Saving...

PenTest.WS

Track Hosts & Services
During a CTF or Pentest Lab

Join for Free!

Recon

Import Nmap scans and quickly gain situational awareness during active engagements.

Exploit

Global Service Notes and Custom Command Templates help you find vulnerabilities fast.

Report

Capture screen shots and code snippets as you gain administrative privileges.

PenTest Workshop News

Penetration Testing Workshop News & Announcements

Pro Tier Release

On August 3, 2019

Two years after initial development began on PenTest.WS, today we are officially releasing Pro Tier!

PenTest.WS Pro is an offline stand-alone version of the online web application designed to run directly inside your Kali Linux virtual machine. The Pro Tier was developed for professional penetration testers who must comply with strict non-disclosure agreements or those who operate within a restricted network environment.

Get Pro Tier at store.pentest.ws

All the benefits of the Hobby Tier, plus:

  • Pro Tier Software Updates
  • Offline Stand-Alone Application
  • Two Modes of Operation:
    • Solo Mode
    • Intranet Mode
  • Host Subnetting System
  • Host Filtering System
  • User Maintenance Control Panel

Pro Tier’s subnetting system allows a penetration tester to breakdown a large engagement, maintain scope, and focus on individual segments of a target network.

These subnets can be used in scan templates:

Intranet Mode:

PenTest.WS Pro installed on your intranet server allows your entire team of penetration testers to track hosts, services and record their findings as they work on client engagements.

Solo Mode:

For individual penetration testers, or field work operatives, PenTest.WS Pro runs directly inside your Kali Virtual Machine.

FAQs:

Who owns the application’s data?

You! The PenTest.WS Pro Tier Application maintains a PostgreSQL database stored on the same physical machine or virtual environment as the binary Application. The data contained in this database is the property of the licensee.

[ Read More ]

How do renewals work?

PenTest.WS Pro Tier licenses are purchased on a per-user-per-year basis. The date of first purchase becomes your license anniversary date and the license will be renewed on this date each year.

[ Read More ]

Can I purchase additional licenses?

Additional user licenses may be purchased throughout the year, with each user license sold at a prorated price based on the number of days remaining on your current license.

[ Read More ]

More FAQs can be found at store.pentest.ws

Pro Tier Status Update

On July 17, 2019

At the end of June, we were fortunate enough to engage with some amazing penetration testers who have been reviewing the Pro Tier binary, ecosystem and auto-update mechanisms. Reports have been positive surrounding both the product itself and the security of the environment.

The release window has been a moving target, and a big appreciation must be given to the entire PTWS community for your patience. We’re working towards a release on August 3rd, 2019.

Pricing Announcement

Today we are announcing Pro Tier pricing!

PenTest.WS Pro Tier is priced at $249.00 per user, per year

All the benefits of the Hobby Tier, plus:

  • Pro Tier Software Updates
  • Offline Stand-Alone Application
  • Two Modes of Operation:
    • Solo Mode
    • Intranet Mode
  • Host Subnetting System
  • Host Filtering System
  • User Maintenance Control Panel

As new Pro Tier features are released, free software updates will be available through an in-app update system so you can easily stay up-to-date.

Pro Tier FAQs are now available in the new support system.

New Support System Launched

To better support the PenTest.WS community at all levels, we have launched a new support website:

support.pentest.ws

  • Submit A Ticket
  • Feature Requests
  • General Discussions
  • FAQs
  • Announcements

Support accounts are separate from PTWS accounts, but they’re free! Head on over and submit a Feature Request or be the first to start a thread in the General Discussions section.

Email support is also available at [email protected]

r/PenTestWS Now Open

Today the PenTestWS subreddit went public.

www.reddit.com/r/PenTestWS

Bare bones for the moment. Just another way to keep in touch.

Final Thoughts…

We’re nearly there. Thanks again for the continued patience and encouraging emails received throughout this year long process.

Point Release – v1.5.3

On June 1, 2019

PenTest.WS Pro is just around the corner! Today we’re pushing a small point release to the online version, including both the Free Tier and the Hobby Tier.

Echo Up Goes Base64

Echo Up now uses base64 encoding

One of the first dedicated tools built into PTWS was Echo Up. This tool is used to easily create files through a terminal interface and relies on the echo command. Previously, Echo Up would double encode single quotes and double quotes, and echo the contents line by line into an output file.

Thanks to @4lph4b and the b64chunk.py script, Echo Up is getting new capabilities. More resilient to non-alphanumeric characters, Echo Up now encodes your file into Base64 and uses a series of targeted shell commands to create the file on a remote server.

There are three options: bash, cmd, and Powershell. Each one works slightly differently, but the end result is the same: an exact copy of your file, on the remote server, using nothing but shell commands. You simply copy and paste these commands into your terminal session, no additional ports or protocols needed.

Note: b64chunk.py supports binary files, while the PTWS version currently supports text only.

Venom Builder NOP Sled

Venom Builder NOPs Option

A late addition to this point release, the Venom Builder tool now includes a NOP Sled option.

-n, --nopsled <length&gt; Prepend a nopsled of [length] size

There are a number of options missing from Venom Builder that are available directly through the msfvenom command line. The NOPs option is a great addition and has been requested a few times, and today its here! Keep that feedback coming!

Last, But Not Least – Export Creds

Export credentials tool

Have you captured usernames, passwords, hashes? Need a quick way to password spray a new service login you just discovered? Want to kick-off a hashcat or john-the-ripper session?

Use the Export Creds button to generate a list of every known username, password, hash in your credentials list and a few different mixtures of each.

Each of the sections in the Export Creds tool is useful in different situations. Sometimes its as simple as reporting your findings – “UN:PW”. Other times it can be a little more complicated.

Here’s a short rundown of each section:

  • Usernames: Every known username in your credentials list
  • Passwords: Every known password in your credentials list
  • UN-PW: A simple combination of username:password
  • UN:PW All-U: All permutations of every known username:password, looped around the username
  • UN:PW All-P: All permutations of every known username:password, looped around the password. This mode is best for password spraying to reduce the chance of account lockout with large lists.
  • Uncracked Hashes: Every known hash in your credentials list that does not also have a password. This is ideal for starting a hashcat or john-the-ripper session.
  • UN:Hash All: Every credential record that contains a hash

Note: Export Creds is currently a Host level export and is available on the Host or Port page. Engagement wide credential management is coming in a future release.

PenTest.WS Pro – Status Update

We’re still on track for an end of June release of PenTest.WS Pro. The features are complete and currently being tested. Pricing is nearly settled. Store infrastructure is under heavy development but moving quickly.

We’ll be releasing more information on this blog and Twitter in the weeks ahead. Any unforeseen delays will be announced as soon as possible. Its been a lot of work to get this far, and we’re incredibly excited about the new product.

Thanks for reading, enjoy the new online features, and as always, keep the feedback coming!!