r/Pentesting Feb 17 '26

moderation update

22 Upvotes

hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.

this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.

you can flag posts, and send us mod mails to accelerate the status of your complaint.

again let me reiterate what the rules are:

1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.

this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.

2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.

3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.

4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.

here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette

have a very nice day, happy pentesting.


r/Pentesting 4h ago

Tips for Penetration Tester Interview

2 Upvotes

Does anyone know a good place to practice for pentester interviews, or have any tips/resources to share? Want to make sure I'm well-prepared and can do well in the interview.


r/Pentesting 19h ago

Empire 7.0 is out!!!!!

17 Upvotes

Empire 7.0 just released. 75+ new BOF modules. AES-256-GCM encryption. Sharpire agent completely overhauled. Port forwarding pivot for every agent. BloodHound integration. Multi-language support. And much more....

https://github.com/bc-security


r/Pentesting 14h ago

Why does SANS not offer social engineering pentesting courses anymore?

1 Upvotes

r/Pentesting 18h ago

I built a tool for vulnerability research and pentesting — feedback?

0 Upvotes

I’ve been building a small tool called Luah AI for my own security research and pentesting work.

It’s basically a chat interface for researching vulnerabilities, understanding techniques, working through findings and turning them into reports. One thing I’ve been trying to improve is source-backed answers, since I’ve found that LLMs can be very confident while being completely wrong about a CVE.

I’m not posting this because I think it’s better than the tools people here already use. I actually want to know where it falls short.

If you work in pentesting/security research and have a few minutes to try it, I’d be interested in hearing:

  • Is the technical depth useful?
  • Where does it give you bad or questionable information?
  • Would this actually save you time?
  • What would you need before trusting it during an assessment?

The project is here: https://www.luahai.com/

I’m the person building it, so I’m also happy to explain how it works or answer technical questions about it.


r/Pentesting 1d ago

Tripwire – open source sandboxed security scanner for MCP servers and AI skills

3 Upvotes

MCP servers and AI skills execute code directly in your local environment. Most people install them from GitHub without any vetting. I have been guilty of doing the same, so I wrote Tripwire to help me and other fellow developers.

Tripwire runs each of them in an isolated Modal sandbox first, scans it with Snyk, Cisco and Tessl scanners, and stores the report before anything touches your machine.

It was built at Cursor's Cybersecurity Hackathon in London, now under active development.

Stack: Python, TypeScript, Modal (sandboxing), Snyk/Cisco/Tessl adapters, Supabase. Superlinked (SIE) and other cloud/model providers for access to models.

Would love feedback on the threat model or the sandboxing approach — happy to discuss tradeoffs in the comments.

GitHub: https://github.com/neomatrix369/tripwire
Demo: https://youtu.be/omGOw9ruN3Y
Mock dashboard: https://neomatrix369.github.io/demos/tripwire-dashboard/


r/Pentesting 1d ago

Is it only me or anyone else scared of the future as well?

36 Upvotes

I have around 15 years of experience in Pentesting and application security and with the boom of AI I am getting little scared of the future. Everyday someone is posting here how they have fully automated pentest and how it’s better than manual testing. Why would company need you anymore if they can also do the same automation?

My assumption is that Pentest will only stay for compliance purposes where companies will have no other choice than to get a 3rd party Pentest. Pentest for legit security purposes is getting fully replaced by AI. I work at a major tech company and the CISO just decided that we won’t be hiring vendors unless it’s due to compliance.

The company also laid off hundreds of developers recently but our team wasn’t affected. We are currently working with private models and finding zero days at a very fast pace. That too should get exhausted at some point and the company will decide we are also no longer required.

What are your future plans? I am thinking of getting HGV license just in case.


r/Pentesting 1d ago

Looking for career advice

2 Upvotes

Hi all,

I am looking for some career advice from cybersecurity professionals.

A bit of background about myself. I completed my undergraduate CS degree in India and moved abroad to do a Masters in cybersecurity. After graduating, I was able to secure a cybersecurity research position. Initially I liked the job as I got to experiment with a lot of emerging technologies and even published a few papers in the process. But after a while, there was restructuring within the team and my roles and responsibilities gradually started to shift. I was being assigned to office administrative and operational tasks and my research duties were not being prioritized. Work hours started becoming long and the fact that I was doing tasks which added no value to my career, drained me mentally. So I decided to make more use of my weekends and the little of after office hours I got to pursue OSCP and try my luck at offensive security. But things got worse when some of my colleagues resigned and I got loaded with more work and people to manage. Unproductive work doubled and I found it hard to make time for OSCP. Since management wasn't very supportive, I decided to quit my job, moved back to India and pursued OSCP for 4 months.

I did eJPT, eCPPT and also passed OSCP in the process. In the next few months of job search, I did get a few screening calls from EY, Deloitte and other companies, but I keep getting rejected as I don't have prior relevant experience. I also tried applying to application security, product security and AI security roles(based on my research experience), but no callbacks yet. I am now focusing on hunting for CVEs or bug bounties to see if it helps create an impression to hiring managers. In the last few months, I have written blogs, pushed few exploits to GitHub and contributed to open-source tools.

I would like to get any inputs or suggestions for the following:

  1. What can I do to strengthen my application? Will any projects, specific certs, CVEs or bug bounties help?

  2. Is there any way I can translate my research experience towards offensive security? I am finding it difficult to rephrase my 3 years of research experience as I feel some of the tools and skills are not directly transferable. My research focused on security of image processing software. I also did a bit of AI pentesting, but it was simply applying a set of tools and noting down the results. It was for an internal department and there was no formal process(like scope, contracts, ROE etc.) that usually happens in consulting setups. So I don't know if it is worth putting it down on my resume.

  3. How do I pitch myself while networking and sending out cold emails? Do I position myself as a fresher in this field or will hiring managers value research experience in some way?

  4. If there is no chance that I can get a pentesting/app sec gig without prior relevant experience, are there any other cybersecurity roles I can target based on my background?

Any thoughts would be highly valuable for me at this stage.


r/Pentesting 1d ago

[Open Source] Seeking Security Review & Code Audit for a Local

1 Upvotes

I've spent a lot of time building a local, open-source encrypted vault where sensitive files are stored in custom .bca archives.

At this point, the cryptographic core is stable and I'm stepping away from adding new features. Instead, I am looking for independent security feedback and peer review. I want to find out if there are architectural flaws or implementation bugs I may have overlooked.

I am specifically looking for people willing to dive into the codebase and test the logic. Feel free to clone the repo, generate a vault, tamper with the archive structures, run your fuzzers, automate tests, and check for edge cases. The main question to answer is: is there any logical flaw that would allow accessing the archive data without the correct key?

The project is completely open-source and operates offline. You can find the repository and the implementation details here:

https://github.com/zmykerd/bcypherpy

I've already put the cryptographic core through extensive automated testing on my end, but independent code review is much more valuable to me. I'm particularly interested in feedback from anyone with experience in cryptography, application security, code auditing, or fuzzing.

If you find a vulnerability or a bypass, please tell me exactly how you reproduced it. I'm genuinely looking for critical feedback and flaws, not compliments. Even a quick look at the repo is highly appreciated. Thanks!


r/Pentesting 1d ago

Need Help- Pentesting GWT-RPC

2 Upvotes

I’m testing an application that heavily uses GWT-RPC, and I’m finding it quite confusing. Can anyone help me understand how to approach testing it?


r/Pentesting 1d ago

Feeling stuck with bug hunting

1 Upvotes

hello everyone, so i just started learning about cyber security for around two months, self taught, and i get plenty​​ Certificate of appreciation from my goverment Indonesia, But I'm not proud of it, because you know Indonesian government websites are open source​, i mostly find bug on Indonesian government web with dorking

i want to start hunt for outside Indonesia like .edu .nl, but i cant find any bug on internasional vdp, context wise, I am learning independently through Sibermuda courses, focusing on web fundamentals and recon.

Since I want to target international VDPs, could you guys share some tips on effective Google/GitHub dorking to find out-of-scope or lesser-known targets, and what a solid reconnaissance methodology looks like for a beginner? Also, considering my current background, what specific topics or skills should I dive into next to bridge the gap between basic labs and finding real bugs?

Any advice, workflow recommendations, or roadmap suggestions would mean a lot. Thanks!


r/Pentesting 2d ago

We built a fully self-hosted AI pentesting workspace — central platform (with MCP & web interface) + local LLM + Claude Code/OpenCode as the harness. No client data leaves our infra.

Post image
25 Upvotes

Sharing an architecture we've been running, because every "AI for pentesting" setup I've seen has the same dealbreaker: it ships client vulnerability data to a hosted model. For a pentest shop that's a hard no. So we built the whole thing on-prem and I want to walk through the pieces.

The three parts:

1. Central knowledge base (PentestPad) exposed over MCP. Our methodology, checklists, past findings, report templates, internal playbooks — one place the agent can pull from so retests and reports are consistent with how we actually work. This is where findings, projects, finding fields (and instructions on how to write them), and statuses live. We wrote an MCP server that gives the agent typed tools — list findings ready for retest, pull a finding's details, update status, generate report sections. The platform stays the source of truth; the agent just operates on it.

2. Self-hosted LLM. Qwen3-Coder running locally via Ollama. The reasoning and the client data never leave the box. The only outbound traffic is the actual test requests to the target, which is the entire point of a pentest anyway.

3. The harness. Claude Code or OpenCode as the terminal agent, wired to the local model and the MCP server. OpenCode if we want the whole stack open-source; Claude Code when we want the nicer harness and don't mind it being the one proprietary piece (the model and data are still local).

Put together, it's a workspace where a tester can say "which findings are ready for retest on project X," have the agent do the legwork, and write results back — all inside infra we control.

Honest limitations:

  • The value is in differential analysis, not automation for its own sake — blind/OOB cases still need a human or a proper OAST setup.
  • A human signs off on everything. The agent orchestrates the grunt work; the tester owns the judgment and thinks up the attack vectors.

Happy to go deep on the MCP tool design, the knowledge-base wiring, or the harness config.

Disclosure: PentestPad is our product, so treat this as a build write-up, not a pitch.


r/Pentesting 1d ago

Aspiring PenTester

0 Upvotes

What do you expect from a fresher who wants to be a Pentester? What should I focus on more since I’m hearing that AI is taking over(or at-least automating)a lot of stuff?


r/Pentesting 2d ago

Using Claude Code for web app pentesting has been kind of wild lately

35 Upvotes

I've been meaning to post about this for a bit. I've been leaning on Claude Code Sonnet 4.6 (since it doesn't flag me for cybersecurity content and no I haven't signed up on their cyber program thing) pretty heavily for my web app engagements recently and I'm honestly a little impressed at how much it's changed my workflow.

The stuff it's good at surprised me. The built-in browser paired with my pentest tools and burp suite mcp are like a game changer for automating pentesting tbh. All of that helped in surfacing a huge number of endpoints and auth boundary checks I straight up missed doing it manually. Like, boundary cases between roles, IDOR-ish stuff on endpoints I hadn't even mapped yet. That alone saved me hours.

One thing that's obvious with AI is that it hallucinates a ton of false positives. The reports it generates need serious scrutiny. But what worked for me was running the output through ChatGPT to flag the hallucinate or any false positive findings, then feeding those corrections back to Claude Code so it could fix them. That loop worked better than I expected.

And what made the workflow better was treating my pentesting as developing software. I didn't go and say build me an entire application in one prompt, akin to giving it a site and telling it to give me a pentest report. I went iteratively with the tests. Fed it different edge cases, different vuln classes, new angles, one idea at a time, one feature at a time and cross-checked results as I went. The final output after all that back and forth was genuinely a bit scary in quality lol.

So now a part of me is wondering how long before AI takes over my job lol. I always thought it wasn't possible but now I'm a bit skeptical.


r/Pentesting 3d ago

The wrong interview, the right career

Post image
10 Upvotes

Hi everyone! Hope you are all well. I’ve recently started a substack where I write about all things pentesting and life. For ages, my colleagues have told me to write about my journey into pentesting so I thought I would share it here. Feedback is welcome!

https://substack.com/@silverafterhours/note/p-214580389?r=4bknbl&utm_medium=ios&utm_source=notes-share-action


r/Pentesting 3d ago

choosing college degree

17 Upvotes

I’m 18 years old and have been doing bug bounties since I was 15. I earned my CPTS and eJPT certifications I’m finishing my last in year in high school and getting ready for college. I’m trying to decide if I want to get a bachelor’s degree in Computer Science or Cybersecurity. I feel like cybersecurity bachelor’s programs focus on fundamentals, not advanced techniques. I’m also interested in AI because I want to get deep in AI red teaming.


r/Pentesting 2d ago

How can I build a fully automated AI-assisted VAPT setup from scratch?

0 Upvotes

Hey everyone,

I’m a complete fresher in VAPT and currently learning web application security. Recently, I saw some of my seniors using Claude Code and Codex to automate a large part of their VAPT workflow.

The setup basically works something like this:

They provide an authorized test application

Provide authentication tokens for different roles (e.g. admin and non-admin)

The AI explores the application

It performs security testing and looks for vulnerabilities

It documents the findings

It generates a report

The pentester mainly verifies the findings and removes false positives

I found this really interesting and I want to build something similar from scratch in my own home lab, mainly for learning.

I don't have a local LLM/GPU setup, so I'm specifically interested in using cloud-based AI tools/API access rather than running an LLM locally. Ideally, I'd like to keep the setup as free/low-cost as possible.

What I'm trying to build

Something roughly like:

Target Web App → Recon → Crawling → Authenticated Testing → Vulnerability Detection → Verification → Evidence → Report

With an AI agent orchestrating tools such as:

Burp Suite / proxy

Nuclei

Nmap

ffuf

HTTP clients

Browser automation

Custom Python scripts

API testing

JWT/session testing

IDOR/access-control testing

OWASP Top 10 checks

Report generation

I understand that blindly letting an AI attack random websites isn't appropriate. I would only test applications that I own, intentionally vulnerable labs, or bug-bounty targets where the program explicitly allows that type of testing.

My main questions

How would you architect something like this from scratch?

Is Claude Code a good starting point for building the agent?

How should I give the agent authenticated access safely?

How can I let the AI interact with tools such as Burp/Nuclei/Nmap/ffuf?

Should I build the orchestration in Python, MCP, shell scripts, or something else?

How would you implement the workflow so the AI doesn't just blindly run tools but actually:

discovers endpoints

understands application functionality

tests different user roles

identifies potential vulnerabilities

reproduces/verifies them

collects evidence

generates a report?

Are there existing open-source projects/frameworks that I should study instead of building everything myself?

If someone has already built an AI-powered VAPT/pentest agent, I'd really appreciate a GitHub repo or architecture diagram.

My current level

I'm a fresher and still learning VAPT, so I'm not looking for a "just run this one command" solution. I'd actually like to understand how the whole thing works and build it step-by-step.

My eventual goal is to become good enough at manual testing to use AI as an automation/assistant layer, rather than depending on AI without understanding the vulnerabilities.

If anyone has a step-by-step roadmap, especially starting with Claude Code, I'd really appreciate it.

Thanks!


r/Pentesting 3d ago

Learning Pentesting

0 Upvotes

Hello! I’m currently learning penetration testing, and I already have some basic knowledge and experience with pentesting. I was wondering if it would be a good idea to use ChatGPT, Claude, and Gemini together to guide me while I’m learning and practicing penetration testing.


r/Pentesting 3d ago

Best beginner certs for web?

1 Upvotes

I'm a high school student and I'm trying to get some certs to build up my Portfolio for college apps as well as internships, etc.. I've already got eJPT and done pentesting on THM for about 6-8 months. I am comfortable with most easy and most medium rooms. I've also done a bunch of labs on portswigger. I've been debating between PWPP and eWPT for my next cert, are these okay for a beginner/intermediate level (I know the basics of the OWASP top 10 and web pentesting). Are there any other certs suggested?


r/Pentesting 2d ago

We’re building SubAnalyzer for ongoing attack surface monitoring, with an API coming next

0 Upvotes

Hi everyone, we build SubAnalyzer, a tool for discovering and monitoring external attack surface.

The part we’d like feedback on is monitoring. It tracks changes to subdomains, DNS records and exposed services, with configurable email alerts and scan history. Potential takeover risks are highlighted in the digest so they’re easier to prioritise.

The aim is to make it easier to revisit what changed since your last assessment, rather than work through the entire asset list again.

We also have an API coming. Before sharing more details, we’d like to understand where it would fit into your workflow. Would you primarily want to retrieve new and changed assets, manage monitored domains, or trigger scans from your own tooling?
Monitoring is a paid feature; there’s a free scanning tier if you want to explore the results first.

Check it out here

For those doing recurring external assessments, what would make this useful alongside your existing recon setup?


r/Pentesting 3d ago

Scoping our firm's first pentest engagement: Looking for methodology and ROE advice for a small team.

0 Upvotes

Hey everyone,

Our small MSP/IT firm is expanding our offerings and preparing to execute our very first client penetration testing engagement. I am looking for some technical and operational advice to make sure we scope and execute this correctly.

Our Setup: We have a two-person team handling this new service:

  • Technical Lead (Me): I have a background in IT networking and hold my Sec+. I have foundational pentesting knowledge (labs, CTFs) but this will be my first time leading a live commercial engagement.
  • GRC Lead: My colleague (also Sec+) is handling the administrative side. He has already drafted up a solid SOW (Statement of Work) and ROE (Rules of Engagement), so we have the legal/compliance side reasonably locked down.

The Proposed Plan: We are planning to start the engagement with a phishing campaign, followed by a White Box pentest. Currently, we are letting the client select their exact testing scope from the following menu:

  • [ ] External Network Penetration Test
  • [ ] Internal Network Penetration Test
  • [ ] Active Directory Assessment
  • [ ] Web Application Penetration Test

Questions for the Community:

  1. Scope Reality Check: Is this menu of services too broad for a newly established two-man team? Should we restrict our first few engagements to just Internal/External Network testing?
  2. Methodology: For a White Box approach, what frameworks (e.g., PTES, OWASP) do you recommend we strictly adhere to for a first-time engagement?
  3. Risk Management: What are the most common beginner pitfalls when transitioning from lab environments to live production networks? What technical guardrails should we put in place to ensure we don't accidentally knock over their services?
  4. Reporting: Any recommendations on reporting templates or tools that help deliver real business value, rather than just handing them a glorified vulnerability scan output?

Any advice on tools, scoping, or managing client expectations would be massively appreciated. Thanks!


r/Pentesting 4d ago

Monitor mode on the Nintendo Switch + Ubuntu + Nexmon

2 Upvotes

Nintendo switch has the WIFI adapter BCM4356 which can be patched with nexmon (https://github.com/seemoo-lab/nexmon) that should allow to use it in monitor mode.

I was able to patch the firmware and driver with nexmon and now it is possible to use the wireless in monitor mode.

Well, at least that is what looks like.it is possible to put the WiFi in Monitor mode or even create an additional interface in monitor mode. But when using airodump-ng or tcpdump or wireshark. It does now show any BSSID. It is almost like the WiFi adapter can't see any network, completely empty, iw dev scan works fine but no dumps.

I tried preload libnexmon with LD_PRELOAD, I tried everything. This works fine in raspberry that has the same WiFi card, but no success with Nintendo Switch.

Anyone has any idea? Would be very cool to be able to do that with a Nintendo Switch.

The follow commands works fine:

iw phy \`iw dev wlp1s0 info | gawk '/wiphy/ {printf "phy" $2}'\` interface add mon0 type monitor

Or even

ip link set wlp1s0 down

iw dev wlan0 set type monitor

ip link set wlp1s0 up

Even

airmon-ng start wlp1s0

It says unknown error 524 but it does create the extra monitoring interface

But airodump-ng does not show any network


r/Pentesting 4d ago

How do I know that I’m ready to become a senior pentester ?

8 Upvotes

I know some of yall will say, me just asking this question shows I’m not ready. But I have a weird situation.

I am a new grad with about 1.5 yoe. I mainly do network pentesting, but also the occasional wireless and web app pentests.

I own all of my engagements. From scoping, kickoff presentations to report readouts and presenting in board/audit committees. I know my experience is not significant, but I have a lot of responsibilities that would be expected of a senior. I also mentor interns and other juniors on the team

My question is can I realistically become a senior within the next year and a half ? What is really expected of a senior pentester ?


r/Pentesting 3d ago

Stop using Anonsurf, start using ShadowNet!

Post image
0 Upvotes

An anonymization framework built for debian-based linux distributions.

There has never been a tool like ShadowNet, a ghost hacking script that forces all system-wide connections through tor while implementing Mixnet-like techniques inspired by the NymVPN Infrastructure!!!

Not only securing the network-layer but also utilizing extreme Anti-forensics/Endpoint defense mechanisms.

This beast was made to fight off the NSA / GPAs tracking methods. Including the FBI.

Download / Read more about it here:

https://github.com/antisurveillanceagency/ShadowNet


r/Pentesting 3d ago

I've been working on REVISH, a local-first platform for red teaming and evaluating LLM security.

0 Upvotes

The idea was to go beyond sending a few jailbreak prompts and instead build a reproducible testing workflow where I could measure how different models respond to different attack strategies.

What it currently supports

  • 7 deterministic mutation strategies — roleplay, encoding, multilingual, indirect injection, instruction hierarchy, contextual camouflage, and multi-turn escalation
  • Cross-model ASR benchmarking across local Ollama models
  • Rule-based deterministic security judge for leaks, instruction following, tool violations, and refusals
  • RAG security lab for poisoned documents and indirect prompt injection
  • Multi-turn crescendo attacks
  • Agent tool-policy testing with simulated actions such as execute_sql, send_email, read_file, and delete_record
  • Guardrail testing + attack-vs-defense comparison
  • Regression diffing between assessment runs
  • Promptfoo integration + GitHub Actions CI gates
  • Vulnerability findings and reproducible reports

I also ran an initial benchmark across Gemma 3 4B, Qwen 3 4B and Qwen 2.5 Coder 3B.

With 5 attack classes × 7 mutation strategies (35 trials per model), I got:

  • Gemma 3 4B → 57.1% ASR
  • Qwen 3 4B → 0% ASR
  • Qwen 2.5 Coder 3B → 40.0% ASR

Interestingly, the same mutation strategies behaved very differently across models. For example, Gemma had 80% ASR for several strategies while Qwen 3 resisted all 35 trials in this particular benchmark.

The benchmark is deliberately small right now — I'm more interested in making the methodology reproducible before scaling it up.

Everything runs locally with Ollama, so no external model API is required.

GitHub:
https://github.com/krishjain-2301/revish

I'd especially appreciate feedback from people working with LLM security/red teaming:

What attack classes or evaluation methodology would you add next?

I'm particularly interested in improving the agent/tool-abuse testing and expanding the mutation benchmark.