Sign in

Volkis

@volkis.au
13 followers 8 following 291 posts
PostsRepliesMedia
Volkis @volkis.au · 30/09/2026
When "just one quick exploit before bed" turns into a 1 AM drink-tasting panel.
001
Volkis @volkis.au · 27/09/2026
A successful pentest relies on clear communication and solid environment prep before the first packet hits the wire. Here’s the pre-flight checklist we walk through with clients before hitting "Go"👇
110
Volkis @volkis.au · 24/09/2026
Fresh updates are live on our site, and we couldn't wait to share them with you! We’ve polished up a few things to make finding what you need even easier. Many more changes to come! Check them out 👇
100
Volkis @volkis.au · 20/09/2026
Here's what we pack for physical intrusion tests 🥷
000
Volkis @volkis.au · 16/09/2026
7 years ago, Alexei set out to build a security consultancy grounded in empathy, transparency, and doing things the right way. Thank you for leading us with genuine kindness, passion, and curiosity, and for everything you do for the team. Happy Volkisversary, boss! 🐺
010
Volkis @volkis.au · 11/09/2026
Ever run docker cp to pull logs, build artifacts, or test results out of a container? You might want to double-check your Docker version. Imperva published details on CopyEscape (CVE-2026-17106).
110
Volkis @volkis.au · 10/09/2026
When you book a pentest, the obvious value comes from the consultant digging into your systems. But what does the company behind them bring to the table? Is it just scheduling and an invoice, or does it make the test better? Here's where we reckon a consultancy earns its keep👇
110
Volkis @volkis.au · 08/09/2026
In an engagement, we phished creds, snuck into a public bathroom below their office and hid a device. From that first foothold to complete network control took less effort than the phishing and the sneaking.
101
Volkis @volkis.au · 02/09/2026
Firewalls don't get "broken through." Attackers just make malicious traffic look legit using protocols the firewall already trusts, or slipping through blind spots where it only sees part of the network path.
100
Volkis @volkis.au · 30/08/2026
Happy Birthday to our Senior Security Consultant, Nathan! 🥳 Whether he’s performing network and web app pentests or running security reviews, Nathan brings incredible skill and genuine kindness to everything he does at Volkis.
000
Volkis @volkis.au · 26/08/2026
Wallpapers, T-shirt designs, and other bits with the Volkis wolf on them. We put it all in one spot. 🐺👇
100
Volkis @volkis.au · 24/08/2026
How mature is your Essential 8 actually? Not what the checklist says but what an attacker would find.
100
Volkis @volkis.au · 13/08/2026
Where does "Volkis" come from? True story. Matt and Alexei were brainstorming names while Alexei was in Europe. Matt suggested "Volk," after Alexei's dog. Close, but not quite.
100
Volkis @volkis.au · 10/08/2026
We are honest and transparent with ourselves, our clients, and the wider community. A philosophy at Volkis is to be "open but secure". We make information public by default unless its under NDA, or could be damaging.
000
Volkis @volkis.au · 06/08/2026
We're hearing a lot about how AI-generated pentest reports and hallucinated findings are plaguing our industry. What do we bring? Trust! The words in our reports are our own. Putting our name on it means we stand by every word and present something you can trust.
000
Volkis @volkis.au · 05/08/2026
Happy Birthday to the big boss, Alexei! 🐺 As one of the two founders who made Volkis possible, thank you for inspiring and leading us with kindness and genuine curiosity to give the best of ourselves
000
Volkis @volkis.au · 03/08/2026
We are Volkis. A group of hackers, Australian, independent from the big players, all local. We are dedicated to offensive security. We love it and we do it well.
110
Volkis @volkis.au · 31/07/2026
Anyone else's brain switch on the second the sun goes down?
000
Volkis @volkis.au · 30/07/2026
Meet the operator, Nathan Jarvie, our Senior Security Consultant. He's a hacker with deep hands-on experience, and he's chasing every certification he can get his hands on. 13 certifications in cybersecurity so far, with more on the way.
000
Volkis @volkis.au · 24/07/2026
Avoid this happening. Reach out today 👇
100
Volkis @volkis.au · 20/07/2026
There was a time when companies proudly talked about what they actually stood for. Then "values" just became corporate posters gathering dust in boardroom hallways.
100
Volkis @volkis.au · 17/07/2026
We just moved the Volkis Handbook from v1 to v2. It still publishes everything we do that isn't confidential: methodologies, sample reports, internal policies, hiring guidelines, our AI usage rules. Open but secure since day one.
100
Volkis @volkis.au · 16/07/2026
We put *.volkis.com.au and *.volk.is in scope for anyone who wants to try.
110
Volkis @volkis.au · 14/07/2026
Look, we could hit you with the usual corporate jargon about "synergistic paradigm-shifting cyber resilience", but honestly, we’d rather just do the job properly.
110
Volkis @volkis.au · 09/07/2026
22% of assessed Australian government entities hit Maturity Level 2 across the Essential Eight, and the board reads it as progress.  ML2 measures if the control exists, but not whether they can stop a real attack.
100
Volkis @volkis.au · 08/07/2026
Meet Matthew Strahan, Co-Founder and Managing Director at Volkis. At Volkis, “people first” shows up in the details: how we talks about clients, hiring, learning, remote work, culture, and even security itself.
100
Volkis @volkis.au · 23/06/2026
Meet Alexei Doudkine, Co-Founder and Offensive Director at Volkis. Alexei is one of the reasons the Volkis voice is so direct. The job is to think like a hacker, explain what matters, and help the client get to a better place.
100
Volkis @volkis.au · 22/06/2026
86,644 Fortinet firewalls across 194 countries, compromised with verified working credentials. Banks, hospitals, telecoms, government agencies.
100
Volkis @volkis.au · 18/06/2026
People are your strongest cybersecurity asset. The most powerful security move you can make is to build a culture that normalises good security. Make it normal to question someone's presence in the office, forward a suspicious email to security, lock your screen, etc.
000
Volkis @volkis.au · 11/06/2026
Once an attacker has obtained Domain Admin on a network, DCShadow (aka Rogue Domain Controller) is a neat technique for dumping more information and persisting access.
100
Volkis @volkis.au · 09/06/2026
Here are a few examples of how attackers make phishing domains look convincing. Would you be fooled?
100
Volkis @volkis.au · 04/06/2026
Varonis Threat Labs disclosed "GhostTree", a cool new technique that weaponises NTFS junctions for EDR evasion. By pointing a junction back at its own parent, an attacker creates a directory loop that yields effectively infinite paths: C:\Parent\Child1\Child2\Child1\Child2\...
100
Volkis @volkis.au · 03/06/2026
There are thousands of wordlists available on the internet, but downloading them all blindly is a quick way to run out of storage and waste time.
100
Volkis @volkis.au · 29/05/2026
We published our internal AI usage guidelines. It covers: 🤖 When you should (and shouldn't) use AI with client data 🤖 The acceptable way to use AI for reporting 🤖 Why you shouldn't use AI to communicate with your coworkers
handbook.volkis.com.au
000
Volkis @volkis.au · 26/05/2026
Using AI for hacking is like a using the pokies. You pay tokens for an output, and hope that the output is good. The thing is, if you don't have solid knowledge of hacking, then you don't know whether the output is good. So you still need humans who are good at hacking.
000
Volkis @volkis.au · 25/05/2026
We took our recent Associate Security Consultant hire to shadow an internal pentest earlier this year, and it was the best. Alissa's training paid off on real network! It was pure joy. It brought back to the incredible rush of hacking. I never want to lose the love of hacking. Thanks Alissa!
000
Volkis @volkis.au · 15/05/2026
Back in 2018, when a CVE was released, it took 2.3 years to exploit. 2024: 56 days. Now: 1 day. End of 2026? 1 hour. Reactive approaches to security are no longer effective. If you want expert guidance for the new era, get in touch. www.volkis.com.au/contact
000
Volkis @volkis.au · 22/04/2026
🧪 Volkis Lab Challenge: Command Execution   Drop your payload 🐺
000
Volkis @volkis.au · 20/04/2026
🧪 Volkis Lab: Privilege Escalation   You don’t need exploits when the system hands you the right tool. 🐺 Can you spot it?
000
Volkis @volkis.au · 10/04/2026
Another happy customer review came through today. 😊
000
Volkis @volkis.au · 26/03/2026
In a recent red team engagement, we needed to get close to the target office, which was on the 15th floor of a skyscraper. It was too difficult to get to the elevators without having an ID badge, so we thought about good excuses to have them let us in.
100
Volkis @volkis.au · 20/03/2026
It is common to think an AI agent is safe because it only handles "public" data. But the most dangerous instructions aren't written by developers. They are the "Injected" commands 👇
110
Volkis @volkis.au · 11/03/2026
We did this pentest recently where we got Domain Admin. Cool, but we wanted more! We had the admin's creds so we just waited... When the admin logged out and left for the day, we just logged back in through RDP as him! 👇
100
Volkis @volkis.au · 08/03/2026
🧪 Volkis Lab: This seems suspicious, doesn't it? Sleep → Decode → Decrypt → Runtime API resolution → explorer.exe 🐺 Name the technique. Drop the ATT&CK ID if you know it.👇
000
Volkis @volkis.au · 04/03/2026
Does guessing or brute-forcing passwords still work? Yep! CompanyName123, Monday2026!, Commodore#1... We still see these, and it's often our foothold into a network. 👇
110
Volkis @volkis.au · 03/03/2026
Hackers don’t need fancy tooling anymore, the target system carries it for us. We can "live off the land". Your PowerShell. Your MSHTA. Your CERTUTIL. Your tools, our commands. #HackingTips
000
Volkis @volkis.au · 03/03/2026
🧪 Volkis Lab: Can you recognise it? Bonus: Drop the MITRE ATT&CK ID 👇🐺
000
Volkis @volkis.au · 27/02/2026
Pumping yourself up to write a pentest report on a Friday afternoon 📢 🎵🕺
010
Volkis @volkis.au · 26/02/2026
🧪 Volkis Lab: Got a reverse shell? Don’t rush into recon or privilege escalation.   Raw, fragile access gets you caught. Stabilise it first.  Control before capability. Drop your thoughts 👇🐺
000
Volkis @volkis.au · 24/02/2026
We were on a red team engagement searching through the external infrastructure for a way in.  Struggling for a way in, a junior asked: "What about DNS?" That comment made us zoom out a notch.👇
100