Tagged: Reconnaissance
4 posts · browse all tags
-
Five Minutes and an Empty Port Part 1: A Field Guide to Network Implant Hardware, and Why This Still Works
Opening a series on the pocket-sized hardware that turns thirty seconds of physical access into a foothold: a history of the category, a threat model for why it still works in 2026, and a taxonomy of the three tool families this series covers before it turns to defense.
-
Five Minutes and an Empty Port Part 2: Shark Jack, Packet Squirrel, and LAN Turtle
The three purpose-built Hak5 wired implants compared on what they actually do between plug-in and pull-out: Shark Jack's quick-strike recon and exfil, Packet Squirrel's inline man-in-the-middle, and LAN Turtle's long-term covert remote access.
-
BloodHound Deep Dive Part 2: SharpHound and What It Actually Collects
SharpHound's real collection methods, the Stealth flag's documented behavior, and what a DCOnly run against CONTOSO.LOCAL would and wouldn't surface, taken from SpecterOps' own flag reference rather than guessed.
-
Sn1per Deep Dive Part 1: From Recon Script to Attack Surface Platform
Sn1per orchestrates 90+ tools into one scan. This opens a new series on how it actually works, verified from the real Community Edition source rather than the marketing page.