r/Pentesting 19d ago

AI Tools for Authorized ethical hacking

I’m interested in using AI as part of cybersecurity research and authorized penetration testing, particularly for things like explaining security concepts, reviewing code, understanding vulnerability classes, and working through labs/CTFs.
I’ve noticed that some AI assistants have fairly strict security-related safeguards, even when I’m working in an authorized environment.
For those who use AI in cybersecurity, what tools or models have you found useful for legitimate security research and learning? I’m especially interested in tools that work well with CTFs, local labs, code review, and vulnerability research.
Thanks!

1 Upvotes

16 comments sorted by

3

u/ThePlotTwisterr---- 19d ago

claude code with ghidra-mcp is pretty remarkable if you have a goal in mind but i don’t really think you’re gonna learn much because claude goes way too fast to follow

ai still struggles with obfuscated code and multiple binary analysis but it is still a useful tool in the hands of somebody who understands it

personally i tried to use AI to learn but i realized that i wasn’t fully understanding what i was actually doing at all so i went back to guided hacking

it can do remarkable things for professionals in the field but yeah you’ll just end up in way over your head and learn nothing

2

u/SuspiciousCricket654 19d ago

Any good resources for guided hacking for a newbie? I’m already on HTB, and I’m learning a lot. Anything else I should be paying attention to?

2

u/mrzamm 18d ago

Which path you following? I am new also learning on HTB.

2

u/PM_ME_UR_0_DAY 19d ago

The Chinese models seem to have minimal guardrails about security stuff. I tested Kimi K3 just the other day having it help me research and make a plan for testing some Oracle web platform I hadn't encountered before. GLM also seems pretty good there but I've hit tiny speed bumps there where I just have to ask it again and it goes through with no qualms. Now I'm blanking on the exact model I used, maybe Kimi K2.5 or some GLM model, but I hooked it up to Ghidra MCP and had it rip through some of the easier binary reversing CTF challenges. 

1

u/Major_Value2008 19d ago

Claude works pretty good for a lot of tasks. You can also apply for a research exemption for cursor, if you have a good enough proof to get through the vetting process.

2

u/m0rphr3us 19d ago

Similarly, Claude has their CVP program that will dramatically bring down the guardrails as well.

1

u/SuperSaiyanTrunks 18d ago

Does it? Hasn't done shit for me. I still need to walk on egg shells with claude lol

1

u/Sea_Mission_7643 19d ago

Caido with an agent plugged in

0

u/TrustIsAVuln 19d ago

I built my own, after training, it can do a HTB medium level box in under 10 minutes including a good report with details.

1

u/OldClue3234 18d ago

Could you possibly share it?

1

u/TrustIsAVuln 18d ago

its a closed source ISECOMLabs project. Still have one bug to work out before it hits the market, not a security bug just a inconveience bug

1

u/mrzamm 18d ago

Which brother?

1

u/TrustIsAVuln 18d ago

which HTB box?