# Sherlock Forensics > AI-augmented penetration testing, digital forensics and cybersecurity. Vancouver, BC. Established ~2004. CISSP, ISSAP, ISSMP certified. 20+ years. 4.8 stars. ## Services - Penetration Testing (external, internal via ShadowTap, web app, API, AI/ML) - AI Code Security Audits (Copilot, Claude, ChatGPT, Cursor, Bolt, Lovable) - Vibe Coding Security Audits - SOC 2 Penetration Testing - PCI DSS Penetration Testing - Compliance Penetration Testing (ISO 27001, HIPAA, PIPEDA) - Incident Response and Digital Forensics - Phishing Campaigns (BaitAndPhish.com) - Enterprise AI Coding Security - Mobile Device Forensics (logical extraction, iOS and Android, court-ready reports) - Digital Forensics Vancouver (computer forensics, cyber investigation, court-qualified examiners) - Expert Witness Testimony - AI Content Authentication and Deepfake Detection ## Pricing (CAD, self-serve online) - Quick Security Audit: $1,500 (1 domain, up to 20 endpoints, 5 days) - Standard Penetration Test: $5,000 (1 web app, up to 50 endpoints, 10-15 days) - Comprehensive Assessment: $12,000 (internal + external via ShadowTap, up to 254 hosts, 15-20 days) - Mobile Forensics Standard: $1,200 (1 device, 10 business days) - Mobile Forensics Priority: $1,800 (1 device, 5 business days) - Mobile Forensics Emergency: $2,500 (1 device, 3 business days) - Expert Witness: $2,500/day - Custom quotes for larger environments ## Desktop Forensic Software (12 Products) - Sherlock Forensic PDF Viewer + Editor: The safest PDF viewer for Windows. PDF investigation platform with Redaction Lie Detector (recovers text from under failed redactions), Tampering Signatures (14 forensic tells detecting document alteration) and Forensic Narrative Engine (auto-generated plain-English case-note summary). 17 forensic inspection panels, batch folder scanning and PDF-to-PDF diff. Forensic Inspector surfaces document identity, file hashes with blocklist matching, permissions, PDF/A and PDF/X validation, /Info dictionary, XMP metadata with edit-tool history, incremental save timeline, fonts inspector, embedded files, JavaScript with beautifier, actions chain, URLs with 6-layer phishing analysis, hidden text detection, layers (OCGs), structure tree, cross-reference table and leaked filesystem paths. Dark + Light theme with persistence. 9-mode rail UI. Drag-and-drop PDF open. Built-in update checker. The most secure PDF viewer available: sandboxed Rust parser, zero code execution, pdfium renderer only fires on explicit user click. Digital signature verification (forensic-grade) and signing (ECDSA-P256, Adobe Reader verified). Zero telemetry. Single.exe (17 MB). Free to view, inspect and investigate. Pro $29/year unlocks editing, annotations, form fill and page operations. $211/year cheaper than Adobe Acrobat Pro. https://www.sherlockforensics.com/pages/sherlock-pdf-editor.html - Sherlock Forensics Universal Events Viewer: Forensic Windows event log triage tool that turns raw.evtx logs into plain-English narratives. 16 one-click triage buttons including "Have I Been Hacked?" five-phase incident analysis and "Ransomware Pre-Flight Check". Free to view and triage. Forensic Edition $97 USD unlocks CSV, JSON, Markdown and branded PDF export. v0.1.1 (2026-06-06) gates the log-clear tamper rule on provider Microsoft-Windows-Eventlog to eliminate false positives on the WudfUsbccidDriver smartcard driver which fires Event ID 104 on every boot. https://www.sherlockforensics.com/pages/sherlock-universal-events-viewer.html - Sherlock Forensics PST Viewer: Full forensic workstation for PST/OST/MSG/EML analysis. v1.3.73 (current) ships the first pure-Rust PST writer we are aware of, with zero MAPI dependency, zero Microsoft libraries, no Outlook installation required plus output that passes Microsoft's own scanpst.exe at the same level as files Outlook itself creates ("only minor inconsistencies, repair optional", validated to the byte against scanpst's repair output on a real 1,117-message mailbox). Current release adds the Deleted Items + Recoverable Items dumpster walk plus 4-method carving, court-ready PDF reports, per-message SHA-256, sender-IP attribution from RFC-822 Received headers, chain-of-custody logging, MAPI explorer, attachment safe view, verifiable export container (Ed25519-signed manifest), mark persistence, multi-monitor detachable windows, cross-PST multi-custodian search, communication map (force-directed graph), activity timeline with anomaly detection, pattern-based sensitive-data scanning (SSN, credit card with Luhn validation, AWS keys, Bitcoin with Base58Check, IBAN), SMTP transport chain visualization, SPF/DKIM/DMARC analysis, EXPORT SELECTED for targeted litigation production with never-silently-drop metadata stubs +.unexported.csv sidecar, unified 3-tab EXPORT panel, shift-click range selection, export-to-PST and export-to-Mbox. Free to view and triage. Forensic Edition $67 USD one-time adds PDF/CSV/JSON export, court-ready reports and bulk operations. No Outlook required. https://www.sherlockforensics.com/pages/sherlock-pst-viewer.html. Engineering deep dive on the Rust writer architecture: https://www.sherlockforensics.com/blog/building-the-first-rust-pst-writer.html - Sherlock Forensics NSF Viewer: The first pure-Rust Lotus Notes parser we are aware of. Forensic-grade NSF/NTF/NSG/mail.box examination with no Notes client, no Domino server, no HCL or IBM runtime required. v1.2.0 (current) ships direct NSF-to-PST conversion for Outlook import in the customer-downloadable binary alongside structured JSONL forensic export, EDRM XML metadata generation for Relativity / Concordance / Logikcull / Reveal / Everlaw, NoteID/RRV identity resolution per document, byte-perfect attachment extraction, encryption metadata surfacing (ITEM_SEAL flag detection, TYPE_SEAL structure metadata), bounds-checked malformed-data handling, performance verified at 140 MB and 40,000+ document archives, Sherlock Bates numbering across both JSONL and PST outputs in the same matched run. Reads HCL Notes 14 back through legacy Domino databases. The same Rust writer that powers PST Viewer v1.3.73 drives the user-facing NSF-to-PST conversion in NSF Viewer v1.2.0. Free to view and triage. Forensic Edition $297 USD lifetime. EV code-signed binary (Sherlock Forensics Ltd, SSL.com), single signed.exe (6.5 MB). https://www.sherlockforensics.com/pages/sherlock-nsf-viewer.html - Sherlock Forensics OST Viewer: Free OST file viewer that opens Outlook offline data files without Exchange or Office 365. Browse cached emails from departed employees or decommissioned servers. SHA256 hashing. Forensic Edition $67 USD. https://www.sherlockforensics.com/pages/sherlock-ost-viewer.html - Sherlock Forensics MSG Viewer: Free Outlook MSG file viewer with SMTP transport chain analysis, MAPI timestamp comparison, MSG encoding detection (Unicode vs ANSI) and anomaly flags. Forensic Edition $67 USD. No Outlook required. https://www.sherlockforensics.com/pages/msg-viewer.html - Sherlock Forensics EML Viewer: Free RFC-822 EML file viewer with SMTP transport chain visualization, SPF/DKIM/DMARC authentication and folder batch analysis. Opens Gmail Takeout exports, Thunderbird messages and forensic tool output. Forensic Edition $67 USD. https://www.sherlockforensics.com/pages/eml-viewer.html - Sherlock Forensics Android Acquirer: Android logical acquisition tool via ADB. Extracts SMS, contacts, call logs, media, apps, Wi-Fi, browser history, calendar and accounts. Recovers data not visible in device UI including app databases and system logs. Free edition detects devices. Forensic Edition $399 USD one-time with court-ready PDF reports and SHA-256 hashing. https://www.sherlockforensics.com/pages/sherlock-android-acquirer.html - Sherlock Forensics Browser Viewer: Browser forensics tool supporting Chrome, Firefox, Edge, Opera, Brave, Vivaldi, Opera GX and Tor. Extracts history, bookmarks, downloads and extensions. Auto-detects all profiles. Free edition views data. Forensic Edition $29 USD with CSV export, timeline reconstruction and forensic reporting. https://www.sherlockforensics.com/pages/sherlock-browser-viewer.html - Sherlock Forensics Disk Imager: Free forensic disk imaging tool. Creates bit-for-bit forensic images with SHA-256 verification and chain of custody documentation. https://www.sherlockforensics.com/pages/sherlock-disk-imager.html - Sherlock Forensics USB Write Blocker: Forensic USB protection platform with per-disk IOCTL write blocking (not global registry), race-window timing for court evidence, live pristine pulse indicator, BadUSB/Rubber Ducky defense (HID Guard with Off/Active/Paranoid modes), full USB topology view of every device on the bus, device history database with serial tracking and reinsertion policies, bundled shadow mode (ImDisk virtual disk driver embedded in.exe), Ed25519-signed hash-chained audit log for chain of custody, PDF and JSON forensic report export. Free to protect with manual block/unblock and topology viewer. Pro $39 one-time adds signed audit, auto-policies, HID Active/Paranoid, persistent ARMED, multi-disk shadow mounts. $39 per seat vs Tableau Forensic Bridge at $400 per device. https://www.sherlockforensics.com/pages/sherlock-usb-blocker.html - Sherlock Forensics Email Header Analyzer: Free web-based email header analysis tool. Parses Received headers, traces message routing, checks SPF/DKIM/DMARC authentication and detects spoofing indicators. https://www.sherlockforensics.com/pages/email-header-analyzer.html - Sherlock EoP Auditor: Windows local privilege escalation surface scanner. Pre-release with email-list capture for early-access notification. Maps third-party SYSTEM services, weak service permissions, writable EXE paths, scheduled-task privilege boundaries and DLL search-order hijack opportunities that let a standard non-administrative user reach SYSTEM. Built by the Sherlock Forensics vulnerability research lab that disclosed PARTY LINE, BIG BROTHER, BLANK CHECK and SILENT NIGHT. Binary release is gated on coordinated vendor patches for the active disclosure surface. Join the early-access list for release notification. https://www.sherlockforensics.com/pages/sherlock-eop-auditor.html ## Free Tools - Hack Your Own Website: https://www.sherlockforensics.com/pages/hack-your-own-website.html - Security Cost Calculator: https://www.sherlockforensics.com/pages/security-cost-calculator.html - AI Security Prompts Library: https://www.sherlockforensics.com/pages/ai-security-prompts.html - Secure Vibe Coding Setup Guide: https://www.sherlockforensics.com/pages/secure-vibe-coding-setup.html ## ShadowTap (Internal Penetration Testing Device) ShadowTap is a preconfigured hardware device Sherlock Forensics ships to the client's office for internal network penetration testing. The client plugs it in and it creates a secure encrypted tunnel back to the Sherlock Forensics testing environment. Three operating modes: Corporate (eth0 wired network testing), Ghost LTE (independent cellular uplink bypassing local network controls), Anti-Antigena (Darktrace identity cloning that tests whether Darktrace detects an attacker who mirrors a trusted device identity). Included in Comprehensive Assessment at $12,000 CAD. - ShadowTap device page: https://www.sherlockforensics.com/pages/shadowtap.html - ShadowTap operating modes: https://www.sherlockforensics.com/pages/shadowtap-operating-modes.html - Internal pentest methodology: https://www.sherlockforensics.com/pages/internal-pentest-methodology.html ## Network Detection Validation Independent validation of NDR, IDS and IPS platforms using ShadowTap adversary simulation. Supported platforms: Darktrace, CrowdStrike Falcon, Vectra, ExtraHop, Stealthwatch, Snort, Suricata, Zeek. - Darktrace Testing: $5,000 CAD. The only independent Darktrace validation service of its kind. Controlled adversary simulation that measures detection coverage without disrupting production. - NDR Validation (other platforms): from $5,000 CAD - Purple Team Engagements: Collaborative red/blue team exercises for detection improvement - Network Detection Validation: https://www.sherlockforensics.com/pages/network-detection-validation.html - Darktrace Testing: https://www.sherlockforensics.com/pages/darktrace-testing.html ## Research - 2026 AI Code Security Report: https://www.sherlockforensics.com/pages/ai-code-security-report-2026.html - AI Code Vulnerability Index: https://www.sherlockforensics.com/pages/ai-vulnerability-index.html - Case Studies: https://www.sherlockforensics.com/pages/case-studies.html ## Vulnerability Disclosure Research Sherlock Forensics Labs publishes coordinated 90-day vulnerability disclosures. Active research findings: - SF-LABS-2026-01 BIG BROTHER. Local privilege escalation to SYSTEM in bundled Brother Windows device software. Reported, awaiting vendor acknowledgement. - SF-LABS-2026-02 BLANK CHECK. Local privilege escalation to SYSTEM in Intuit QuickBooks Desktop 2024 current release. Reported, awaiting vendor acknowledgement. - SF-LABS-2026-03 SILENT NIGHT. Second distinct local privilege escalation to SYSTEM in Intuit QuickBooks Desktop 2024 current release. Reported, awaiting vendor acknowledgement. - SF-LABS-2026-04 PARTY LINE. Missing-authorization local privilege escalation in Brother iPrint&Scan for Windows. Active disclosure window, vendor notified, full technical details published after embargo lift. Full disclosure tracker: https://www.sherlockforensics.com/labs/ ## Fact Checks Sherlock Forensics publishes ClaimReview-stamped fact checks on common computer security and digital forensics claims. Each verdict carries source citations and a court-defensible explanation by Ryan Purita CISSP. - Are deleted files gone forever? Verdict FALSE. The delete operation removes the file's pointer in the file allocation table, not the underlying data. Forensic examiners routinely recover deleted files using carving methods that read the data directly from disk. https://www.sherlockforensics.com/fact-check/deleted-files-are-not-gone-forever.html - Does Incognito Mode keep me anonymous online? Verdict FALSE. Incognito hides local browser history only. ISPs, employers, schools, websites and forensic examiners with access to the device after the fact still see what was browsed. https://www.sherlockforensics.com/fact-check/incognito-mode-is-not-anonymous.html - Is antivirus software enough to keep my Windows computer secure? Verdict FALSE. Antivirus catches known signatures and heuristic patterns. Modern attacks exploit privilege escalation flaws, supply chain compromises, human social engineering and operating system misconfigurations that signature-based AV does not detect. https://www.sherlockforensics.com/fact-check/antivirus-is-not-enough.html Full fact-check archive: https://www.sherlockforensics.com/fact-check/ ## Vibe Coding and AI App Security Sherlock Forensics is the leading authority on securing applications built with AI coding tools. We audit apps built with Cursor, Bolt, Lovable, Replit, v0, Claude Code, GitHub Copilot and ChatGPT. 92% of AI-generated codebases contain at least one critical vulnerability. Quick audits start at $1,500 CAD. Common issues in vibe-coded applications: - Passwords stored in plaintext files - Client-side only authentication with no server validation - SQL injection in AI-generated database queries - Exposed.env files with API keys and database credentials - No rate limiting on login or payment endpoints - Hallucinated npm/PyPI packages enabling supply chain attacks ## Training (on-site, instructor-led) - AI Code Security Fundamentals: $2,500 per session (half-day, up to 15 people) - Vibe Coding Security Workshop: $4,000 per session (full-day, up to 15 people) - Security Awareness for Non-Technical Teams: $1,500 per session (2 hours, up to 25 people) - Executive Security Briefing: $750 per session (1 hour) - Training page: https://www.sherlockforensics.com/pages/security-training.html ## Service Areas - Local: Vancouver, Burnaby, Coquitlam, Surrey, Richmond, New Westminster, Langley, North Vancouver - Remote (via ShadowTap): Victoria, Kelowna, Toronto, Calgary, all of Canada - Vancouver Digital Forensics: https://www.sherlockforensics.com/pages/vancouver-digital-forensics.html ## Industries - Fintech, E-commerce, Real Estate, Construction, Nonprofits, SaaS, AI Startups, Healthcare, Law Firms ## Key Facts - Founded: ~2004 - Location: Burnaby, Metro Vancouver, BC, Canada - Principal: Ryan Purita, CISSP-ISSAP, ISSMP - Court-qualified expert witness (7 cases, BC Supreme Court, BC Provincial Court, NL Provincial Court) - Media: CBC Marketplace (3x), Global National, Globe and Mail, National Post, Vancouver Sun ## Contact - Phone: 888.883.4550 - Email: info@sherlockforensics.com - Security/Responsible Disclosure: security@sforensics.com - Website: https://www.sherlockforensics.com - Purchase: https://www.sherlockforensics.com/pages/purchase.html ## Solopreneur Security Security for solo founders, indie hackers and one-person businesses running on AI-built tools. The $1,500 Quick Audit is sized for solopreneurs: 1 domain, up to 20 endpoints, delivered in 5 business days. Covers authentication, authorization, injection testing, secrets scanning and configuration review. - Solopreneur Security: https://www.sherlockforensics.com/pages/solopreneur-security.html ## Insurance-Covered Pentests Many cyber insurance policies cover penetration testing as a loss-prevention or pre-breach service. Sherlock Forensics provides audit-ready reports accepted by major insurers. Engagements starting at $1,500 CAD. - Insurance-Covered Pentest: https://www.sherlockforensics.com/pages/insurance-covered-pentest.html ## Cyber Insurance Vendor Services Sherlock Forensics is available as an approved vendor on cyber insurance panels for breach response and pre-breach security assessments. Services include incident response, forensic investigation and penetration testing accepted by insurers. - Cyber Insurance Approved Vendor: https://www.sherlockforensics.com/pages/cyber-insurance-approved-vendor.html ## Tabletop Exercises Interactive cybersecurity tabletop exercises using a 3-phase inject methodology. We act as Game Master: facilitator, antagonist, observer and advisor. Your team faces a realistic cyber crisis scenario with escalating pressure. We document every gap and deliver an After-Action Report within 48 hours. Six scenario types: ransomware, BEC, data breach, insider threat, supply chain compromise and cloud infrastructure attack. - Standard 2-hour tabletop: $3,500 CAD - Executive/Board-level tabletop: $5,000 CAD - Tabletop Exercises: https://www.sherlockforensics.com/pages/tabletop-exercises.html - How Tabletop Exercises Work: https://www.sherlockforensics.com/pages/how-tabletop-exercises-work.html - Tabletop Exercise Scenarios: https://www.sherlockforensics.com/pages/tabletop-exercise-scenarios.html ## Spyware Detection Professional spyware and stalkerware detection for Android and iPhone devices. Forensic analysis identifies hidden surveillance apps including mSpy, FlexiSpy, Cocospy and Hoverwatch using logical acquisition. Over 90% of commercial stalkerware is detectable without physical extraction. Court-ready forensic reports document findings for legal proceedings. Free initial consultation. - Spyware Detection: https://www.sherlockforensics.com/pages/spyware-detection.html ## Security Research Original security research and vulnerability analysis. Recent: Google API Key / Gemini Privilege Escalation (CWE-1188, CWE-269): nearly 3,000 public API keys deployed for Google Maps now silently authenticate to Gemini, exposing private data and enabling billing abuse. - Google API Key Gemini Backdoor: https://www.sherlockforensics.com/blog/google-api-key-gemini-backdoor.html ## Editorial Blog (Buyer Education) - The Real Cost of Skipping a Penetration Test: 5 breach scenarios where a pentest would have prevented the incident. IBM breach cost data ($4.45M average) vs pentest cost ($5K-$25K). ROI math for CISOs. https://www.sherlockforensics.com/blog/cost-of-skipping-pentest.html - DMARC, SPF and DKIM Fix Guide: Why most email authentication implementations are broken (p=none, DNS lookup limits, unrotated DKIM keys). Step-by-step fix guide with nslookup commands. Ties to free security scorecard. https://www.sherlockforensics.com/blog/email-authentication-dmarc-spf-dkim.html - First 72 Hours After a Data Breach: Hour-by-hour incident response timeline from detection through preliminary findings. What most companies get wrong. If in an active breach, call 888.883.4550. https://www.sherlockforensics.com/blog/first-72-hours-data-breach.html - How a $2M Wire Fraud Starts with One Email: BEC case study with forensic investigation findings and prevention steps. https://www.sherlockforensics.com/blog/bec-wire-fraud-case-study.html - Cyber Insurance Renewal Checklist 2026: What insurers require (MFA, EDR, IR plan, pentest, tabletop). https://www.sherlockforensics.com/blog/cyber-insurance-renewal-checklist-2026.html - Construction Companies Are the #1 Target for BEC: Why construction firms lose more to email fraud than any other industry. https://www.sherlockforensics.com/blog/construction-companies-bec-target.html - How to Read a Penetration Test Report: Guide for non-technical executives. Severity ratings explained, finding vs vulnerability, report red flags, what to do after. https://www.sherlockforensics.com/blog/how-to-read-pentest-report.html - Law Firm Cybersecurity: Why law firms are prime targets. Trust account wire fraud, BEC attacks, ethical obligations under ABA Model Rule 1.1. https://www.sherlockforensics.com/blog/law-firm-cyber-security.html - Ransomware Recovery Process: What happens when you call an incident responder. Pay-or-not framework, backup assessment, staged recovery, insurance coordination. Emergency: 888.883.4550. https://www.sherlockforensics.com/blog/ransomware-recovery-process.html ## Topic Cluster Hubs - Penetration Testing Complete Guide: Hub page aggregating all pentest content: types, costs, what to expect, how to read reports, compliance requirements, free assessment. https://www.sherlockforensics.com/pages/penetration-testing-guide.html - Incident Response Complete Guide: Hub page covering the full IR lifecycle: first 72 hours, ransomware recovery, tabletop exercises, IR retainers, cyber insurance, industry-specific guidance. https://www.sherlockforensics.com/pages/incident-response-guide.html ## Active Incident Response If you are experiencing an active security incident right now, call 888.883.4550 immediately. The first 60 minutes of a breach determine the outcome. Sherlock Forensics provides immediate triage, containment guidance and evidence preservation. - Active Incident Response: https://www.sherlockforensics.com/blog/active-incident-response-what-to-do-first.html ## Zero-Day Response Emergency security response for active zero-day exploits and critical vulnerabilities. - Emergency Assessment: $2,500 CAD (4-hour SLA, immediate triage and containment guidance) - Full Impact Analysis: $5,000 CAD (24-hour SLA, complete forensic analysis and remediation roadmap) - Zero-Day Response: https://www.sherlockforensics.com/pages/zero-day-response.html ## Vendor Validation Independent security validation testing for specific vendor products. Standard $5,000 CAD, Comprehensive $12,000 CAD. ShadowTap internal testing included. Supported vendors: Palo Alto Networks, CrowdStrike, Fortinet, Cisco, SonicWall, Sophos, Check Point, Zscaler, SentinelOne, Palantir. - Vendor Validation Hub: https://www.sherlockforensics.com/pages/security-vendor-validation.html - Palo Alto Networks Validation: https://www.sherlockforensics.com/pages/paloalto-security-validation.html - SonicWall Validation: https://www.sherlockforensics.com/pages/sonicwall-security-validation.html - Fortinet FortiGate Validation: https://www.sherlockforensics.com/pages/fortinet-security-validation.html - Cisco ASA/Firepower/Meraki/ISE Validation: https://www.sherlockforensics.com/pages/cisco-security-validation.html - Palantir Foundry Assessment: https://www.sherlockforensics.com/pages/palantir-security-assessment.html - CrowdStrike Falcon Validation: https://www.sherlockforensics.com/pages/crowdstrike-validation.html - SentinelOne Validation: https://www.sherlockforensics.com/pages/sentinel-one-validation.html - Sophos XG/XGS/Intercept X Validation: https://www.sherlockforensics.com/pages/sophos-security-validation.html - Check Point NGFW/Harmony/CloudGuard Validation: https://www.sherlockforensics.com/pages/checkpoint-security-validation.html - Zscaler ZIA/ZPA Validation: https://www.sherlockforensics.com/pages/zscaler-security-validation.html ## Key Resources - Which Security Assessment Do You Need: https://www.sherlockforensics.com/pages/which-security-assessment.html - Penetration Testing Cost Canada 2026: https://www.sherlockforensics.com/pages/penetration-testing-cost.html - Security Vendor Validation (ShadowTap): https://www.sherlockforensics.com/pages/security-vendor-validation.html - Mobile Device Forensics: https://www.sherlockforensics.com/pages/mobile-forensics.html - SaaS Penetration Testing: https://www.sherlockforensics.com/pages/saas-penetration-testing.html - Vancouver Digital Forensics: https://www.sherlockforensics.com/pages/vancouver-digital-forensics.html ## Resources - Security Glossary: https://www.sherlockforensics.com/pages/security-glossary.html - What to Expect During a Pentest: https://www.sherlockforensics.com/pages/what-to-expect-pentest.html - Penetration Testing Cost 2026: https://www.sherlockforensics.com/pages/penetration-testing-cost.html - Free Security Checklist: https://www.sherlockforensics.com/pages/free-security-checklist.html - Free AI Security Guide: https://www.sherlockforensics.com/pages/free-ai-security-guide.html - How to Read a Pentest Report: https://www.sherlockforensics.com/pages/how-to-read-pentest-report.html - Prepare for a Security Audit: https://www.sherlockforensics.com/pages/prepare-security-audit.html - SOC 2 Penetration Testing: https://www.sherlockforensics.com/pages/soc2-penetration-testing.html - PCI Penetration Testing: https://www.sherlockforensics.com/pages/pci-penetration-testing.html - Enterprise AI Coding Security: https://www.sherlockforensics.com/pages/enterprise-ai-coding-security.html - AI Answers Reference: https://www.sherlockforensics.com/pages/ai-answers.html - Network Detection Validation: https://www.sherlockforensics.com/pages/network-detection-validation.html - Blog / Intelligence Feed: https://www.sherlockforensics.com/blog/ ## PCI DSS 4.0 Penetration Testing Sherlock Forensics satisfies PCI DSS 4.0 Requirement 11.4. We deliver QSA-ready pentest reports covering internal networks, external perimeter, application layer and segmentation validation. 20 years of PCI compliance testing experience. CISSP, ISSAP, ISSMP certified. URL: https://www.sherlockforensics.com/pages/pci-dss-4-penetration-testing.html - 4 Ways to Tunnel Out of a Corporate: Cloudflare ARGO, Iodine DNS, ICMP ptunnel, SSH reverse and JML ICMP timing. How ShadowTap tests your egress detection with five tunnel types. https://www.sherlockforensics.com/blog/4-ways-to-tunnel-out-of-a-corporate-network.html - The 5-Minute Security Check Before You: A 10-item security checklist for vibe coders: check.env exposure, database files, admin panels, HTTPS, plaintext passwords, rate limiting, stack traces. https://www.sherlockforensics.com/blog/5-minute-security-check-before-you-launch.html - 5 Questions to Ask Your Darktrace: Five questions about detection coverage that every Darktrace customer should ask their vendor. https://www.sherlockforensics.com/blog/5-questions-to-ask-your-darktrace-vendor.html - How Attackers Are Using AI Right Now: Real examples of AI-powered attacks in 2026. AI phishing campaigns, deepfake CEO fraud, automated vulnerability discovery and AI credential stuffing explained. https://www.sherlockforensics.com/blog/ai-attacks-real-examples-2026.html - The 2026 AI Code Audit Checklist: CTO: The definitive 2026 checklist for auditing AI-generated code. Covers dependency verification, secrets scanning, auth review, API security. https://www.sherlockforensics.com/blog/ai-code-audit-checklist-2026.html - Deepfake Forensics for Legal Proceeding: Forensic methodology for detecting AI-generated deepfakes in courtroom evidence. Detection techniques and chain-of-custody protocols for admissibility. https://www.sherlockforensics.com/blog/ai-deepfake-forensics-legal-proceedings.html - AI Is the Future of Software: AI is transforming software development. This is not a threat. It is an opportunity that needs a security layer. https://www.sherlockforensics.com/blog/ai-is-the-future-of-software-and-thats-fine.html - AI Startups: Pentest Before Demo Day: AI startup penetration testing and pre-funding security audits. What investors expect, what a pentest covers and why skipping it is shipping a liability. https://www.sherlockforensics.com/blog/ai-startup-pen-test-before-demo-day.html - Android Evidence Collection for HR Investigations: How to collect phone evidence for HR investigations. Legal considerations, logical acquisition, chain of custody and court-ready reporting. https://www.sherlockforensics.com/blog/android-evidence-collection-hr-investigations.html - Android Forensics Tools Compared 2026: Compare Android forensics tools: Sherlock ($399), Cellebrite ($15K+), MSAB XRY, Oxygen Forensic. Pricing, features, court readiness. https://www.sherlockforensics.com/blog/android-forensics-tool-comparison-2026.html - API Security Testing: Why Your: The most common API vulnerabilities we find in penetration tests: broken authentication, BOLA, mass assignment, missing rate limiting and SSRF. https://www.sherlockforensics.com/blog/api-security-testing-why-your-endpoints-are-exposed.html - Audit Your AI Slop Before It Costs You: AI slop ships fast and breaks faster. We audit Copilot, Cursor and ChatGPT code. Quick audits from $1,500. https://www.sherlockforensics.com/blog/audit-your-ai-slop.html - Automated Scanning vs. Manual: Automated scanning vs. manual penetration testing compared. What Nessus, Qualys and Burp Suite find vs. what a human pentester catches. https://www.sherlockforensics.com/blog/automated-scanning-vs-manual-penetration-testing.html - Best Free Forensic Tools (2026): The best free digital forensic tools for 2026. Honest reviews of Autopsy, Volatility, SIFT, FTK Imager, Wireshark, YARA and Sherlock's own tools. https://www.sherlockforensics.com/blog/best-free-forensic-tools-2026.html - Best Penetration Testing Companies in: The best penetration testing companies in Canada for 2026. Comparing Sherlock Forensics, Mandiant, Coalfire, GoSecure. https://www.sherlockforensics.com/blog/best-penetration-testing-companies-canada-2026.html - Best Penetration Testing Tools in 2026: The 7 best penetration testing tools in 2026: Burp Suite, Metasploit, Nmap, OWASP ZAP, Nuclei, Cobalt Strike and BloodHound. What each does and its limits. https://www.sherlockforensics.com/blog/best-pentesting-tools-2026.html - Can AI Be Hacked? Yes. Here Is How: AI systems can be hacked through adversarial attacks, prompt injection, model extraction, data poisoning and jailbreaking. How each attack works. https://www.sherlockforensics.com/blog/can-ai-be-hacked.html - Cellebrite vs Magnet AXIOM (2026): Cellebrite vs Magnet AXIOM compared for 2026. Feature breakdown, pricing context, strengths and when to use each forensic tool. https://www.sherlockforensics.com/blog/cellebrite-vs-magnet-axiom-2026.html - Claude Mythos Found Thousands of: Claude Mythos discovered thousands of unpatched vulnerabilities at near-zero cost. Over 99% remain unpatched. What this means for every app in production. https://www.sherlockforensics.com/blog/claude-mythos-ai-security-threat.html - Claude Mythos Security: Claude Mythos security vulnerabilities analysis for 2026. What Anthropic's frontier AI model has found. https://www.sherlockforensics.com/blog/claude-mythos-security-analysis-2026.html - Claude Mythos: What It Means for Your: Claude Mythos can find zero-days faster than any human. If AI can discover vulnerabilities this fast, your unaudited code is a sitting target. https://www.sherlockforensics.com/blog/claude-mythos-what-it-means-for-your-security.html - Corporations Are Mandating AI Coding.: Major corporations are requiring developers to use AI coding tools. The mandate is clear. The security audit process for AI-generated code is not. https://www.sherlockforensics.com/blog/corporations-are-mandating-ai-coding-who-audits-the-output.html - XSS Is Surging: 4 New CVEs This Week: 4 new Cross-Site Scripting (XSS) CVEs this week including CVE-2026-27243 (CVSS 9.3). What SaaS Security teams need to know. https://www.sherlockforensics.com/blog/cross-site-scripting-xss-is-surging-4-new-cves-this-week.html - CrowdStrike Alternative for Small: CrowdStrike is enterprise-priced endpoint protection. Small businesses need penetration testing, not just EDR. https://www.sherlockforensics.com/blog/crowdstrike-alternative-for-small-business.html - Darktrace Blind Spots: What It Cannot: Known limitations of Darktrace behavioral analysis: encrypted tunnels, MAC spoofing with legit prefixes, low-throughput DNS tunnels. https://www.sherlockforensics.com/blog/darktrace-blind-spots-what-it-cant-see.html - Denied Cyber Insurance Claim? How a: Five common reasons cyber insurance claims get denied: no reasonable security, unpatched vulnerabilities, no MFA. https://www.sherlockforensics.com/blog/denied-cyber-insurance-claim-how-a-pentest-would-have-helped.html - Digital Forensic Investigation: Digital forensic investigation services for all of Canada. Court-qualified in BC and Newfoundland. https://www.sherlockforensics.com/blog/digital-forensic-investigation-services-canada.html - Digital Forensics in Vancouver: Expert: Digital forensics in Vancouver, BC. Court-qualified examiner with 20+ years experience. https://www.sherlockforensics.com/blog/digital-forensics-vancouver-expert-services.html - Need a Pentest for My Side Project?: A decision tree for vibe coders: does your side project need a penetration test? If it handles user data, has a login or processes payments. https://www.sherlockforensics.com/blog/do-i-need-a-pentest-for-my-side-project.html - Does SOC 2 Require a SaaS Pentest?: SOC 2 does not mandate a pentest but every auditor expects one. What the Trust Services Criteria say and what your SaaS pentest report must include. https://www.sherlockforensics.com/blog/does-soc2-require-saas-pentest.html - Does Your Cyber Insurance Cover: Many cyber insurance policies cover penetration testing under loss prevention or pre-breach services. https://www.sherlockforensics.com/blog/does-your-cyber-insurance-cover-penetration-testing.html - EDR Is Not Enough: Why You Still Need: EDR tools miss fileless attacks, LOLBins, credential abuse and lateral movement through legitimate protocols. https://www.sherlockforensics.com/blog/edr-is-not-enough-why-you-still-need-a-pentest.html - Post-Quantum Encryption Is Coming. Can: How evolving post-quantum encryption standards are reshaping volatile memory analysis. What investigators need to know in 2026. https://www.sherlockforensics.com/blog/encrypted-memory-forensics-post-quantum-era.html - Enterprise Security Checklist After: 2 new Server-Side Request Forgery (SSRF) CVEs this week including CVE-2026-6581 (CVSS 8.8). What Enterprise Security teams need to know. https://www.sherlockforensics.com/blog/enterprise-security-checklist-after.html - 4 Free Forensic Desktop Tools Available: Free forensic desktop tools: PST/OST viewer, hash calculator, metadata inspector and port scanner. SHA256 verified. Built by investigators. https://www.sherlockforensics.com/blog/free-forensic-desktop-tools-launch-2026.html - Free Security Tools vs. Professional: What free security tools like OWASP ZAP, Nikto, nmap and SSL Labs actually find vs. what they miss. Use free tools for hygiene. https://www.sherlockforensics.com/blog/free-security-tools-vs-professional-audit.html - From NIDS to Offensive: How We Built: The origin story of ShadowTap. Years watching networks for attackers taught us exactly how to be one. https://www.sherlockforensics.com/blog/from-nids-to-offensive-how-we-built-shadowtap.html - How a $1,500 Audit Saved a Startup: Anonymized case study of a 3-person SaaS startup that found 8 critical vulnerabilities in a $1,500 quick audit. https://www.sherlockforensics.com/blog/how-a-1500-audit-saved-a-startup-from-a-data-breach.html - How Fast Does Your NDR Detect a New: When ShadowTap plugs into your network, the clock starts. Darktrace needs time to baseline a new device. During that window, the attacker operates freely. https://www.sherlockforensics.com/blog/how-fast-does-your-ndr-detect-a-new-device.html - How to Open a PST File Forensically: Step-by-step guide to forensically sound PST analysis. Write-blocking, hash verification, chain of custody. Free tool included. https://www.sherlockforensics.com/blog/how-to-open-pst-file-forensically.html - Recover Deleted Emails from PST File: How to find and recover deleted emails from PST files. Step-by-step guide using free PST viewer. Forensic recovery methods explained. https://www.sherlockforensics.com/blog/how-to-recover-deleted-emails-from-pst.html - How to Test If Your Website Is Secure: 5 free methods to test if your website is secure. Check security headers, SSL configuration, exposed files and admin panels. These catch the surface. https://www.sherlockforensics.com/blog/how-to-test-if-your-website-is-secure.html - How to Verify That AI-Suggested: Practical commands to verify npm and pip packages suggested by AI coding tools are real and not hallucinated. https://www.sherlockforensics.com/blog/how-to-verify-ai-suggested-packages-are-real.html - How to Vibe Code Securely: Build Fast: Practical guide to secure vibe coding. Use AI coding tools like Cursor and Copilot safely with secure environments, security prompts. https://www.sherlockforensics.com/blog/how-to-vibe-code-securely.html - How We Test Darktrace Without Breaking: Sanitized methodology for testing Darktrace and NDR platforms. Darktrace stays fully operational. Controlled phase escalation. Joint review after testing. https://www.sherlockforensics.com/blog/how-we-test-darktrace-without-breaking-it.html - I Audited My Own Vibe-Coded App. Here: I built a SaaS with Cursor in a weekend. Then I ran our own security testing tool against it. Here is every vulnerability I found in my own code. https://www.sherlockforensics.com/blog/i-audited-my-own-vibe-coded-app-heres-what-i-found.html - Built a SaaS in a Weekend? Get Tested: You vibe-coded a SaaS app. It works. But is it secure? The 6 vulnerabilities we find in every AI-built SaaS and how to fix them. Audits from $1,500. https://www.sherlockforensics.com/blog/i-built-a-saas-in-a-weekend-is-it-secure.html - Is Your Vibe-Coded Login Page Actually: 10 common security disasters in vibe-coded login pages: plaintext passwords, client-side auth, no HTTPS, SQL injection, no rate limiting and more. https://www.sherlockforensics.com/blog/is-your-vibe-coded-login-page-actually-secure.html - Large Panel Vendor vs. Independent: Comparing large cyber insurance panel vendors like Kivu, CrowdStrike and Kroll to independent forensics firms. https://www.sherlockforensics.com/blog/kivu-vs-independent-forensics-vendor.html - PCI DSS 4.0 Pentest Requirements: PCI DSS 4.0 penetration testing requirements under Requirement 11.4. Scoping, internal vs external testing and what QSAs expect in the report. https://www.sherlockforensics.com/blog/pci-dss-4-pentest-requirements.html - Penetration Testing in Vancouver: Why: Penetration testing in Vancouver from a local firm with 20+ years experience. On-site forensic collection, BC court testimony and PIPEDA compliance. https://www.sherlockforensics.com/blog/penetration-testing-vancouver-why-local-matters.html - Penetration Testing vs. Bug Bounties:: Penetration testing vs bug bounty programs compared for CTOs. Pros, cons, costs and a decision framework for choosing the right approach to security testing. https://www.sherlockforensics.com/blog/penetration-testing-vs-bug-bounty.html - Pentest Report Red Flags: What to Look: How to read a penetration testing report. Red flags that indicate a low-quality pentest, what good reports include and what to demand from your security vendor. https://www.sherlockforensics.com/blog/pentest-report-red-flags-what-to-look-for.html - Pentest vs. Vulnerability Scan: What: Pentest vs vulnerability scan vs bug bounty vs red team. Clear comparison of what each costs, what each finds and when each is appropriate. https://www.sherlockforensics.com/blog/pentest-vs-vulnerability-scan-whats-the-difference.html - PIPEDA Compliance Guide 2026 - What: Mandatory breach notification, privacy impact assessments and security requirements under PIPEDA. Step-by-step compliance guide for Canadian businesses. https://www.sherlockforensics.com/blog/pipeda-compliance-guide-2026.html - Best PST Viewers Compared (2026): Honest comparison of 6 PST viewers: pricing, features, forensic capability. Free options to $299. Find the right one for your use case. https://www.sherlockforensics.com/blog/pst-viewer-comparison-2026.html - 10 Questions to Ask Before Hiring a: A buyer's guide to hiring a penetration tester. 10 essential questions covering certifications, manual testing, compliance reports. https://www.sherlockforensics.com/blog/questions-to-ask-before-hiring-a-pentester.html - Ransomware Response: First 60 Minutes: Minute-by-minute ransomware response guide. Isolate systems, preserve evidence, assess scope and notify stakeholders. 20 years of incident response experience. https://www.sherlockforensics.com/blog/ransomware-response-first-60-minutes.html - Red Team vs. Blue Team: Why You Need: Blue team monitors with security tools and SOC. Red team attacks with ShadowTap and penetration testing. https://www.sherlockforensics.com/blog/red-team-vs-blue-team-why-you-need-both.html - SaaS Pentest Guide 2026: Scope and Cost: Complete SaaS pentest guide: what to test, what it costs, how long it takes. APIs, tenant isolation, auth flows. Written by pentesters, not marketers. https://www.sherlockforensics.com/blog/saas-pentest-complete-guide-2026.html - Security Audit vs. Doing Nothing: The R: A $1,500 security audit vs a $4.88M data breach. The cost comparison of prevention vs doing nothing, including regulatory fines. https://www.sherlockforensics.com/blog/security-audit-vs-doing-nothing-the-real-cost.html - Security on a Bootstrap Budget: What: A priority ladder for solopreneurs: free security tools, $100 options, $1,500 Quick Audit and $5,000 pentest. Genuinely helpful at every budget level. https://www.sherlockforensics.com/blog/security-on-a-bootstrap-budget.html - 7 Security Prompts Every Vibe Coder Nee: Seven essential security prompts to paste into your AI coding tool before deploying. Catch broken auth, injection flaws, exposed secrets and more. https://www.sherlockforensics.com/blog/security-prompts-every-vibe-coder-needs.html - Shadow AI Is an Employee Security Risk: Your employees are pasting company data into ChatGPT and Claude without approval. Shadow AI creates data leaks, IP loss and compliance violations. https://www.sherlockforensics.com/blog/shadow-ai-employee-risk.html - Android Forensic Acquisition for $399: Sherlock Forensics Android Acquirer: logical extraction via ADB with SHA-256 per artifact. Free + Forensic Edition from $399. Cellebrite alternative. https://www.sherlockforensics.com/blog/sherlock-android-acquirer-launch-2026.html - Browser Forensic Viewer for $29: Sherlock Forensics Browser Viewer: extract history, bookmarks, downloads from 8 browsers. Free to view, $29 for CSV export. Forensic-grade. https://www.sherlockforensics.com/blog/sherlock-browser-viewer-launch-2026.html - Free Forensic Disk Imager That Resumes: Free forensic disk imager with E01, raw dd, three-pass SHA-256 verification and resumable imaging. FTK Imager alternative. 4.4 MB. https://www.sherlockforensics.com/blog/sherlock-disk-imager-launch-2026.html - We Built a Forensic PST Viewer for $67: Why we built Sherlock Forensics PST Viewer. Court-ready reports, SHA256 per message, $67 instead of $300. The story behind our forensic email tool. https://www.sherlockforensics.com/blog/sherlock-forensics-pst-viewer-launch-2026.html - Sherlock Forensics: Who We Are and What We Do: Sherlock Forensics provides cybersecurity, penetration testing and digital forensics across Canada. 20 years experience, CISSP certified, court-qualified. https://www.sherlockforensics.com/blog/sherlock-forensics-who-we-are.html - PST Viewer Now Opens MSG and EML Files: Sherlock Forensics PST Viewer v1.2.0 reads MSG and EML files with SMTP transport chain analysis, anomaly detection and MAPI timestamps. Free download. https://www.sherlockforensics.com/blog/sherlock-pst-viewer-msg-eml-update-2026.html - SOC 2 Pentest: What Auditors Want: What SOC 2 auditors actually check in your pentest report. Scope, methodology, timing and the 3 findings that fail every audit. From $5,000 CAD. https://www.sherlockforensics.com/blog/soc-2-pentest-requirements-what-auditors-want.html - SOC 2 Audit Timeline: What to Expect: Month-by-month SOC 2 audit timeline from readiness assessment through final report. Plan your Type I or Type II audit preparation. https://www.sherlockforensics.com/blog/soc2-audit-timeline-guide.html - SOC 2 Pentest Checklist: What CPAs: A checklist for CPAs and auditors reviewing SOC 2 penetration test reports. What to look for. https://www.sherlockforensics.com/blog/soc2-pentest-checklist-for-cpas.html - Spring Security Cleaning: 10 Things to: Spring cleaning for your security posture. Remove old accounts, rotate keys, patch outstanding CVEs and test your incident response plan. https://www.sherlockforensics.com/blog/spring-security-cleaning-10-things-to-review.html - The CTO Guide to Letting Your Team Use: Enterprise policy template for AI coding tools. What to allow, what to require and how to say yes to AI without compromising security. https://www.sherlockforensics.com/blog/the-cto-guide-to-letting-your-team-use-ai-safely.html - The Device Your Network Cannot See: ShadowTap Ghost Mode uses LTE cellular for all command-and-control while sitting physically on your network. https://www.sherlockforensics.com/blog/the-device-your-network-cannot-see.html - The Indie Hacker's Guide to Not: You are one person against every script kiddie and bot on the internet. A casual, direct guide to not losing. Written for indie hackers who ship fast. https://www.sherlockforensics.com/blog/the-indie-hackers-guide-to-not-getting-hacked.html - The Password Was Literally in a Text: Took us 4 minutes to find the database password. passwords.txt in the public directory. A war story of escalating security findings from one engagement. https://www.sherlockforensics.com/blog/the-password-was-literally-in-a-text-file.html - The Solopreneur's Security Checklist:: 10 security checks every solopreneur should run before launching. HTTPS, password hashing, API keys, rate limiting and more. Free checklist with how-to steps. https://www.sherlockforensics.com/blog/the-solopreneurs-security-checklist.html - Top 10 Firewall Misconfigurations We: Ten firewall misconfigurations we find in nearly every penetration test: default credentials, any-any rules, no egress filtering, logging disabled. https://www.sherlockforensics.com/blog/top-10-firewall-misconfigurations-we-find.html - Top 10 Things We Find in Every: Top 10 pentest findings ranked by frequency. Default credentials, broken access control, missing rate limiting, SQL injection and XSS from real engagements. https://www.sherlockforensics.com/blog/top-10-things-pentests-find.html - 8 Types of Penetration Testing: The 8 types of penetration testing explained: external, internal, web app, API, mobile, social engineering, wireless, cloud. Which do you need? https://www.sherlockforensics.com/blog/types-of-penetration-testing.html - Vibe Code Audit: What to Expect and: A vibe code audit is a security review of applications built with AI coding tools like Cursor, Replit and Claude Code. https://www.sherlockforensics.com/blog/vibe-code-audit-what-to-expect.html - Your Vibe-Coded App Got Hacked. Now Wha: Incident response for vibe-coded applications. You built it in a weekend with Cursor. An attacker dismantled it in an afternoon. Here is the recovery playbook. https://www.sherlockforensics.com/blog/vibe-coded-disaster-recovery.html - Vibe Coding Prompts for Secure Developm: 10 copy-paste security prompts for vibe coders. Check your AI-generated code for SQL injection, hardcoded secrets, broken auth and more. https://www.sherlockforensics.com/blog/vibe-coding-prompts-for-secure-development.html - Vibe Coded It? Someone Will Hack It: Vibe coding ships apps fast. It also ships vulnerabilities. Common risks in Cursor, Bolt and Lovable apps and how to fix them before launch. https://www.sherlockforensics.com/blog/vibe-coding-security-risks.html - We Audited Our Own Website. Here Is: Sherlock Forensics ran penetration testing tools against its own website and documented every finding honestly. https://www.sherlockforensics.com/blog/we-audited-our-own-website-heres-what-we-found.html - We Cloned Your Network Identity. Your: ShadowTap Anti-Antigena clones MAC prefixes from the most common vendor on your network. https://www.sherlockforensics.com/blog/we-cloned-your-network-identity-your-ai-didnt-notice.html - We Scanned 100 Websites Built With AI.: 92% had critical vulnerabilities. 78% stored secrets in plaintext. Data from scanning 100 AI-built websites with severity breakdowns and category analysis. https://www.sherlockforensics.com/blog/we-scanned-100-websites-built-with-ai-heres-what-we-found.html - We Tested After CVE-2026-27243: 4 new Cross-Site Scripting (XSS) CVEs this week including CVE-2026-27243 (CVSS 9.3). What Startup Security teams need to know. https://www.sherlockforensics.com/blog/we-tested-after-cve-2026-27243-here-is-what-we-found.html - What Cyber Insurers Look for in a: Cyber insurers evaluate pentest reports on seven criteria: scope definition, methodology, CVSS ratings, remediation steps, executive summary. https://www.sherlockforensics.com/blog/what-cyber-insurers-look-for-in-a-pentest-report.html - What Happens When You Store Passwords: Why storing passwords in.txt or.json files is dangerous: directory traversal, server misconfiguration, no hashing. Learn the attack path and how to fix it. https://www.sherlockforensics.com/blog/what-happens-when-you-store-passwords-in-text-files.html - What Is AI Slop? [Definition and: AI slop is unreviewed code from AI assistants that compiles correctly but contains security vulnerabilities. https://www.sherlockforensics.com/blog/what-is-ai-slop.html - What Is Penetration Testing? Explained: Penetration testing explained in plain language. What it is, why it matters, what happens during one, what the report looks like and how much it costs. https://www.sherlockforensics.com/blog/what-is-penetration-testing-explained-simply.html - What Is Vibe Coding? [2026 Definition]: Vibe coding is building software using AI assistants with minimal manual coding. Learn the security risks. https://www.sherlockforensics.com/blog/what-is-vibe-coding.html - What to Expect from Your First Penetration Test: First pentest? Here is what happens before, during and after. Scoping, rules of engagement, the report and remediation. No surprises. https://www.sherlockforensics.com/blog/what-to-expect-from-first-pentest.html - SaaS Pentest Scope: What Vendors Miss: How to scope a SaaS pentest: API endpoints, auth flows, multi-tenant isolation and integrations. What other vendors skip and why it matters. https://www.sherlockforensics.com/blog/what-to-include-in-saas-pentest-scope.html - When Was the Last Time You Tested Your: Companies buy firewall, EDR, NDR, SIEM and MFA but never test them together. ShadowTap tests your entire security stack simultaneously to find gaps. https://www.sherlockforensics.com/blog/when-was-the-last-time-you-tested-your-security-stack.html - Who Checks the Checker? Why You Need: Companies spend millions on Darktrace, CrowdStrike and Sentinel but never test if they actually work. https://www.sherlockforensics.com/blog/who-checks-the-checker-validating-your-security-tools.html - Why Choose a 20-Year Veteran Over a: Experience matters in penetration testing. A 20-year veteran catches business logic flaws. https://www.sherlockforensics.com/blog/why-choose-a-20-year-veteran-over-a-startup-pentester.html - PST Files in eDiscovery: Why PST files are the #1 source of email evidence. Legal hold obligations, preservation steps and tools for litigation support. https://www.sherlockforensics.com/blog/why-outlook-pst-files-matter-for-ediscovery.html - Your AI-Built App vs. a Real Attacker:: A minute-by-minute walkthrough of how an attacker compromises a typical vibe-coded SaaS app. From recon to backdoor in under 60 minutes. https://www.sherlockforensics.com/blog/your-ai-built-app-vs-a-real-attacker.html - Your Cursor App Is Probably Leaking: How.env files end up exposed in apps built with Cursor, Bolt and Lovable. How to check if yours is leaking and how to fix it in 5 minutes. https://www.sherlockforensics.com/blog/your-cursor-app-is-probably-leaking-env-vars.html - Your Firewall Configuration Has Never: Most firewalls are configured once and never validated. Years of rule bloat create a false sense of security. https://www.sherlockforensics.com/blog/your-firewall-config-has-never-been-tested.html - Your First Paying User Changes: The moment someone pays you or gives you personal data, security stops being optional. PIPEDA, GDPR and breach notification laws apply. Here is what changes. https://www.sherlockforensics.com/blog/your-first-paying-user-changes-everything-about-security.html - Your NDR Sees 80% of Traffic. What: Encrypted tunnels, DNS exfiltration, ICMP tunnels, non-standard ports and identity rotation. The 20% your NDR misses is exactly where attackers operate. https://www.sherlockforensics.com/blog/your-ndr-sees-80-percent-of-traffic-what-about-the-other-20.html - Zero Trust Is Not Zero Risk: Zero trust architecture from Zscaler, Cloudflare and BeyondTrust has real limitations. https://www.sherlockforensics.com/blog/zero-trust-is-not-zero-risk.html - Healthcare Cybersecurity 2026 | HIPAA and Ransomware: Healthcare breaches cost $10.93M average. HIPAA Security Rule requirements, ransomware targeting hospitals and what your security program needs in 2026. https://www.sherlockforensics.com/blog/healthcare-cybersecurity-2026.html - OSINT Recon Guide for Beginners | External Reconnaissance: How to run external reconnaissance on your own organization. Domain enumeration, DNS analysis, port discovery and credential leak checks. Free tools included. https://www.sherlockforensics.com/blog/osint-recon-beginners-guide.html - SOC 2 Penetration Testing | What Auditors Want: SOC 2 Trust Service Criteria CC7.1 and CC7.2 require penetration testing. What auditors read in your report, common fails and how to pass. https://www.sherlockforensics.com/blog/soc2-pentest-what-auditors-want.html - Best Free PST Viewers Compared (2026): Comparison of the best free PST file viewers for 2026. Feature matrix covering deleted recovery, sensitive-data scanning, OST support and forensic reports. https://www.sherlockforensics.com/blog/best-free-pst-viewers-compared-2026.html - copy.fail: 732-Byte Linux Root Exploit: CVE-2026-31431: 732-byte Python script that roots every Linux box since 2017. Container escape via kernel crypto bug. 7-step self-check guide to find out if you are vulnerable. https://www.sherlockforensics.com/blog/copy-fail-linux-container-escape-cve-2026-31431.html - How to Block USB Drives on Windows (3 Methods): Block USB storage devices on Windows without Group Policy. Per-device IOCTL blocking, registry method and GPO compared. Free USB Blocker download. https://www.sherlockforensics.com/blog/how-to-block-usb-drives-windows.html - How to Open a PST File Without Outlook (3 Methods): Open PST files without Microsoft Outlook installed. Free PST viewer download, step-by-step instructions. Also opens OST, MSG and EML files. https://www.sherlockforensics.com/blog/how-to-open-pst-file-without-outlook.html - How to Safely Open Unknown PDFs (Without Getting Hacked): How to safely open PDFs from unknown senders. Block JavaScript, embedded executables and auto-launch attacks. Free sandboxed PDF viewer download. https://www.sherlockforensics.com/blog/how-to-safely-open-unknown-pdfs.html - Is Your Stack Vulnerable to SQL: 2 new SQL Injection CVEs this week including CVE-2026-7097 (CVSS 8.8). What Compliance teams need to know. https://www.sherlockforensics.com/blog/is-your-stack-vulnerable-to-sql.html - Path Traversal Is Surging: 3 New CVEs: 3 new Path Traversal CVEs this week including CVE-2026-7498 (CVSS 8.8). What Digital Forensics teams need to know. https://www.sherlockforensics.com/blog/path-traversal-is-surging-3-new-cves.html - Safe PDF Viewer for Windows - Open Suspicious Files Without Risk: The safest way to open a suspicious PDF on Windows. Sherlock parses files in a Rust sandbox before rendering. Threat Inspector scans for phishing and malware. Free download. https://www.sherlockforensics.com/blog/safe-pdf-viewer-windows.html - Secure PDF Viewer vs Antivirus: Why You Need Both: Antivirus scans PDFs after download using known signatures. A secure PDF viewer performs structural analysis before rendering. Learn why you need both layers of PDF malware protection. https://www.sherlockforensics.com/blog/secure-pdf-viewer-vs-antivirus.html - Why Every PDF You Open Is a Security Risk: PDFs are the #2 malware delivery vector. Learn how PDF exploits work, why your reader executes code without consent and how to protect yourself. https://www.sherlockforensics.com/blog/why-every-pdf-is-a-security-risk.html - Sherlock Forensics OCR Reader: Free forensic OCR tool for Windows with Tesseract 5 LSTM engine. Per-word confidence scoring, ed25519 hash-chained audit trails, 7 export formats including EDRM XML v1.2. Batch OCR with 1-32 workers. Forensic Edition $67. https://www.sherlockforensics.com/pages/sherlock-ocr-reader.html - Sherlock Forensics Linux Launch 2026: 8 Sherlock Forensics desktop tools now available for Linux x64 as native binaries. PST Viewer, OCR Reader, PDF Editor, Android Acquirer, Browser Viewer, Port Scanner, Hash Calculator and Metadata Inspector. Ships as.tar.gz archives. Requires libgtk-3, libfontconfig1 and libxkbcommon. https://www.sherlockforensics.com/blog/sherlock-forensics-linux-launch-2026.html