gaps for cyber security insurance?
How cyber security insurance works, why it can be tricky to get approved, and how NaviSec's penetration testing, vulnerability assessment, managed detection and response, and security audit services help close the gaps insurers look for.
Read →Who needs a Penetration Test?
A rundown of the regulations and standards — PCI DSS, GLBA, HIPAA, SOC 2, GDPR, CCPA, FINRA, and PIPEDA — that call for or recommend regular penetration testing.
Read →Penetration Testing vs. Vulnerability Assessment: What is the difference?
A breakdown of how penetration testing and vulnerability assessment differ in meaning, focus, skill required, automation, coverage, frequency, cost, and time to complete.
Read →Cloud Penetration Testing
What cloud penetration testing is, the major cloud security issues businesses face, the shared responsibility model, and the methodology pentesters follow to secure cloud infrastructure.
Read →Stories from a Successful Partnership: Totem Technologies, LLC
Two client success stories showing how NaviSec and Totem Technologies, LLC have partnered to help DoD contractors achieve cybersecurity compliance.
Read →IoT Penetration Testing
What IoT penetration testing covers, why it matters as connected devices proliferate, the OWASP IoT top 10, and the methodology pentesters follow to secure IoT and SCADA systems.
Read →Physical Penetration Testing
What physical penetration testing is, why organizations should undertake it, the five-phase methodology pentesters follow, and the most common attack vectors used.
Read →Web Application Penetration Testing
What web application penetration testing covers, why it matters, the OWASP Top 10 risks it targets, the four-phase testing methodology, and the tools pentesters commonly use.
Read →Mobile Application Penetration Testing
What mobile application penetration testing covers, the categories of mobile apps, the top security risks it mitigates, and the four-phase methodology pentesters use.
Read →Wireless Penetration Testing
An overview of wireless penetration testing, covering common vulnerabilities, testing goals, benefits, the engagement process, and what to look for in a testing partner.
Read →Gray Box Penetration Testing
An overview of gray box penetration testing, a hybrid approach combining black box and white box methods, including techniques, benefits, methodology, and challenges.
Read →White Box Penetration Testing
An overview of white box penetration testing, its core methodologies, benefits, step-by-step process, common tools, and constraints testers may face.
Read →What is Penetration Testing (PenTest): Types of Penetration Testing from Black to White Box and everything in-between
A guide to penetration testing covering what it is, why organizations use it, common testing methods, and the major types of pentests from black box to cloud testing.
Read →NaviSec Penetration Testing Methodology – Penetration Testing Execution Standard (PTES)
An overview of the Penetration Testing Execution Standard (PTES) and its seven phases, the methodology NaviSec uses as a baseline for its penetration testing engagements.
Read →Black Box Penetration Testing
An overview of black box penetration testing, including its techniques, benefits, methodology, and limitations for evaluating an organization's cybersecurity posture.
Read →Partner Feature: CrowdStrike – NaviSec's Managed Detection and Response Services
How NaviSec's Managed Detection and Response services leverage CrowdStrike's endpoint security platform to detect, respond to, and remediate threats.
Read →NaviSec Discovers Critical Zero-Day Exploit for Cacti Services
NaviSec's Delta Team discovered a critical zero-day exploit (CVE-2022-0730) affecting all versions of Cacti services prior to v1.2.20, and worked with Cacti to patch it.
Read →Cybersecurity for Connected Medical Device Manufacturers
Six areas of cybersecurity focus for connected medical device manufacturers, from compliance landscaping to ongoing security monitoring.
Read →GLBA and the Penetration Testing Mandate: Everything You Need to Know
What the Gramm-Leach-Bliley Act requires, its recent Safeguards Rule updates, and what the penetration testing mandate means for financial institutions.
Read →The Importance of Penetration Testing for Medical Software and Medical Device Vendors
Why the growing attack surface of the internet of medical things (IoMT) makes regular penetration testing essential for medical software and device vendors.
Read →A Pentester's Guide – Part 5 (Unmasking WAFs and Finding the Source)
Techniques for identifying WAFs, unmasking the real origin server behind them, and interacting with the source host directly during a penetration test.
Read →A Pentesters Guide – Part 4 (Grabbing Hashes and Forging External Footholds)
External and internal techniques for grabbing NTLM hashes during a penetration test, from malicious Word documents and URI handlers to LLMNR poisoning.
Read →A Pentester's Guide – Part 3 (OSINT, Breach Dumps, & Password Spraying)
A practical walkthrough of passive service recon, email generation, indexing breach data, and password spraying with BurpSuite.
Read →A Pentester's Guide – Part 2 (OSINT – LinkedIn is not just for jobs)
The second installment of a pentester's guide, covering how to use LinkedIn and email-pattern generation for OSINT, plus a bonus section on password spraying.
Read →A Pentester's Guide – Part 1 (OSINT – Passive Recon and Discovery of Assets)
The first installment of a pentester's guide, covering passive reconnaissance and OSINT techniques for asset discovery, including Burp Suite, Shodan, DNS enumeration, and email scraping.
Read →DNS & Web Enumeration Reference
A technical reference for DNS and web enumeration during penetration testing engagements, covering passive recon tools, active reconnaissance with nmap, HTTP enumeration, and web framework fingerprinting.
Read →Who is NaviSec Delta?
An introduction to NaviSec Delta, the offensive security arm of NaviSec, covering penetration testing, vulnerability management, red teaming, and security research.
Read →Privilege Escalation Reference
A technical reference for Linux and Windows privilege escalation, covering situational awareness commands, escalation vectors, and tools like pspy and PowerUp.
Read →Penetration Testing Engagement References
A centralized hub of cheatsheets and reference articles for penetration testing engagements, including privilege escalation and reverse shell references.
Read →Find out where you stand — free.
Take the free online risk assessment, or start with a confidential conversation about your risk, threats, and current cybersecurity posture.
Take the Free Risk Assessment