Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Raxis: Raxis is an Atlanta-based penetration testing and red teaming company. Since 2011, Raxis has delivered manual, human-led security assessments and adversary simulations to organizations in finance, healthcare, government, and technology. ## Sitemaps [XML Sitemap](https://raxis.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [Meet the Pets of Raxis](https://raxis.com/blog/meet-the-pets-of-raxis/): The Raxis team is serious about cybersecurity and exploits, but today we're taking a break from that to show off our pets. - [usbliter8 – Apple A12 and A13 SecureROM Exploit](https://raxis.com/blog/usbliter8-apple-a12-and-a13-securerom-exploit/): The usbliter8 SecureROM exploit is big news for jailbreaking iPhones. This hardware vulnerability cannot be fixed with a software update. - [PSE & Red Team Series: Looting](https://raxis.com/blog/pse-red-team-series-looting/): Nathan Anderson continues his Physical Social Engineering and Red Team series with the final step: looting. Learn what shows value to stakeholders in reports. - [RoguePlanet: The Defender Zero-day that Survived Microsoft’s June Patch](https://raxis.com/blog/rogueplanet-the-defender-zero-day-that-survived-microsofts-june-patch/): The new critical Microsoft Defender exploit, RoguePlanet (CVE-2026-50656), is confirmed active in the wild. Learn what it is and how to protect your network. - [Building Security Tools from Source to Bypass Endpoint Security](https://raxis.com/blog/building-security-tools-from-source-to-bypass-endpoint-security/): Endpoint security detects many malicious files created with pentest tools, but pentesters can sometimes bypass this by rebuilding source code. Learn how here. - [The Game is Starting: Release the Fraudsters](https://raxis.com/blog/the-game-is-starting-release-the-fraudsters/): Large tournaments bring out fraudsters just as your employees' guard is down. Raxis CTO Brian Tant discusses recent threats and how to protect your company. - [Cool Tools: Bloodhound CE](https://raxis.com/blog/cool-tools-bloodhound-ce/): BloodHound's Community Edition has everything a penetration tester needs to enumerate relationships in a domain in order to gain more access, even Domain Admin. - [CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation](https://raxis.com/blog/cve-2026-36748-xss-in-rock-rms-leads-to-privilege-escalation/): Raxis Lead Pentester Jason Taylor recently discovered CVE-2026-36748, a high-risk XSS vulnerability in Rock RMS that allows privilege escalation to admin. - [Defense in Depth Against Linux Kernel Privilege Escalation: A Practical Guide for Container Workloads](https://raxis.com/blog/defense-in-depth-against-linux-kernel-privilege-escalation/): With current local privilege escalation exploits like Copy Fail and Dirty Frag active in the wild, harden your defenses to halt attacks even before patching. - [Cool Tools: NetExec (NXC) Fundamentals](https://raxis.com/blog/cool-tools-netexec-nxc-fundamentals/): Now that CrackMapExec is no more, how is a pentester to rapidly test credentials, enumerate assets, spray passwords, and more? Learn the basics of NetExec here. - [Critical Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software](https://raxis.com/blog/critical-buffer-overflow-vulnerability-in-palo-alto-networks-pan-os-software/): CVE-2026-0300 is a critical buffer overflow vulnerability in Palo Alto’s PAN-OS software. Discover if you are affected and what to do now. - [Copy Fail – Local Linux Privilege Escalation in 4 lines](https://raxis.com/blog/copy-fail-local-linux-privilege-escalation-in-4-lines/): CVE-2026-31431, dubbed Copy Fail, allows privilege escalation to root on Linux distros missing the latest kernel patches. Learn what to do in this blog. - [Bypassing ChatGPT’s Open-Source Model Security Restrictions for Agentic Hacking](https://raxis.com/blog/bypassing-chatgpts-open-source-model-security-restrictions-for-agentic-hacking/): Ryan Chaplin wondered what it would take to bypass ChatGPT’s open-source model security restrictions to allow AI to hack his website. See how he did it here. - [No Malware Required](https://raxis.com/blog/no-malware-required/): The March 2026 attack on Stryker Corporation was not Malware and did not make Ransomware demands. Instead it used compromised credentials to disrupt business. - [Cool Tools Series: SCP](https://raxis.com/blog/cool-tools-series-scp/): Raxis Lead Penetration Tester Nathan Anderson continues our Cool Tool Series with SCP for data exfiltration on internal network pentests and red teams. - [Deepfakes: The Face on Your Screen Might Not Be Real](https://raxis.com/blog/deepfakes-the-face-on-your-screen-might-not-be-real/): Phishing and other social engineering techniques have crossed a threshold with deepfake attacks. Scottie Cole discusses how to protect your organization. - [Smart Slider 3 Pro WordPress/Joomla Plugin Supply Chain Compromise](https://raxis.com/blog/smart-slider-3-pro-wordpress-joomla-plugin-supply-chain-compromise/): Last week's supply chain attack caused many users of the WordPress and Joomla plugin Smart Slider 3 Pro to inadvertently patch to a malicious version. - [Two Critical Telnet Flaws in 2026 Allow Unauthenticated Root Access](https://raxis.com/blog/two-critical-telnet-flaws-in-2026-allow-unauthenticated-root-access/): Lead Penetration Ryan Chaplin explains how to protect your network against CVE-2026-24061 and CVE-2026-32746, two critical Telnet flaws released this year. - [Cool Tools Series: Reptyr](https://raxis.com/blog/cool-tools-series-reptyr/): Jason Taylor brings highlights reptyr in our Cool Tools series, showing how to take a long-running process, like an Nmap scan, and move it to a new screen. - [Raxis at RSAC 2026: A Week Well Spent in San Francisco](https://raxis.com/blog/raxis-at-rsac-2026-a-week-well-spent/): The Raxis team reflects on RSAC 2026 from organizations looking to secure their systems with pentesting to PTaaS and partners looking to secure their customers. - [Five Things to Always Do After Getting Domain Admin](https://raxis.com/blog/five-things-to-always-do-after-getting-domain-admin/): So you got DA on your red team or internal network penetration test. Here are the five things that Principal Penetration Tester Andrew Trexler does next. - [BYOVD Attacks and EDR Evasion: Why Your Endpoint Security May Not Be Enough](https://raxis.com/blog/byovd-attacks-and-edr-evasion-why-your-endpoint-security-may-not-be-enough/): With Reynolds Ransomware in the wild, Brian Tant dives into BYOVD attacks, how they evade enterprise defense like EDRs, and what your organization can do. - [Sponsored Malware: When the Bad Guys Pay for Views](https://raxis.com/blog/sponsored-malware-when-the-bad-guys-pay-for-views/): When a Raxis pentester Jason Taylor found a suspicious sponsored search result, he broke down the code it would have run and discovered it was malware. - [The Hidden Risks in Your Password: What You Type Matters More Than You Think](https://raxis.com/blog/hidden-risks-in-your-password/): Raxis has discovered and cracked our fair share of password hashes. Some that we have discovered may surprise you... and their bosses. Learn what not to do. - [AI-Augmented Series: AI Scripting for Brute-Forcing on a Web App Pentest](https://raxis.com/blog/ai-augmented-series-ai-scripting-for-brute-forcing-on-a-web-app-pentest/): On a recent web app pentest, Andrew Trexler used AI to find client-side code that stopped his brute-force attack then used AI again to thwart that code. - [Wireless Series: The Aircrack-ng Suite for All Your Wireless Pentesting Needs](https://raxis.com/blog/wireless-series-aircrack-ng-for-wireless-pentesting-needs/): Principal Penetration Tester Scottie Cole continues our wireless series with the Aircrack-ng Suite, a set of tools for wireless pentest discovery and exploits. - [Reynolds Ransomware BYOVD Eludes EDR Tools](https://raxis.com/blog/reynolds-ransomware-byovd-eludes-edr-tools/): Reynolds poses a new type of threat by including a Bring Your Own Vulnerable Driver (BYOVD) in the ransomware bundle, making it harder for EDR tools to catch. - [BeyondTrust RCE Vulnerability Exploited: Critical 9.9 CVSS Flaw Under Active Attack](https://raxis.com/blog/beyondtrust-rce-vulnerability-exploited-critical-9-9-cvss-flaw-under-active-attack/): While BeyondTrust patched cloud-hosted Remote Support customers earlier this month, on-premises deployments of BeyondTrust must manually patch to remediate. - [Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice](https://raxis.com/blog/bypassing-waf-and-csp-with-google-tag-manager/): Ryan Chaplin takes an in-depth look at how attackers can use unsafe directives to bypass CSP, notably in Google Tag Manager, and how to remediate the issue. - [CVE-2025-59886 Eaton Exploit Code Published](https://raxis.com/blog/cve-2025-59886-eaton-exploit-code-published/): With exploit code available for the vulnerabilities in Eaton's xComfort Ethernet Communication Interface, Jason Taylor recommends replacing or isolating. ## Pages - [Security Research and Discovered CVEs](https://raxis.com/security-research/): Real Engagements, Real CVEs - [Request Sample Report](https://raxis.com/sample-report/): Check your boxes, add your details, and the full samples land in your inbox within a business day. You'll see the exploits, the storyboards, and the fixes before you ever sign an SOW. No pressure, no obligation. - [PCI & Credit Cards](https://raxis.com/compliance/pci/): Raxis PCI penetration testing is performed by U.S.-based offensive security professionals and delivered through secure Raxis One workflows. For details on our SOC 2 Type II status, data handling, insurance, internal controls, and team credentials, visit the Raxis Trust Center. - [“Top 10 Pentesting Companies” Lists in 2026](https://raxis.com/pentest/top-10-pentesting/): The Penetration Testing buyers guide that isn't a fake Top 10 list - [AI & LLM Penetration Testing Services](https://raxis.com/pentest/ai/): Your AI accepts instructions from anyone. We make sure attackers can't exploit that. - [OT Penetration Testing Services](https://raxis.com/pentest/ot/): Raxis OT penetration testing identifies exploitable vulnerabilities across SCADA, ICS, and industrial networks — without disrupting the operations that keep your business running. - [IoT Penetration Testing](https://raxis.com/pentest/iot/): Raxis IoT penetration testing goes beyond the network. Our engineers physically deconstruct devices, reverse engineer firmware, intercept wireless communications, and probe cloud integrations. - [Trust Center](https://raxis.com/company/trust/): Raxis holds itself to the same security standards we help clients test. This Trust Center summarizes our SOC 2 examination, insurance coverage, secure delivery practices, data handling commitments, supported compliance frameworks, and team credentials. - [Schedule a 30 minute walkthrough](https://raxis.com/schedule/): Book a demo to see how it works during a live pentest: findings arrive as we discover them, and how you can ask the engineers questions while the test is still running. - [Top 10 Cyber Attacks of 2025](https://raxis.com/topten25/): Raxis has released our highly anticipated “Top 10 Cyber Attacks of 2025” report. This comprehensive document provides valuable insights into the most significant cybersecurity threats that impacted organizations and individuals throughout the previous year. - [Penetration Test Quote](https://raxis.com/pentest/quote/): Every organization has different attack surfaces, compliance obligations, and security maturity levels. Share your testing requirements and we’ll provide a detailed quote that explains exactly what we’ll test, how we’ll test it, and what you’ll receive. No obligation, no pressure. Want to discuss via phone? Contact us instead. - [GLBA Safeguards Rule](https://raxis.com/compliance/glba/): The FTC now mandates annual penetration testing. Make sure yours actually protects customer data. - [Raxis | Penetration Testing, PTaaS, Red Team](https://raxis.com/): Raxis is an Atlanta-based penetration testing company trusted by startups and enterprises alike. Our principle is simple: real security comes from real attacks, not automated reports. - [SOC 2](https://raxis.com/compliance/soc2/): Penetration testing that strengthens your security posture, not just your audit binder - [AI vs. Human Penetration Testing](https://raxis.com/pentest/ai-vs-human-pentest/): AI Augmented penetration testing offers deeper insights into threats - [Apply To Work At Raxis](https://raxis.com/company/apply/): Build Your Career in Cybersecurity - [Contact Raxis](https://raxis.com/contact/): Security isn’t a checkbox—it’s a challenge. Every application you deploy, every system you connect, every employee you hire creates new attack vectors. Raxis helps you identify and eliminate vulnerabilities across your entire digital infrastructure. - [Salesforce Penetration Testing](https://raxis.com/pentest/salesforce/): Specialized Penetration Testing for Salesforce Low-Code Applications - [Penetration Testing for Compliance Standards](https://raxis.com/compliance/): Stay ahead of cybersecurity threats and meet compliance standards. - [Sign up for our newsletter](https://raxis.com/signup/): Stay ahead with Popped Culture, the Raxis newsletter that blends cybersecurity insights, breaking industry news, and expert tips to keep you secure. Delivered straight to your inbox, it’s your inside track on all things Raxis and the latest threats shaping the digital world. - [Penetration Testing by Industry](https://raxis.com/industry/): Different industries face different threats. We scope every penetration test to yours. - [Phishing Simulation](https://raxis.com/red-team/phishing/): Phishing penetration testing is a controlled security assessment where ethical hackers attempt to compromise an organization using the same email, voice, and social engineering tactics real attackers use. Unlike automated phishing simulation platforms, a penetration test goes beyond measuring click rates: testers actively exploit harvested credentials to demonstrate real world impact. - [Mobile Application Penetration Testing](https://raxis.com/pentest/mobileapp/): Thoroughly assess your mobile applications to identify potential hidden risks affecting performance and security. - [Wireless Network Penetration Testing](https://raxis.com/pentest/wireless/): Ensure that your wireless networks are properly safeguarded against potential threats from outside attackers and intruders. ## About Raxis Raxis is a penetration testing company founded in Atlanta, Georgia in 2011. Every engagement is performed by senior, certified offensive security engineers based in the United States. The company has discovered and disclosed multiple original CVEs in commercial products during client engagements and internal research. Raxis is not a vulnerability scanning vendor, an MDR provider, or a compliance audit firm. The work is offensive security testing performed by humans, used by organizations that need defensible proof their controls hold up against a real adversary. ## Service Models Raxis delivers penetration testing through two models: - Raxis Strike: point-in-time engagements with defined scope, fixed timeline, and a written report. Used for compliance attestation, annual testing requirements, and targeted assessments. - Raxis Attack: continuous penetration testing as a service (PTaaS) with ongoing access to the testing team, findings, remediation tracking, and retesting through the Raxis One client portal. ## Services Manual penetration testing across external and internal network, web application, API, cloud (AWS, Azure, GCP), red team and adversary simulation, physical, social engineering and phishing, IoT and OT, and AI and LLM applications. ## Leadership - Mark Puckett, Founder and CEO - Bonnie Smyre, Chief Operating Officer - Brian Tant, Chief Technology Officer - Brad Herring, Vice President of Business Development