Penetration testing has traditionally been treated as a point in time exercise centered on identifying and exploiting vulnerabilities. While severity charts and baseline reporting are standard, they often fall short in giving executives the context required for strategic decision making. This article introduces two powerful yet straightforward enhancements, remediation effort mapping and threat model context graphs. Both of these elevate reports into holistic snapshots of an organization’s security posture. By reframing deliverables in this way, penetration testing shifts from a checklist of vulnerabilities and exploits, to a source of leadership insight, enabling more informed, timely, and impactful decisions.
Category: Penetration Testing
Trap Shooter – Flock Safety Sniffer & Alarm
Custom firmware for the M5NanoC6 (ESP32-C6) that sniffs and then alerts you of nearby Flock Safety devices. Will be integrated into a exploit tool releasing on 09/27/25 for Flock Safety devices!
GainSec in the Middle!
Implementation of Man-in-the-Middle (MiTM) Router / Access Point (AP). Great for embedded, IoT, hardware or similar penetration tests, hacks or research. Creates all interfaces and configurations on the fly, integrates other functionality to make TLS stripping, Android use or Burp Suite use more streamlined.
Unbricking and Flashing the Yardstick One
Bricked your Yardstick One? This step-by-step guide shows how to recover it using its cousin, the GreatFET, by erasing, flashing, and verifying full Sub 1 GHz sniffer functionality.
The quickest and simplest guide to spinning up a powerful local AI stack. Part 7 – Current Stack – Docker Deploy
Going to keep this post extremely brief. I have published the current stack and how to spin it up yourself on my GitHub. Next Part will be implementing Local Agentic RAG with Crawl4AI! Check out the repo HERE
The quickest and simplest guide to spinning up a powerful local AI stack. Part 6 – Open-WebUI To Crawl4AI – Chat
Step by Step instructions on how to Integrate Crawl4AI as a tool within Open-WebUI to be used by any model.
The quickest and simplest guide to spinning up a powerful local AI stack. Part 3 – Image Generation via Stable Diffusion
So as this is the first part that integrates things that aren't included out of the box, I'm going to build these parts out separately and then at the end I'll release my full docker-compose.yml which will have all the pieces. With that in mind, lets get started. First you should go to your users … Continue reading The quickest and simplest guide to spinning up a powerful local AI stack. Part 3 – Image Generation via Stable Diffusion
How to generate *VALID* TLS Certificates that are *NOT* self-signed for internal only services.
Step by step instructions on how to easily use Caddy and Cloudflare to generate valid TLS certificates on the fly for services only exposed internally. No self-signing, importing CAs, cleartext HTTP, browser warnings or hassle ever again!
Complete Install Guide of Kali NetHunter on Nexus 6P – 2025
Simple and clear installation instructions to install Kali NetHunter onto a Nexus 6P (Angler) running Android 8.1 (Oreo).
Using a Nexus 6P and QCSuper to Sniff LTE.
Step by step instructions on how to setup and configure a Nexus 6P to sniff portions of the LTE wireless stack.






