Companion-course connectionExploits
An exploit is code, a technique, or a sequence of actions that takes advantage of a vulnerability or unsafe condition to produce unintended behavior.
Open article →Companion-course connectionPenetration Test Reporting
A penetration test report explains what was tested, what was demonstrated, why it matters, how confident the tester is, and what should happen next.
Open article →Companion-course connectionPenetration Testing Lifecycle
A penetration test moves through authorization, planning, reconnaissance, analysis, controlled exploitation, post-exploitation, evidence handling, reporting, cleanup, and retesting.
Open article →Companion-course connectionReconnaissance and Enumeration
Reconnaissance gathers information about a target, while enumeration actively identifies services, accounts, resources, versions, trust relationships, and other usable details.
Open article →Companion-course connectionRunbook Automation Safeguards
Runbook automation safeguards convert operational procedures into controlled actions with validated preconditions, bounded permissions, approvals, logging, and clear handoff to people.
Open article →Companion-course connectionCredential Access
Credential access includes techniques used to obtain passwords, hashes, tokens, keys, tickets, cookies, or other material that can authenticate an identity.
Open article →Companion-course connectionLateral Movement
Lateral movement is the use of credentials, remote services, trust relationships, and administrative tools to move from one system or account to another.
Open article →Companion-course connectionScope and Rules of Engagement
Scope defines what a security test may include, while rules of engagement define how, when, and under which conditions testing may occur.
Open article →Companion-course connectionAccess Control Lists on Hosts
Host access control lists extend basic owner-group-other permissions with named user and group entries, default inheritance, and more precise authorization for shared files and directories.
Open article →Companion-course connectionAI-Assisted Audit Governance
AI-assisted audit governance establishes approved uses, boundaries, validation, confidentiality, accountability, and documentation when auditors use AI tools.
Open article →Companion-course connectionAI Literacy and Training
AI literacy and training give each stakeholder enough role-specific knowledge to use, build, supervise, procure, govern, or challenge AI responsibly.
Open article →Companion-course connectionAPI Token Scope Design
API token scope design grants an automation client only the operations, resources, environments, and duration needed for its approved purpose.
Open article →