Sign in

Volkis

@volkis.au
13 followers 8 following 293 posts
PostsRepliesMedia
Volkis @volkis.au · 03/10/2026
Curious about what our pentest reports actually look like? 📄 Thanks to some awesome clients, we've published real, sanitised sample reports so you can see exactly how we document findings and remediation.👇
100
Volkis @volkis.au · 30/09/2026
When "just one quick exploit before bed" turns into a 1 AM drink-tasting panel.
001
Volkis @volkis.au · 27/09/2026
A successful pentest relies on clear communication and solid environment prep before the first packet hits the wire. Here’s the pre-flight checklist we walk through with clients before hitting "Go"👇
110
Volkis @volkis.au · 24/09/2026
Fresh updates are live on our site, and we couldn't wait to share them with you! We’ve polished up a few things to make finding what you need even easier. Many more changes to come! Check them out 👇
100
Volkis @volkis.au · 20/09/2026
Here's what we pack for physical intrusion tests 🥷
000
Volkis @volkis.au · 16/09/2026
7 years ago, Alexei set out to build a security consultancy grounded in empathy, transparency, and doing things the right way. Thank you for leading us with genuine kindness, passion, and curiosity, and for everything you do for the team. Happy Volkisversary, boss! 🐺
010
Volkis @volkis.au · 11/09/2026
Ever run docker cp to pull logs, build artifacts, or test results out of a container? You might want to double-check your Docker version. Imperva published details on CopyEscape (CVE-2026-17106).
110
Volkis @volkis.au · 10/09/2026
When you book a pentest, the obvious value comes from the consultant digging into your systems. But what does the company behind them bring to the table? Is it just scheduling and an invoice, or does it make the test better? Here's where we reckon a consultancy earns its keep👇
110
Volkis @volkis.au · 08/09/2026
In an engagement, we phished creds, snuck into a public bathroom below their office and hid a device. From that first foothold to complete network control took less effort than the phishing and the sneaking.
101
Volkis @volkis.au · 02/09/2026
Firewalls don't get "broken through." Attackers just make malicious traffic look legit using protocols the firewall already trusts, or slipping through blind spots where it only sees part of the network path.
100
Volkis @volkis.au · 30/08/2026
Happy Birthday to our Senior Security Consultant, Nathan! 🥳 Whether he’s performing network and web app pentests or running security reviews, Nathan brings incredible skill and genuine kindness to everything he does at Volkis.
000
Volkis @volkis.au · 26/08/2026
Wallpapers, T-shirt designs, and other bits with the Volkis wolf on them. We put it all in one spot. 🐺👇
100
Volkis @volkis.au · 24/08/2026
How mature is your Essential 8 actually? Not what the checklist says but what an attacker would find.
100
Volkis @volkis.au · 13/08/2026
Where does "Volkis" come from? True story. Matt and Alexei were brainstorming names while Alexei was in Europe. Matt suggested "Volk," after Alexei's dog. Close, but not quite.
100
Volkis @volkis.au · 10/08/2026
We are honest and transparent with ourselves, our clients, and the wider community. A philosophy at Volkis is to be "open but secure". We make information public by default unless its under NDA, or could be damaging.
000
Volkis @volkis.au · 05/08/2026
Happy Birthday to the big boss, Alexei! 🐺 As one of the two founders who made Volkis possible, thank you for inspiring and leading us with kindness and genuine curiosity to give the best of ourselves
000
Volkis @volkis.au · 03/08/2026
We are Volkis. A group of hackers, Australian, independent from the big players, all local. We are dedicated to offensive security. We love it and we do it well.
110
Volkis @volkis.au · 31/07/2026
Anyone else's brain switch on the second the sun goes down?
000
Volkis @volkis.au · 30/07/2026
Meet the operator, Nathan Jarvie, our Senior Security Consultant. He's a hacker with deep hands-on experience, and he's chasing every certification he can get his hands on. 13 certifications in cybersecurity so far, with more on the way.
000
Volkis @volkis.au · 24/07/2026
Avoid this happening. Reach out today 👇
100
Volkis @volkis.au · 20/07/2026
There was a time when companies proudly talked about what they actually stood for. Then "values" just became corporate posters gathering dust in boardroom hallways.
100
Volkis @volkis.au · 17/07/2026
We just moved the Volkis Handbook from v1 to v2. It still publishes everything we do that isn't confidential: methodologies, sample reports, internal policies, hiring guidelines, our AI usage rules. Open but secure since day one.
100
Volkis @volkis.au · 16/07/2026
We put *.volkis.com.au and *.volk.is in scope for anyone who wants to try.
110
Volkis @volkis.au · 14/07/2026
Look, we could hit you with the usual corporate jargon about "synergistic paradigm-shifting cyber resilience", but honestly, we’d rather just do the job properly.
110
Volkis @volkis.au · 09/07/2026
22% of assessed Australian government entities hit Maturity Level 2 across the Essential Eight, and the board reads it as progress.  ML2 measures if the control exists, but not whether they can stop a real attack.
100
Volkis @volkis.au · 08/07/2026
Meet Matthew Strahan, Co-Founder and Managing Director at Volkis. At Volkis, “people first” shows up in the details: how we talks about clients, hiring, learning, remote work, culture, and even security itself.
100
Volkis @volkis.au · 23/06/2026
Meet Alexei Doudkine, Co-Founder and Offensive Director at Volkis. Alexei is one of the reasons the Volkis voice is so direct. The job is to think like a hacker, explain what matters, and help the client get to a better place.
100
Volkis @volkis.au · 22/06/2026
86,644 Fortinet firewalls across 194 countries, compromised with verified working credentials. Banks, hospitals, telecoms, government agencies.
100
Volkis @volkis.au · 18/06/2026
People are your strongest cybersecurity asset. The most powerful security move you can make is to build a culture that normalises good security. Make it normal to question someone's presence in the office, forward a suspicious email to security, lock your screen, etc.
000
Volkis @volkis.au · 03/06/2026
There are thousands of wordlists available on the internet, but downloading them all blindly is a quick way to run out of storage and waste time.
100
Volkis @volkis.au · 15/05/2026
Back in 2018, when a CVE was released, it took 2.3 years to exploit. 2024: 56 days. Now: 1 day. End of 2026? 1 hour. Reactive approaches to security are no longer effective. If you want expert guidance for the new era, get in touch. www.volkis.com.au/contact
000
Volkis @volkis.au · 22/04/2026
🧪 Volkis Lab Challenge: Command Execution   Drop your payload 🐺
000
Volkis @volkis.au · 20/04/2026
🧪 Volkis Lab: Privilege Escalation   You don’t need exploits when the system hands you the right tool. 🐺 Can you spot it?
000
Volkis @volkis.au · 10/04/2026
Another happy customer review came through today. 😊
000
Volkis @volkis.au · 20/03/2026
It is common to think an AI agent is safe because it only handles "public" data. But the most dangerous instructions aren't written by developers. They are the "Injected" commands 👇
110
Volkis @volkis.au · 11/03/2026
We did this pentest recently where we got Domain Admin. Cool, but we wanted more! We had the admin's creds so we just waited... When the admin logged out and left for the day, we just logged back in through RDP as him! 👇
100
Volkis @volkis.au · 08/03/2026
🧪 Volkis Lab: This seems suspicious, doesn't it? Sleep → Decode → Decrypt → Runtime API resolution → explorer.exe 🐺 Name the technique. Drop the ATT&CK ID if you know it.👇
000
Volkis @volkis.au · 04/03/2026
Does guessing or brute-forcing passwords still work? Yep! CompanyName123, Monday2026!, Commodore#1... We still see these, and it's often our foothold into a network. 👇
110
Volkis @volkis.au · 03/03/2026
Hackers don’t need fancy tooling anymore, the target system carries it for us. We can "live off the land". Your PowerShell. Your MSHTA. Your CERTUTIL. Your tools, our commands. #HackingTips
000
Volkis @volkis.au · 03/03/2026
🧪 Volkis Lab: Can you recognise it? Bonus: Drop the MITRE ATT&CK ID 👇🐺
000
Volkis @volkis.au · 27/02/2026
Pumping yourself up to write a pentest report on a Friday afternoon 📢 🎵🕺
010
Volkis @volkis.au · 26/02/2026
🧪 Volkis Lab: Got a reverse shell? Don’t rush into recon or privilege escalation.   Raw, fragile access gets you caught. Stabilise it first.  Control before capability. Drop your thoughts 👇🐺
000
Volkis @volkis.au · 24/02/2026
We were on a red team engagement searching through the external infrastructure for a way in.  Struggling for a way in, a junior asked: "What about DNS?" That comment made us zoom out a notch.👇
100
Volkis @volkis.au · 20/02/2026
It’s common to enumerate your attack surface using DNS records. But the weakest systems usually aren’t in DNS. They are the ones that have drifted: 👇
110
Volkis @volkis.au · 19/02/2026
🧪 Volkis Lab: What attack would you do and what tool(s) would you use? The scan is telling you everything if you know how to read it. Drop your answers below 👇🐺
000
Volkis @volkis.au · 17/02/2026
The company rolled out a new webpage. It looked normal. Just another page asking you to “verify you’re human.” It was a ClickFix attack. 👇
110
Volkis @volkis.au · 15/02/2026
Nothing annoys us, as attackers, more than well placed honeypots/tokens. It makes us paranoid at every step. That's good! 👇
100
Volkis @volkis.au · 10/02/2026
🧪 Volkis Lab: What attack can you perform here? In this code, nothing is executed, dropped or broken. Yet, there are multiple attack possibilities.   The important thing is how you think. Drop your thoughts below 👇🐺
000
Volkis @volkis.au · 08/02/2026
It took us months, but we're in. And now it's time to pull the trigger. We'll go in fast, hit our goals, and leave. At 7pm no one's around right? It works! The 6 of us get our goal in an hour. Turns out, no one was "officially" on call. An easy mistake to make🐺 #HackingStories
001
Volkis @volkis.au · 05/02/2026
🧪 Volkis Lab: What’s the attack? A good attacker knows what their activity looks like in logs. Here, everything looks legit, but it's not. Bonus: What tools would you use to perform it? Drop your answers below 👇🐺
000