Logo

Search

Home

PNPT Studies

PJPT Studies

AD CS / Certificate Attacks (ESC1-15) (1, 8, 11 for now)

Report Writing / Client Presentation

Operationalizing Cybercrime Data (June 2025)

Study Notes
/
External Pentest Playbook
/
Common Pentest Findings (External Testing)

Common Pentest Findings (External Testing)

Insufficient Authentication ControlsWeak Password PolicyInsufficient PatchingDefault CredentialsInsufficient Encryption (The Most by far)Information DisclosureUsername EnumerationDefault Web PagesOpen Mail RelaysIKE Aggressive ModeUnexpected Perimeter ServicesInsufficient Traffic BlockingUndetected Malicious ActivityHistorical Account Compromises