The $0 Pentest Stack: Free Tools, Real Frustrations, and What I Learned Building a Security Practice

Time: 3:00 PM CT

Room: Room 1

Speaker: Mark Wharton

Description

Most penetration testing guides show you the final workflow. Nobody talks about what it actually looks like to build a security practice from scratch using only free and open-source tools — the incompatibilities, the missing connective tissue, the hours spent reformatting output from one tool so another tool can read it.

This is that talk. We’ll walk through the real journey: starting with nothing but time and freely available tools (BloodHound, Certipy, Impacket, kerbrute, hashcat, Burp Community), the moments where “works great with X” absolutely did not work with X, and the workflow problems that nobody’s documentation covers.

The goal isn’t to discourage you — it’s the opposite. The free toolchain is genuinely powerful. But understanding where the friction points are, what you have to bridge manually, and how to think about the end-to-end workflow before you start saves you the weeks of frustration I had to spend. Whether you’re an IT admin who wants to run your first internal assessment, a security analyst evaluating your defensive posture, or someone just starting to learn offensive security — this talk gives you the honest map, not the polished one.