Blog
News and updates from OffSec

Jul 7, 2020
6 min read
Offensive Security AWAE/OSWE Review
In this post Mihai gives us a review of his experience with the Advanced Web Attacks And Exploitation course after obtaining his OSWE certification.

Kali Linux
PowerShell Hacking: Mastering PSSession and Reverse Shells on Kali Linux
In this series, Tony Punturiero (TJ Null) will be showing how to use PowerShell on Kali Linux to obtain initial access with PSSession on Windows and Linux.
Jun 30, 2020
10 min read

Web App Security
Offensive Security Advanced Web Attacks and Exploitation (AWAE): What You Need To Know
What do you need to know before taking Advanced Web Attacks and Exploitation (AWAE)? OSCP holder and penetration tester Samuel Whang shares his perspective.
Jun 16, 2020
4 min read

Research & Tutorials
AMFI syscall
Csaba Fitzl covers the `dyld` restriction decision process in macOS and a previously undiscussed or undocumented AMFI (AppleMobileFileIntegrity) system call.
Jun 9, 2020
10 min read

OffSec News
Offensive Security PWK 2020 Update: Should you upgrade?
OSCP holder Samuel Whang shares his perspective on why upgrading to the 2020 materials is worth it for those who have already completed PWK.
May 19, 2020
3 min read

Research & Tutorials
macOS Kernel Debugging with SIP
As security researchers, we often find ourselves needing to look deep into various kernels to fully understand our target and accomplish our goals. Doing so on the Windows platform is no mystery, as there have been countless well-written posts about kernel debugging setups. For macOS, however, the situation is slightly different. There are many great
May 12, 2020
9 min read

OffSec News
Exploit Database SearchSploit Update
To help search the local copy of Exploit DB, we created “SearchSploit“, which gives you a powerful command line interface to perform detailed queries. SearchSploit has recently been updated. Let’s review the update and the benefits.
May 5, 2020
2 min read

Web App Security
White Box Testing for Web Applications
How can source code review help penetration testers with web application security assessments? Learn the benefits of white box web app penetration testing.
Apr 28, 2020
0
Community Spotlight
The AWAE/OSWE Journey: A Review
Donavan Cheah gives us some of his thoughts on the subject of penetration testing, and his journey with the AWAE course in particular.
Apr 14, 2020
10 min read

Kali Linux
Customizing Kali Linux
One of the designers on the Kali Linux team shares his top tips and tools to customize Kali Linux. Dig in under the hood with Daniel Ruiz de Alegría.
Mar 31, 2020
12 min read

Web App Security
Attacking the Web: The Offensive Security Way
OffSec student 0xklaue wrote this review of Advanced Web Attacks and Exploitation and the OSWE exam. Find out how to prepare and what you need to know.
Mar 24, 2020
8 min read

Enterprise Security
Playbook for Running a Global Work-from-Home Company
With people located in over 24 countries, we’ve been working from our homes since our founding in 2006. Here’s five tips on how to run a distributed team effectively.
Mar 17, 2020
11 min read

Insights
Information Security Training Paths at OffSec
Find out where to start with OffSec’s information security training courses. We outline our learning paths to certification and career development.
Mar 12, 2020
7 min read
Join the OffSec Community!
Our community members connect, communicate and collaborate on all things cybersecurity.