Feldnotizen über offensive Sicherheit, Compliance und das Pentest-Handwerk.
Geschrieben von den Testern, Ingenieuren und Betreibern, die SecureBlock-Engagements durchführen. Ausführlich, gelegentlich, kein Marketing-Füllmaterial.
methodologyphilosophy
Empfohlen
Why we do manual pentesting
Scanners find signatures. Attackers chain business logic. Here's why every SecureBlock engagement is human-led, and why that changes the finding mix.
Marta Kovač 18. Juni 2026 5 min read
Beitrag lesen Alle Beiträge
3 Einträgepricingproduct
How we scope in under two minutes
A discovery call, a scoping spreadsheet, three follow-up emails, and a quote three weeks later. We rebuilt the whole thing as a four-question form. Here's the rubric behind it.
Luka Šikić·27. Mai 2026·6 min read
compliancesoc2
A field guide to SOC 2 evidence packs
The awkward gap between a great pentest report and the evidence your SOC 2 auditor actually wants to see. What we put in the pack, and why.
Mirna Novak·11. April 2026·7 min read

