logo

Pentesting in the spotlight – a view

ID: b849499d-8ba9-5e62-9096-df95733440a2

STIX ID: report--b849499d-8ba9-5e62-9096-df95733440a2

Feed Name: SensePost Blog

Date Published: 2012-05-07

Date Updated: 2026-04-29

...
...

This piece critiques narrow, attack-focused penetration testing by reflecting on Haroon Meer’s talk and argues that pen testing is only one phase within broader security assessment. It highlights how 0-day capabilities distort outcomes and proposes using '0-day cards' to emulate such advantages, while recommending enterprise-wide threat modeling to enumerate, prioritize, and test risks systematically as part of an iterative, business-aligned risk management process.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.