Practical guides, interactive security labs, and downloadable tools built to help teams understand testing, findings, scoping, and remediation guidance.
Whether you are preparing for an assessment or trying to make sense of a finding in a report, start with the section that matches what you need.
The library spans assessment planning, identity and infrastructure, and web security. Pick the topic that matches the question in front of you.
Questions and evaluation criteria for comparing penetration testing providers beyond methodology language and tool lists.
Read the guide Buyer GuideUnderstand what automated scanning can tell you, what manual testing adds, where AI fits, and how to tell whether you are buying a penetration test or a scan with a different label.
Understand the difference Assessment PlanningUnderstand the information needed to define an assessment, estimate effort, and gather the details needed for penetration testing or other security reviews.
Start scopingUnderstand passwords, passphrases, password managers, multi-factor authentication, passkeys, common credential attacks, exposed credentials, and why length and predictability matter.
Understand credential security Exposure & Reconnaissance GuideUnderstand what the dark web actually is, what exposed data can appear there, why old credentials still matter, and how attackers use that information during reconnaissance.
Demystify the dark webBreak down CSP directives, source expressions, fallback behavior, and the common gotchas that determine what a browser is actually being told to trust.
Understand CSP Browser Security GuideUnderstand how HSTS changes browser behavior, what max-age and includeSubDomains mean, and why preload should be a deliberate decision rather than a copied setting.
Understand HSTSInteractive tools and guided demos that make common web security controls easier to understand, reproduce, and discuss with developers or stakeholders.
Review common HTTP security headers, see the values the application returns, and identify protections that appear present, missing, or worth a closer look.
Check security headers Guide + Interactive TesterUnderstand how clickjacking works, check whether a page can be framed by another site, and review browser framing protections such as CSP and X-Frame-Options.
Explore clickjacking Guide + Interactive LabA plain-English walkthrough of Cross-Origin Resource Sharing (CORS), including controlled demos, a GET-based browser test, and practical remediation guidance.
Explore CORSDownloadable worksheets and questionnaires for vendor evaluation, internal coordination, and assessment planning.
A structured interview and scoring tool for comparing penetration testing providers across technical depth, staffing, communication, reporting, and program maturity.
Download PDFAn offline version of the scoping questionnaire for teams that want to gather details internally before sending the information back to KobReySec.
Download PDFIf a guide or lab raised more questions than it answered, that is usually a good reason to talk through the actual environment, finding, or assessment objective.