Adding Pentest Sauce to your Vulnerability Management Recipe, will discuss the question we often get after performing a penetration tests: "Why didn't I see some of these vulnerabilities during our vulnerability scans?". We will discuss flaws that both attackers and pentesters exploit and why they do not typically show up in a Nessus, Nexpose, or [insert-vuln- scanner-name- here] scan. Most senior penetration testers and attackers will seldom leverage a vulnerability scanning tool as it's very noisy on a network and can get you detected/removed/bandwidth issues/etc. We will also discuss why many good pentesting techniques require manual testing and a creative attacker mindset. Lastly, we will review several things pentesters do regularly that could be adopted into a vulnerability management program.In the end we hope to share some tips and tricks that pentesters use so that others can adopt these techniques and raise the bar of any vulnerability management program.