Guide

Pentest, Red Team, Scan, SOC 2, ISO 27001 — What's Actually What

Reference guide PentestSA Team

Testing activities and compliance frameworks get talked about as if they're the same thing. They're not. A plain-English guide to scanning, pentesting and red teaming — and to SOC 2, ISO 27001, PCI DSS, POPIA and Joint Standard 2 — so you know exactly what your client or bank is asking for...

Read the Guide →
8-Part Series

The Hacker's Arsenal: Beginner's Guide to Web Security

January 2025 PentestSA Team

A comprehensive 8-part series taking you from zero to hacker. Learn XSS, SQL Injection, authentication attacks, session hijacking, CSRF, and more with hands-on labs...

View Series →
OWASP #1

Broken Access Control: The #1 Web Security Risk

January 2025 PentestSA Team

IDOR vulnerabilities, privilege escalation, and the Optus breach case study. Learn how broken access control became the most critical web vulnerability...

Read More →
OWASP #3

Injection Attacks: SQL, Command, and Beyond

January 2025 PentestSA Team

SQL injection, command injection, NoSQL injection, and SSTI. From SQLMap automation to the MOVEit breach - master injection vulnerabilities...

Read More →
Web Security

Understanding CSP from a Hacker's Point of View

January 2025 PentestSA Team

A deep dive into Content Security Policy from an attacker's perspective. Learn how CSP works, the dangers of not having it, common misconfigurations, and bypass techniques used by penetration testers...

Read More →