Blog
News and updates from OffSec

Jul 20, 2020
AWAE Frequently Asked Questions
The Advanced Web Attacks and Exploitation (AWAE) course has been updated for 2020. Get your questions about AWAE and OSWE answered.
Categories

Web App Security
AWAE: Updated with More Content for 2020
The Advanced Web Attacks and Exploitation (AWAE) course has been updated for 2020. Learn what changed, why we did it, and how it will help you.
Jul 14, 2020
3 min read

Web App Security
Offensive Security AWAE/OSWE Review
In this post Mihai gives us a review of his experience with the Advanced Web Attacks And Exploitation course after obtaining his OSWE certification.
Jul 7, 2020
6 min read

Kali Linux
PowerShell Hacking: Mastering PSSession and Reverse Shells on Kali Linux
In this series, Tony Punturiero (TJ Null) will be showing how to use PowerShell on Kali Linux to obtain initial access with PSSession on Windows and Linux.
Jun 30, 2020
10 min read

Web App Security
Offensive Security Advanced Web Attacks and Exploitation (AWAE): What You Need To Know
What do you need to know before taking Advanced Web Attacks and Exploitation (AWAE)? OSCP holder and penetration tester Samuel Whang shares his perspective.
Jun 16, 2020
4 min read

Research & Tutorials
AMFI syscall
Csaba Fitzl covers the `dyld` restriction decision process in macOS and a previously undiscussed or undocumented AMFI (AppleMobileFileIntegrity) system call.
Jun 9, 2020
10 min read

OffSec News
Offensive Security PWK 2020 Update: Should you upgrade?
OSCP holder Samuel Whang shares his perspective on why upgrading to the 2020 materials is worth it for those who have already completed PWK.
May 19, 2020
3 min read

Research & Tutorials
macOS Kernel Debugging with SIP
As security researchers, we often find ourselves needing to look deep into various kernels to fully understand our target and accomplish our goals. Doing so on the Windows platform is no mystery, as there have been countless well-written posts about kernel debugging setups. For macOS, however, the situation is slightly different. There are many great
May 12, 2020
9 min read

OffSec News
Exploit Database SearchSploit Update
To help search the local copy of Exploit DB, we created “SearchSploit“, which gives you a powerful command line interface to perform detailed queries. SearchSploit has recently been updated. Let’s review the update and the benefits.
May 5, 2020
2 min read

Web App Security
White Box Testing for Web Applications
How can source code review help penetration testers with web application security assessments? Learn the benefits of white box web app penetration testing.
Apr 28, 2020

Community Spotlight
The AWAE/OSWE Journey: A Review
Donavan Cheah gives us some of his thoughts on the subject of penetration testing, and his journey with the AWAE course in particular.
Apr 14, 2020
10 min read

Kali Linux
Customizing Kali Linux
One of the designers on the Kali Linux team shares his top tips and tools to customize Kali Linux. Dig in under the hood with Daniel Ruiz de Alegría.
Mar 31, 2020
12 min read

Web App Security
Attacking the Web: The Offensive Security Way
OffSec student 0xklaue wrote this review of Advanced Web Attacks and Exploitation and the OSWE exam. Find out how to prepare and what you need to know.
Mar 24, 2020
8 min read
Join the OffSec Community!
Our community members connect, communicate and collaborate on all things cybersecurity.