The Coalfire Labs Blog

Welcome to the Coalfire Labs Blog, a resource covering the most important issues in IT security and compliance.  The Coalfire Labs blog is written by the company's leadership team and our highly-credentialed security assessment experts.


  • Getting the Most Value Out of Your Phishing Program

    June 27, 2017, Ryan MacDougall, Sr. Security Consultant

    Are your phishing tests worth the money you are spending on them?

    Please don't misinterpret that as suggesting you shouldn't be testing your users. To the contrary, I think you should be testing all your users (executives of all ranks included) on a regular basis. What I mean by that question is; are you really "testing" your users, or are you merely spot quizzing them?

  • IT Security Horror Story: Digging your own grave with Default Credentials

    October 29, 2014, Mark Manousogianis, Information Security Consultant, Coalfire Labs

    I recently performed a penetration test that really required no “hacking skills” whatsoever. I was able to obtain domain administrator rights simply by logging into web applications and network hardware using default credentials.

  • IT Security Horror Story: Slow Network, Big Phish

    October 29, 2014, Mark Manousogianis, Information Security Consultant, Coalfire Labs

    It was a typical morning, just like any other for Annie. She arrived at the office just in time to fill her coffee mug and get to her desk to read her email that had been piling up since Friday. After reading through the standard office wide emails she came across one from the help desk.

Top