We have created the #Hackcraft Discord community, where we can share #redteam and #pentest tips and discuss about open-source releases. You can also seek help or contribute on our own open-source software. Join us: https://t.co/l2vqPQxoJh
The business value of a password cracking assessment?
🔍 Identify weak passwords across users, apps & systems
📊 Measure password hygiene & credential attack exposure
🛡️ Improve defenses against spraying, stuffing, brute force & lateral movement
✅ Develop remediation plans
Be proactive and build a Mythos-ready mindset.
Insights by @RoadRunnerHacks, Head of Hackcraft.
👉Stay tuned for more tips on offensive security and tips for business growth!
When Fairplay was first released, the focus was clear: to help Red Teams.
⚡Here you have the newest features we added, with an emphasis on operational convenience: a web dashboard, a dedicated API layer and more.
https://t.co/pEvlnoDxJo
#RedTeaming
📌AI Act Compliance for trust
📌AI Security Architecture for secure scalability
📌Cyber readiness -through real-world threat scenarios to target your AI assets- for confidence.
That’s what we explored during our recent exclusive event on securing intelligent systems.
#AI
If we had to describe the past two months in one phrase? Security chaos, accelerated by AI.🤖
Dive into the stories that stood out over the last two months and what they mean for you, plus blogs + tools worth your time.
👉https://t.co/vDYLkVji3b
#cybersecurity
Access to Mythos-style defense is limited.
For attackers, it’s not. Open tools and custom frameworks already exist.
So what now?
Build a Mythos-ready mindset:
🔸Know your real gaps
🔸Continuously validate defenses
🔸Simulate real attacks
#CyberSecurity#AI
What about Mythos? Not just a tool but an approach. Adopted by Anthropic, it shifts from isolated CVEs to interconnected risk mapping, prioritizing vulnerabilities based on exploitability, context, and how they connect across your ecosystem.
#CyberSecurity#AI
👓 Need a hacking homework during the Easter holidays? Hackcraft is always by your side.
“Race Conditions and Where to Find Them”
🔎 Research and analysis by @ThemisZoub, Hackcraft’s Senior Cybersecurity Tester.
#cybersecurity#ethicalhacking
https://t.co/O2LaqTEnOG
The real question about #ransomware? Would you detect & contain it in time?
Not ready for full Red Teaming?
🔐Ransomware Simulation tests real-world resilience: detection, response, coordination & recovery.
Validate resilience against one of today’s most disruptive threats.
A pen test is one of the most effective ways to evaluate your organization’s security posture, but its effectiveness depends on its scope. Too broad? You waste budget. Too narrow? You miss critical risk. The key question? “Are we testing systems or are we testing business risk?”
"Can we validate credential weaknesses without a full Red Teaming?"
Hackcraft’s Password Cracking Assessment evaluates users' password strength & provides statistics on your resilience against password spraying.
Ready to test your identities?
https://t.co/2ZAIiM7pmS
⚠️During a #ransomware attack, plans that work on paper often fail in practice.
✔️Hackcraft's Ransomware Simulation replicates real attacks to turn assumptions into measurable improvements before attackers do.
Ready to test your defenses?
"How do we validate defenses without a full Red Teaming?"
Budgets and maturity vary. Attackers don’t.
Hackcraft’s Workstation Defense Evaluation tests endpoint detection & response against real threats.
Validation beats assumption.
Ready to test yours? https://t.co/2ZAIiM7pmS
💡While Burp Suite provides session handling rules & macros, our team needed a faster, simpler & flexible approach. The Token Auto-Refresher extension was born from this need.
#penetrationtesting
https://t.co/OOgYU1KeUU
👋Hello world!
This is Hackcraft’s Team Newsletter, aka our official excuse to share what we’ve been researching, noticing, debating and bookmarking obsessively over the past two months.
Dive deeper.👇 https://t.co/Ape0q7fWYV
💡#RedTeaming , penetration testing, assume breach, social engineering & tabletop exercises serve different purposes.
Choosing the wrong one, or the right one at the wrong time, can leave real risks untested.
🤿 Deep dive: https://t.co/oYcSBBXGFy
Hey hackers 👋
Kicking off the year with research. Our team member NeCro (aka Giannis Christodoulakos) shares an interesting finding from a deep dive into MSSQL Server hacking via the TDS protocol.
Enjoy 🍹
#ServerHacking#Cybersecurity
https://t.co/Ghlquwvena
🎅You may be AFK, but our hackers never are. The only breach we allow in your systems is that of Christmas spirit.🎄🔐
Stay tuned for more research, TTPs & blog posts. 🎋
#RedTeam#PenTesting#CyberResilience#HolidaySeason
When Your Server Secretly Starts #Mining Monero🤕 Here is a real-world example of how silent infrastructure compromise actually looks 😅
https://t.co/3rWboDP48b
#Hacking#CyberSecurity
What should your organization choose?
🎭 Phishing = awareness training, testing staff reactions to suspicious emails/calls
🔴 Red Teaming = full‑scope attack simulation, testing resilience & response
👉 Choose based on maturity, risk & priorities.