<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://brackish.io/</loc>
</url>
<url>
<loc>https://brackish.io/blog/</loc>
<lastmod>2026-08-13</lastmod>
</url>
<url>
<loc>https://brackish.io/services/</loc>
</url>
<url>
<loc>https://brackish.io/topics/</loc>
</url>
<url>
<loc>https://brackish.io/about/</loc>
</url>
<url>
<loc>https://brackish.io/contact/</loc>
<lastmod>2026-08-27</lastmod>
</url>
<url>
<loc>https://brackish.io/partners/</loc>
</url>
<url>
<loc>https://brackish.io/privacy/</loc>
<lastmod>2026-08-27</lastmod>
</url>
<url>
<loc>https://brackish.io/affordable-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/external-pentest-companies/</loc>
</url>
<url>
<loc>https://brackish.io/illinois-pentest-companies/</loc>
</url>
<url>
<loc>https://brackish.io/internal-pentest-companies/</loc>
</url>
<url>
<loc>https://brackish.io/penetration-testing-in-the-midwest/</loc>
</url>
<url>
<loc>https://brackish.io/services/network-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/web-application-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/api-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/mobile-app-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/iot-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/social-engineering/</loc>
</url>
<url>
<loc>https://brackish.io/services/red-teaming/</loc>
</url>
<url>
<loc>https://brackish.io/services/vulnerability-scanning/</loc>
</url>
<url>
<loc>https://brackish.io/services/attack-surface-management/</loc>
</url>
<url>
<loc>https://brackish.io/services/cloud-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/secure-code-review/</loc>
</url>
<url>
<loc>https://brackish.io/services/configuration-reviews/</loc>
</url>
<url>
<loc>https://brackish.io/services/ai-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/physical-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/services/wireless-penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/topics/cloud-and-network-security/</loc>
</url>
<url>
<loc>https://brackish.io/topics/compliance-and-risk/</loc>
</url>
<url>
<loc>https://brackish.io/topics/iot-and-hardware/</loc>
</url>
<url>
<loc>https://brackish.io/topics/mobile-security/</loc>
</url>
<url>
<loc>https://brackish.io/topics/penetration-testing/</loc>
</url>
<url>
<loc>https://brackish.io/topics/red-teaming/</loc>
</url>
<url>
<loc>https://brackish.io/topics/social-engineering-and-phishing/</loc>
</url>
<url>
<loc>https://brackish.io/topics/web-application-security/</loc>
</url>
<url>
<loc>https://brackish.io/blog/captivecrunch-when-the-network-is-the-phish/</loc>
<lastmod>2026-08-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/healthcare-regulation-brief/</loc>
<lastmod>2026-08-07</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/phishingtest-compliance-security-control-clickrate/</loc>
<lastmod>2026-07-30</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/ai-phishing-what-to-look-for-when-the-old-tells-are-gone/</loc>
<lastmod>2026-07-17</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-first-ai-run-ransomware-attack-is-here-what-it-actually-means/</loc>
<lastmod>2026-07-09</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/five-questions-to-ask-before-you-trust-a-vendor-with-your-data/</loc>
<lastmod>2026-06-30</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-breach-that-skips-your-wi-fi-why-physical-security-still-matters/</loc>
<lastmod>2026-06-25</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/can-you-still-trust-your-own-eyes-a-plain-guide-to-deepfakes/</loc>
<lastmod>2026-06-19</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/shadow-ai-the-hidden-security-risk-your-employees-are-already-creating/</loc>
<lastmod>2026-06-15</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/staying-safe-on-wifi-while-you-travel-this-summer/</loc>
<lastmod>2026-06-12</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/most-attacks-dont-beat-your-defenses/</loc>
<lastmod>2026-06-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/penetration-testing-is-no-longer-a-checkbox-its-a-business-risk-control/</loc>
<lastmod>2026-05-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-95-32-problem-why-most-enterprises-are-pentesting-just-enough-to-fail/</loc>
<lastmod>2026-05-08</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-end-of-the-annual-pentest/</loc>
<lastmod>2026-04-24</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/what-a-pentest-actually-covers-and-what-it-does-not/</loc>
<lastmod>2026-04-15</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-clock-is-running-out-and-pentesting-is-no-longer-optional/</loc>
<lastmod>2026-04-03</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/dns-reconnaissance-for-defenders-using-dnsdumpster-to-map-your-external-attack-surface/</loc>
<lastmod>2026-03-26</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-expanding-attack-surface-why-visibility-alone-is-not-security/</loc>
<lastmod>2026-03-19</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/security-vs-compliance-why-passing-an-audit-isnt-the-same-as-being-secure/</loc>
<lastmod>2026-03-06</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/when-low-severity-becomes-high-impact-the-limits-of-vulnerability-risk-management/</loc>
<lastmod>2026-02-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/cvss-v4-vs-cvss-3-1-whats-new-and-improved/</loc>
<lastmod>2026-02-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-5-things-to-do-this-quarter-to-prepare-for-2026-cyber-threats/</loc>
<lastmod>2026-02-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/top-external-network-penetration-testing-findings-of-2025/</loc>
<lastmod>2026-01-21</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/ai-changed-the-rules-the-threats-you-need-to-model-in-2026/</loc>
<lastmod>2026-01-16</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/external-penetration-testing-in-2026-why-proactive-security-matters-more-than-ever/</loc>
<lastmod>2025-12-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-2025/</loc>
<lastmod>2025-12-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/why-linkedin-is-the-new-phishing-hotspot-and-what-your-organization-should-do-about-it/</loc>
<lastmod>2025-12-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/why-penetration-testing-is-no-longer-optional-lessons-from-the-sharepoint-breach/</loc>
<lastmod>2025-10-10</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-future-of-penetration-testing-how-ai-and-continuous-validation-are-redefining-security-in-2025/</loc>
<lastmod>2025-10-02</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/api-security-best-practices-for-protecting-your-application-interfaces/</loc>
<lastmod>2025-09-12</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-role-of-continuous-penetration-testing-in-modern-cybersecurity-strategies/</loc>
<lastmod>2025-07-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/red-teaming-vs-penetration-testing-understanding-the-differences/</loc>
<lastmod>2025-07-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/network-penetration-testing-strengthening-your-organizations-defenses/</loc>
<lastmod>2025-06-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/web-application-security-common-vulnerabilities-and-how-to-prevent-them/</loc>
<lastmod>2025-06-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/emerging-cyber-threats-preparing-your-organization-for-the-future/</loc>
<lastmod>2025-04-28</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/understanding-attack-surface-management-protecting-your-digital-assets/</loc>
<lastmod>2025-04-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/tsas-proposed-cybersecurity-rule-for-the-transportation-sector-the-need-for-penetration-testing/</loc>
<lastmod>2024-11-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/web-and-mobile-application-fuzzing-best-practices/</loc>
<lastmod>2024-10-09</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/what-are-default-credentials-a-penetration-testers-best-friend/</loc>
<lastmod>2024-09-24</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/part-1-understanding-the-basics-of-penetration-testing/</loc>
<lastmod>2024-09-09</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/logging-mobile-application-penetration-testing-6/</loc>
<lastmod>2024-08-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/physical-penetration-testing-why-every-company-should-prioritize-it/</loc>
<lastmod>2024-08-21</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/diy-penetration-testing/</loc>
<lastmod>2024-08-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/javascript-source-map-vulnerabilities/</loc>
<lastmod>2024-07-03</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/penetration-testing-findings-exposed-non-production-environments/</loc>
<lastmod>2024-04-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/iot-penetration-testing-part-1/</loc>
<lastmod>2024-03-04</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/mousejacking-with-flipper-zero-tales-from-pen-testing-trenches/</loc>
<lastmod>2024-02-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-ultimate-guide-to-protecting-your-business-from-phishing-scams/</loc>
<lastmod>2024-02-26</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/tales-from-pen-testing-trenches-mac-address-whitelisting-failure/</loc>
<lastmod>2024-02-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/different-types-of-penetration-testing-a-comprehensive-guide/</loc>
<lastmod>2024-02-01</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/penetration-testing-101-what-every-business-owner-should-know/</loc>
<lastmod>2024-01-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/risks-of-storing-passwords-in-bitbucket-repositories/</loc>
<lastmod>2024-01-24</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-risks-of-storing-passwords-in-sharepoint/</loc>
<lastmod>2024-01-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/what-is-blind-xss/</loc>
<lastmod>2023-12-18</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/android-studio-mobile-application-penetration-testing-5/</loc>
<lastmod>2023-12-15</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/another-oscp-blog-post/</loc>
<lastmod>2023-12-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/common-iot-device-vulnerabilities-in-2023/</loc>
<lastmod>2023-12-07</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-importance-of-comprehensive-iot-penetration-testing-in-modern-cybersecurity/</loc>
<lastmod>2023-12-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/shodan-series-part-2-the-untraditional-web-ports/</loc>
<lastmod>2023-11-28</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-power-of-password-complexity/</loc>
<lastmod>2023-11-26</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/not-all-penetration-tests-are-created-equally/</loc>
<lastmod>2023-11-20</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/iis-short-file-name-enumeration/</loc>
<lastmod>2023-11-17</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/shodan-series-part-1-the-accidental-open-door/</loc>
<lastmod>2023-11-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/even-more-mobsf-mobile-application-penetration-testing-4/</loc>
<lastmod>2023-11-10</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/penetration-testing-for-small-businesses-why-its-crucial-and-how-to-get-started/</loc>
<lastmod>2023-11-08</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/software-and-data-integrity-failures-owasp-top-ten/</loc>
<lastmod>2023-11-07</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/more-mobsf-mobile-application-penetration-testing-3/</loc>
<lastmod>2023-11-03</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/what-is-the-difference-between-vulnerability-assessments-and-penetration-testing/</loc>
<lastmod>2023-11-01</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/ai-enhanced-reconnaissance-fueling-sophisticated-security-breaches/</loc>
<lastmod>2026-08-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/does-affordable-penetration-testing-exist/</loc>
<lastmod>2023-10-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/mobile-application-penetration-testing-2-mobsf-intro/</loc>
<lastmod>2023-10-26</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/mobile-application-penetration-testing-1-getting-started/</loc>
<lastmod>2023-10-23</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/turkeys-will-get-stuffed-soon-credentials-will-get-stuffed-now/</loc>
<lastmod>2023-10-17</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/unmasking-the-shadows-the-unseen-vulnerabilities-within-your-walls/</loc>
<lastmod>2023-10-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/beyond-the-breach-the-essential-role-of-regular-penetration-testing-in-safeguarding-organizational-reputation/</loc>
<lastmod>2023-10-09</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/guarding-the-digital-front-door-the-external-penetration-test/</loc>
<lastmod>2023-10-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/white-box-web-application-testing-for-pentesters-and-bug-bounty-hunters/</loc>
<lastmod>2023-10-02</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-insecure-design/</loc>
<lastmod>2023-09-25</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-security-misconfiguration/</loc>
<lastmod>2023-09-21</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-broken-access-control/</loc>
<lastmod>2023-09-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/the-shield-of-cyberspace-understanding-web-application-firewalls/</loc>
<lastmod>2023-05-25</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/penetration-testing-white-box-black-box-and-grey-box-testing/</loc>
<lastmod>2023-05-01</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/cert-pinning-and-root-detection/</loc>
<lastmod>2023-04-22</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/insecure-direct-object-reference-idor-vulnerabilities-understanding-exploiting-and-detecting/</loc>
<lastmod>2023-04-21</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-mobile-application-security-testing-guide-mastg/</loc>
<lastmod>2023-04-19</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/reflected-xss-differences-and-relationship-with-stored-and-dom-xss/</loc>
<lastmod>2023-04-13</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/unraveling-the-intricacies-of-iot-penetration-testing/</loc>
<lastmod>2023-04-12</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-cryptographic-failures-2/</loc>
<lastmod>2023-04-04</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-server-side-request-forgery-ssrf/</loc>
<lastmod>2023-03-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/iot-testing/</loc>
<lastmod>2023-03-26</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/insecure-deserialization/</loc>
<lastmod>2023-03-20</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/phishing-and-tlds/</loc>
<lastmod>2023-03-15</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-identification-and-authentication-failures/</loc>
<lastmod>2023-03-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/local-administrator-accounts/</loc>
<lastmod>2023-02-28</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/phishing-the-most-important-thing/</loc>
<lastmod>2023-02-21</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/tls-versions-explained/</loc>
<lastmod>2023-02-20</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/wordpress-security/</loc>
<lastmod>2023-02-20</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/why-you-need-a-dmz/</loc>
<lastmod>2023-02-18</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/attack-surface-management/</loc>
<lastmod>2023-02-01</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/what-are-weak-hashing-algorithms/</loc>
<lastmod>2023-02-01</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/data-privacy-day/</loc>
<lastmod>2023-01-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/taking-over-organizr-accounts/</loc>
<lastmod>2023-01-25</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-injection/</loc>
<lastmod>2023-01-15</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/tutortrac-multiple-stored-xss/</loc>
<lastmod>2023-01-14</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-insufficient-logging-monitoring/</loc>
<lastmod>2023-01-08</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/owasp-top-ten-vulnerable-and-outdated-components/</loc>
<lastmod>2023-01-08</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/why-your-business-needs-a-penetration-test/</loc>
<lastmod>2023-01-01</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/what-is-zero-trust/</loc>
<lastmod>2022-12-25</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/credentials-gone-wild/</loc>
<lastmod>2022-12-19</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/a-password-manager-for-enhanced-cybersecurity/</loc>
<lastmod>2022-12-18</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/2/</loc>
<lastmod>2026-06-05</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/3/</loc>
<lastmod>2026-02-11</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/4/</loc>
<lastmod>2025-07-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/5/</loc>
<lastmod>2024-08-27</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/6/</loc>
<lastmod>2024-01-29</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/7/</loc>
<lastmod>2023-11-20</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/8/</loc>
<lastmod>2023-10-26</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/9/</loc>
<lastmod>2023-05-25</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/10/</loc>
<lastmod>2023-03-20</lastmod>
</url>
<url>
<loc>https://brackish.io/blog/page/11/</loc>
<lastmod>2023-01-29</lastmod>
</url>
</urlset>
