Pentester Diaries

Follow Pentester Diaries
Share on
Copy link to clipboard

Welcome to Pentester Diaries, a new podcast series that shines a light on the – not so secret, somewhat anonymized, and at times glamorized life of offensive security professionals. In this series, we will gather pentesters from across the globe to learn

Pentester Diaries


    • Aug 25, 2022 LATEST EPISODE
    • infrequent NEW EPISODES
    • 33m AVG DURATION
    • 11 EPISODES


    Search for episodes from Pentester Diaries with a specific topic:

    Latest episodes from Pentester Diaries

    Pentester Diaries: Full-time Freelance Pentesting

    Play Episode Listen Later Aug 25, 2022 21:08


    This episode of Pentester Diaries is all about full-time freelance pentesting. I sat down with Core Pentesters Harsh Bothra and Parveen Yadav to talk about their lives as full-time freelancers. 

    Pentester Diaries Ep.10: Journey into Reverse Engineering and Exploit Develpment

    Play Episode Listen Later Nov 30, 2021 28:53


    In this episode of Pentester Diaries, we sit down with a vetted Cobalt Core Pentester - Andreea Durga! This podcast includes insights on Andreea's journey into Reverse Engineering and Exploit Development.  Follow Andreea's work here: https://www.linkedin.com/in/andreea-cristina

    Pentester Diaries Ep.9: Certifications with Heath Adams

    Play Episode Listen Later Oct 8, 2021 30:20


    In this edition of Pentest Diaries, we had the opportunity to sit down with the founder of TCM Security, Heath Adams! We wanted to chat about the evolving state of the pentesting job market and the role certifications play within that system. TCM Security has amassed 200k students and issued 675 vouchers in a short period of time. We'd like to know more about their impact as new entrants to the certification and education space. Follow Heath's work here:https://twitter.com/thecybermentorhttps://linktr.ee/thecybermentor

    Android Pentesting

    Play Episode Listen Later Sep 2, 2021 51:57


    In this edition of Pentest Diaries, we had the opportunity to sit down with three of our distinguished Core members to talk Android Pentesting: https://twitter.com/harshbothra_https://twitter.com/pcastagnarohttps://twitter.com/b0rn2pwn1:00 What's your opening move when starting a pentest?6:00 What tools are they using?  11:00 Out of Static, Dynamic, API testing, which takes the majority of your time? 18:14 What are some of the blockers you discover in Android pentesting? 26:55 What sort of exploit chains have you personally found? 34:44 Is there a place to learn more about exploit chaining for Android?36:55 Takes on Windows 11 running Android native applications. 43:12 Why is Android pentesting important?Listen to the whole podcast to get the most out of the Core's amazing takes on this subject. 

    Tips for Communicating with Customers

    Play Episode Listen Later Aug 9, 2021 29:43 Transcription Available


    Welcome back to Pentester Diaries. In this episode, Cobalt's Grahame Turner interviews Core pentester Stefan Nicula on customer communications. Exploring the importance of transparency, alignment, and empathy.  Guests:https://twitter.com/TheInstaGrahame https://twitter.com/stefan_niculaResources:SlackMicrosoft Teams

    The Importance of Report Writing

    Play Episode Play 27 sec Highlight Listen Later Jun 22, 2021 31:18 Transcription Available


    Welcome back to Pentester Diaries In this episode, longtime Core member and Cobalt Research Manager, Robert Kugler talks with Grahame Turner, an experienced security technical writer, about report writing, why it's important, and tips on how to improve your writing as a pentester.  Guests: https://twitter.com/robertchrkhttps://twitter.com/TheInstaGrahameResources:https://portswigger.net/burphttps://cheatsheetseries.owasp.org/https://developers.google.com/style/voicehttps://communicatehealth.com/wehearthealthliteracy/use-zombies-to-fight-the-passive-voice/https://www.mindmeister.com/http://textfiles.com/

    Understanding Severity Ratings

    Play Episode Play 21 sec Highlight Listen Later May 26, 2021 25:30 Transcription Available


    Welcome back to Pentester Diaries, a podcast series that aims to take off the hacker hoodie and have a real conversation about this growing profession. In this episode, Jon Helmus talks with Joan Bono, a long-time Cobalt Core pentester. They will take a look at understanding pentest severity ratings.Guests:https://twitter.com/Moos1e_Moosehttps://twitter.com/joan_bonoResources:https://cobalt.io/blog/understanding-the-cvss-base-score-an-essential-guidehttps://nvd.nist.gov/vuln-metrics/cvss/v3-calculatorhttps://portswigger.net/web-security/cross-site-scripting/reflectedhttps://jquery.com/

    Beyond Security Hygiene

    Play Episode Play 19 sec Highlight Listen Later May 11, 2021 33:00 Transcription Available


    In this episode, Jon Helmus talks with Shashank Dixit, a long-time cybersecurity professional with a love for the offensive side of security. Jon and Shashank will talk about Beyond Security Hygiene, diving into the fundamentals, and more.Guests:https://twitter.com/shashankdixitshttps://twitter.com/Moos1e_MooseResources:https://inservice.sumeru.com/cyber-security/https://www.virtualbox.org/https://www.iso.org/isoiec-27001-information-security.htmlhttps://owasp.org/www-project-top-ten/

    Time Management & Pentest Organization

    Play Episode Play 33 sec Highlight Listen Later Apr 16, 2021 40:44 Transcription Available


    In this episode, Jon Helmus talks with Matt Buzanowski, a longtime offensive security professional who has done everything from Red Teaming, mobile, physical pentesting, social engineering, and more. Jon and Matt talk about two important concepts related to pentesting: time management and pentest organization.Guests:https://twitter.com/mateusz_jozef https://twitter.com/Moos1e_Moose Resources: https://www.defcon.org/ https://www.blackhat.com/https://grayhat.co/https://owasp.org/www-project-web-security-testing-guide/https://trello.com/enhttps://www.securityinfowatch.com/cybersecurity/information-security/article/21211106/how-to-set-yourself-up-for-cyber-success

    2FA Bypass Techniques

    Play Episode Play 43 sec Highlight Listen Later Mar 29, 2021 30:28 Transcription Available


    In this episode, Jon Helmus speaks with Harsh Bothra, a pentester with an appetite for learning and sharing his knowledge. In this episode, they'll examine Multi-Factor Authentication.Guests: https://twitter.com/harshbothra_ https://twitter.com/Moos1e_MooseResources:- https://harshbothra.tech/- https://hbothra22.medium.com/- https://blog.cobalt.io/bypassing-the-protections-mfa-bypass-techniques-for-the-win-8ef6215de6ab?source=friends_link&sk=bfd8bbbbbfe884f7e6016d4bf79e3034- https://www.mindmeister.com/1736437018?t=SEeZOmvt01

    Understanding Business Logic

    Play Episode Play 29 sec Highlight Listen Later Mar 10, 2021 39:56


    For our first episode,  Jon Helmus talks with Dan Beavin. A pentester with a passion for applying his architect background to security. In this episode, they will dig into business logic. Exploring the importance of understanding every aspect of an application before pentesting.Guests:https://twitter.com/danbeavinhttps://twitter.com/Moos1e_MooseResources mentioned:https://portswigger.net/burphttps://portswigger.net/burp/documentation/desktop/tools/intruder/usinghttps://portswigger.net/bappstore/f9bbac8c4acf4aefa4d7dc92a991af2f

    Claim Pentester Diaries

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel