Tagged: Pentesting
12 posts · browse all tags
-
Old Kit, New Kit Part 12: The Verdict
All ten pairs, pulled together — the scoreboard, the nine findings that kept recurring across posts, the lab-build lessons that never made a single pair post, and the actual verdict: detection depends on configuration, not on which decade wrote the tool.
-
Old Kit, New Kit Part 11: AD Enumeration, BloodHound and Certipy vs ldapsearch and net
Enumerating a fresh Active Directory domain two ways — ldapsearch and net rpc against bloodhound-python and certipy-ad — including a full ESC1 certificate exploit, and checking what each one actually leaves in Wazuh.
-
Old Kit, New Kit Part 10: Remote Access, evil-winrm vs psexec and Manual RDP
Running psexec, manual RDP, and evil-winrm against the same weak local admin credential on target-win2022, and checking what each one actually leaves in Wazuh.
-
Old Kit, New Kit Part 9: Pivoting — Chisel vs ssh -D / socat
Two classic pivoting options cost wildly different amounts to actually deploy on Windows, chisel gets caught and quarantined by name the moment it touches disk — and the SIEM watching the pivot host misses all of it, including the one thing that actually got caught.
-
Old Kit, New Kit Part 8: Web Screenshotting — Gowitness vs Manual Screenshotting
A real 22x speedup and free structured metadata from gowitness's batch scanning against one-target-at-a-time manual headless screenshots — plus the series' first genuinely quiet, zero-alert pair since Part 4.
-
Old Kit, New Kit Part 7: SMB Enumeration — NetExec vs Enum4linux and Smbclient
NetExec against enum4linux and smbclient for real SMB enumeration on a legacy Samba box and a hardened Windows Server 2022 host — the first Windows-agent Wazuh detection results in the series, and a genuine split decision between the two tools.
-
Old Kit, New Kit Part 6: Vulnerability Scanning — Nuclei vs Nmap's Vulnerability Scripts
Nuclei's active-check templates against nmap's vulners-driven --script vuln, run for real against a lab metasploitable2 box and two Wazuh-monitored targets — plus the richest, most diverse Wazuh alert haul this series has produced yet.
-
Old Kit, New Kit Part 5: Content and Parameter Discovery — Feroxbuster and Ffuf vs Dirb and Gobuster
The first pair in the series with a real, unmissable Wazuh alert footprint — plus a real leaked ops file and a live directory-listing misconfig that only feroxbuster's crawling behaviour actually found.
-
Old Kit, New Kit Part 4: Service and Tech Fingerprinting — Httpx-Toolkit and Naabu vs Nmap -sV and Whatweb
This pair splits down the middle: naabu is 25-30x slower than nmap without root privileges, while httpx-toolkit clearly beats whatweb on speed, detail, and even leaves a quieter log trace doing it.
-
Old Kit, New Kit Part 3: Subdomain and DNS Recon — Amass and Dnsx vs Whois, Dig, theHarvester, and Sublist3r
Sublist3r crashes outright on current Python, amass needs a CLI correction pass and downloads 58MB unannounced, and once both actually run, they agree completely: there was nothing more to find.
-
Old Kit, New Kit Part 2: Port and Service Discovery — Rustscan vs Nmap
Rustscan's async port sweep is genuinely near-instant, but the moment a real workflow asks for service versions, it hands straight off to nmap — and that handoff is where the marketed speed advantage quietly disappears.
-
Old Kit, New Kit Part 1: Introduction
Ten classic-vs-modern pentest tool pairs, one real isolated lab, one genuine Wazuh SIEM watching — every run, every timing figure, every log line real. This is the series intro, written last, once there were real findings to introduce.