Volkis

@volkis.au

We're hearing a lot about how AI-generated pentest reports and hallucinated findings are plaguing our industry. What do we bring? Trust! The words in our reports are our own. Putting our name on it means we stand by every word and present something you can trust.

Happy Birthday to the big boss, Alexei! 🐺 As one of the two founders who made Volkis possible, thank you for inspiring and leading us with kindness and genuine curiosity to give the best of ourselves

Bild

We are Volkis. A group of hackers, Australian, independent from the big players, all local. We are dedicated to offensive security. We love it and we do it well.

Bild

Meet the operator, Nathan Jarvie, our Senior Security Consultant. He's a hacker with deep hands-on experience, and he's chasing every certification he can get his hands on. 13 certifications in cybersecurity so far, with more on the way.

Bild

There was a time when companies proudly talked about what they actually stood for. Then "values" just became corporate posters gathering dust in boardroom hallways.

Bild

We just moved the Volkis Handbook from v1 to v2. It still publishes everything we do that isn't confidential: methodologies, sample reports, internal policies, hiring guidelines, our AI usage rules. Open but secure since day one.

Look, we could hit you with the usual corporate jargon about "synergistic paradigm-shifting cyber resilience", but honestly, we’d rather just do the job properly.

Bild

22% of assessed Australian government entities hit Maturity Level 2 across the Essential Eight, and the board reads it as progress.  ML2 measures if the control exists, but not whether they can stop a real attack.

Bild

Meet Matthew Strahan, Co-Founder and Managing Director at Volkis. At Volkis, “people first” shows up in the details: how we talks about clients, hiring, learning, remote work, culture, and even security itself.

Bild

Meet Alexei Doudkine, Co-Founder and Offensive Director at Volkis. Alexei is one of the reasons the Volkis voice is so direct. The job is to think like a hacker, explain what matters, and help the client get to a better place.

Bild

86,644 Fortinet firewalls across 194 countries, compromised with verified working credentials. Banks, hospitals, telecoms, government agencies.

Bild

People are your strongest cybersecurity asset. The most powerful security move you can make is to build a culture that normalises good security. Make it normal to question someone's presence in the office, forward a suspicious email to security, lock your screen, etc.

Bild

Once an attacker has obtained Domain Admin on a network, DCShadow (aka Rogue Domain Controller) is a neat technique for dumping more information and persisting access.

Varonis Threat Labs disclosed "GhostTree", a cool new technique that weaponises NTFS junctions for EDR evasion. By pointing a junction back at its own parent, an attacker creates a directory loop that yields effectively infinite paths: C:\Parent\Child1\Child2\Child1\Child2\...

There are thousands of wordlists available on the internet, but downloading them all blindly is a quick way to run out of storage and waste time.

Bild

We published our internal AI usage guidelines. It covers: 🤖 When you should (and shouldn't) use AI with client data 🤖 The acceptable way to use AI for reporting 🤖 Why you shouldn't use AI to communicate with your coworkers

handbook.volkis.com.au

Using AI for hacking is like a using the pokies. You pay tokens for an output, and hope that the output is good. The thing is, if you don't have solid knowledge of hacking, then you don't know whether the output is good. So you still need humans who are good at hacking.

We took our recent Associate Security Consultant hire to shadow an internal pentest earlier this year, and it was the best. Alissa's training paid off on real network! It was pure joy. It brought back to the incredible rush of hacking. I never want to lose the love of hacking. Thanks Alissa!

🧪 Volkis Lab: Privilege Escalation   You don’t need exploits when the system hands you the right tool. 🐺 Can you spot it?

Bild

In a recent red team engagement, we needed to get close to the target office, which was on the 15th floor of a skyscraper. It was too difficult to get to the elevators without having an ID badge, so we thought about good excuses to have them let us in.

It is common to think an AI agent is safe because it only handles "public" data. But the most dangerous instructions aren't written by developers. They are the "Injected" commands 👇

We did this pentest recently where we got Domain Admin. Cool, but we wanted more! We had the admin's creds so we just waited... When the admin logged out and left for the day, we just logged back in through RDP as him! 👇

Bild

🧪 Volkis Lab: This seems suspicious, doesn't it? Sleep → Decode → Decrypt → Runtime API resolution → explorer.exe 🐺 Name the technique. Drop the ATT&CK ID if you know it.👇

Bild