We have open sourced our legal documentation used for physical penetration tests.
The purpose is to help the community and organizations protect their employees when conducting testing.
Includes three docs:
MSA
SOW
Authorization Letter
github.com/trustedsec/phy…
#TrustedSec
TrustedSec
5,208 posts
End-to-end Cybersecurity consulting team leading the industry, supporting organizations, and giving back. #Hacktheplanet
Blogs, news, webinars, and tools!
- We have just released a new tool for exploiting CVE-2019-19781. Our goal was to keep private as long as possible to have a longer window to fix. Other researchers have published the exploit code in the wild already. Cats out of the bag. github.com/trustedsec/cve… #TrustedSec
- We've just released a scanner that checks to see if a server is vulnerable for CVE-2019-19781. It does not actually exploit the target and is erfectly safe with no impact on the system. #TrustedSec github.com/trustedsec/cve…
- PenTesters Framework (PTF) v2.3 “All the Tools” released. Adds 7 new tools including rdp scanner, support for internal gitlab, support for customized installs of only certain tools, and more. (Fixed link) GitHub.com/TrustedSec/ptf #TrustedSec
- Secret's out! @Carlos_Perez announces the release of the TrustedSec #Sysmon Community Guide. Discover the vision for making the guide and how you can contribute to making the best #resource for all things sysmon!
- New Public Tool Release: Hate_Crack Automated Hash Cracking Techniques with Hashcat Written by: @Spoonman1091 trustedsec.com/2018/02/public… #TrustedSec
- The PenTesters Framework (PTF) version 2.2 “Tool Haven” released. Adds support for docker containers, number of new tools and fixes. Total of 252 tools now! GitHub.com/TrustedSec/ptf #TrustedSec
- With initial access to a M365 account, Red Teamers can potentially find a treasure trove of sensitive information. @Flangvik goes over three tools (and one script) that he believes to be the modern-day Triforce for initial access. Read it now on our blog!
- A message from CEO @HackingDave regarding the recent incident at the Dallas County Courthouse Judicial Branch Building in Iowa. hubs.ly/H0lxZ3Q0
- We are proud to announce the addition of @Carlos_Perez as lead of the Research and Development team at #TrustedSec. Excited to have you on board Carlos! Great addition to our team, and our continued commitment of having amazing folks. trustedsec.com/2018/02/carlos…
- Senior Security Consultant @Jean_Maes_1994 gives us the first comprehensive resource about all things #relaying. This guide covers a range of techniques from most common to the lesser-known.
- For almost a year, invisible password spraying could be performed against any #Azure tenant due to a vulnerability in #MicrosoftGraph. In our latest blog, @nyxgeek walks us through how these attacks could have been carried out. Read it now!
- Today, TrustedSec is releasing #Specula (our previously internal framework) into the world, which will transform the Outlook email client into a beaconing C2 agent. @Oddvarmoe and @freefirex2 walk through how to use Specula in our latest blog!
- New version of the PenTesters Framework v2.3.1 “All the Tools” released. Adds pexpect checks for gitlab support and requirements installation. GitHub.com/TrustedSec/ptf #TrustedSec


