The Exploit

Penetration Testing Blog

Offensive security, written by the professionals who live it.

Real Attacks, Real Writeups

No Malware Required

The March 2026 attack on Stryker Corporation was not Malware and did not make Ransomware demands. Instead it used compromised credentials to disrupt business.

Cool Tools Series: SCP

Raxis Lead Penetration Tester Nathan Anderson continues our Cool Tool Series with SCP for data exfiltration on internal network pentests and red teams.

Cool Tools Series: Reptyr

Jason Taylor brings highlights reptyr in our Cool Tools series, showing how to take a long-running process, like an Nmap scan, and move it to a new screen.

292 posts, newest first.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.