关于攻击性安全、合规和渗透测试技艺的现场笔记。
由执行SecureBlock参与的测试员、工程师和运营人员撰写。长篇,定期,无营销填充内容。
methodologyphilosophy
精选
Why we do manual pentesting
Scanners find signatures. Attackers chain business logic. Here's why every SecureBlock engagement is human-led, and why that changes the finding mix.
Marta Kovač 2026年6月18日 5 min read
阅读文章 所有文章
3 篇文章pricingproduct
How we scope in under two minutes
A discovery call, a scoping spreadsheet, three follow-up emails, and a quote three weeks later. We rebuilt the whole thing as a four-question form. Here's the rubric behind it.
Luka Šikić·2026年5月27日·6 min read
compliancesoc2
A field guide to SOC 2 evidence packs
The awkward gap between a great pentest report and the evidence your SOC 2 auditor actually wants to see. What we put in the pack, and why.
Mirna Novak·2026年4月11日·7 min read

