HTTP/2. What is it? How is it different? What does this mean for security? Modern web applications are moving to HTTP/2 to help deliver faster, more feature rich, real-time applications for the client. As a penetration tester we must adapt to this new protocol, not only to understand it and how to test it, but also what new attack surfaces it might provide. Sadly the current state of tools still seems to be lagging behind and don't work with this protocol. So, how do we take advantage of this protocol in our tests. We will have a look.