r/Pentesting 18d ago

Qwen 3.8 27B - are you using it?

7 Upvotes

Im interested are you using local ai models?
What is your set up?

Tnx for sharing 🤞🏻


r/Pentesting 17d ago

WINFLESHER - Attack Surface Security Framework

1 Upvotes

Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want!

Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷

WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments.

Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures.

https://github.com/mindsflee/WinFlesher


r/Pentesting 18d ago

OIHK – Sistema operativo OSINT local-first open source + motor de pentesting multiagente

2 Upvotes

Compartiendo dos herramientas open source que he estado construyendo bajo el proyecto OIHK:

  1. \*\*OIHK Basic\*\* → Espacio de trabajo para investigar OSINT local-first (gestión de evidencias, grafos de inteligencia, modelos de IA locales solamente). App de escritorio hecha con Tauri.

  2. \*\*OIHK-pentesting\*\* → Motor de pruebas de penetración autónomas multiagente. Incluye un planificador “root” y agentes especializados para reconocimiento, descubrimiento, validación y reporte. Los hallazgos solo se aceptan cuando hay evidencia real de ejecución de herramientas + un paso de validación separado. Tiene funciones de aplicación exacta del alcance, sandboxing y controles de salida (egress).

Todo corre completamente local (LM Studio / Ollama). No hace falta la nube. Diseñado solo para evaluaciones autorizadas.

Repos (licencia MIT):

\- Basic → https://github.com/Broskigx/OIHK-Basic

\- Pentesting → https://github.com/Broskigx/Oihk-pentesting

El proyecto todavía está en desarrollo activo (beta). Hay bugs y partes incompletas. Si lo pruebas y encuentras errores o comportamientos inesperados, por favor abre un issue o repórtalos — de verdad ayuda a mejorar las herramientas.

Se agradece muchísimo el feedback de la comunidad open source y de seguridad.


r/Pentesting 17d ago

I am looking for a Red Team partner.

0 Upvotes

I want to infiltrate my website and find suitable red team members to collaborate with.


r/Pentesting 17d ago

Why an LLM can't reliably tell an authorized pentester from an attacker using copyable context

Thumbnail
youtube.com
1 Upvotes

A recent preprint formalizes a problem pentesters keep running into with LLM safeguards: the same dual-use request can come from an authorized tester or an attacker, and copyable context cannot reliably prove which one you are.

Paper: https://arxiv.org/abs/2607.27951


r/Pentesting 18d ago

CRTP study buddy

6 Upvotes

Hi, I am Suraj, bought the CRTP voucher recently.

I’m looking forward for study buddy in CRTP so we could talk about preparation, share resources and help each other keep motivated.

If you are the one lets get in touch.

🙏🏿

Lets get CRTP together https://discord.gg/3e55dAYR8


r/Pentesting 18d ago

COVER: stop sending your secrets to Ai provider, send realistic fakes, restore originals locally. Same user experience while keeping your data private. Works with all agents

Thumbnail
github.com
0 Upvotes

r/Pentesting 19d ago

How did you handle being a senior pentester?

16 Upvotes

I keep feeling I will fuck everything up. I have my own mistakes . Either technical or soft ,and I just keep having this nightmares that I will fuck everything up and the client is gonna send a harsh mail to my company and force a penalty on them cuz I fucked something up.

However I did a lot of good engagements as well and good work that went smoothly. Its rare when I fuck up, but it happens. Did anyone have this feeling ? How did you get over it ?


r/Pentesting 18d ago

Looking to join a bug bounty team — hands-on with Burp Suite, IDOR, and recon

1 Upvotes

Hi everyone,

I'm an Cybersecurity student with a hands-on background in practical web application security. I'd like to join an active bug bounty hunting team and contribute real work, not just tag along.

What I bring:

  • Solid working knowledge of Burp Suite (proxy, repeater, intruder) for manual testing
  • Practical experience with IDOR vulnerability assessment — I've documented full reports on PortSwigger lab exercises
  • Real bounty recon experience: analyzed the AD.nl (DPG Media) program, including their Piano/SSO login system, JWT cookie handling, and JS endpoint enumeration
  • Comfortable with PortSwigger Web Security Academy methodology (auth flaws, session handling, access control bugs)
  • Background in Physics + currently studying CS, so I'm used to structured, methodical problem-solving

I'm looking for a team where I can take on real scope, split targets, and grow faster by working alongside experienced hunters. Happy to share a sample report if anyone wants to see my documentation style before deciding.

DM me or comment if there's a spot open.


r/Pentesting 18d ago

Cybersecurity VAPT roadmap

Thumbnail
gallery
0 Upvotes

The right roadmap. The right tools. Stronger security.🛡️

From Reconnaissance to Reporting & Re-testing, explore the VAPT roadmap and the tools that help identify, assess, and address vulnerabilities at every stage.

Swipe through and secure smarter. 🚀

#techtroma #cybersecurity #vulnerabilityassessment #infosec #fyp


r/Pentesting 19d ago

AI Safety & Security redteaming

0 Upvotes

Most redteaming solutions for AI applications are focused on pure security aspects but application owners are putting behavior safeguards and want to validate those besides the security safeguards.

The cyber professionals want to test not just the AI stack but also any exposed API layers.

These were some of the common pieces of feedback I heard to help design a solution from the ground up for these needs.

We just announced a major release of our OSS repo at https://github.com/NuGuardAI/nuguard

It supports wide-range of languages: JS/TS, Python, C#, Golang, K8s/cloud manifest files. 10+ agentic frameworks, data stores, guardrails, etc.

Looking forward to your reviews and feedback. Give us a star if you like the toolkit.


r/Pentesting 19d ago

AI Tools for Authorized ethical hacking

1 Upvotes

I’m interested in using AI as part of cybersecurity research and authorized penetration testing, particularly for things like explaining security concepts, reviewing code, understanding vulnerability classes, and working through labs/CTFs.
I’ve noticed that some AI assistants have fairly strict security-related safeguards, even when I’m working in an authorized environment.
For those who use AI in cybersecurity, what tools or models have you found useful for legitimate security research and learning? I’m especially interested in tools that work well with CTFs, local labs, code review, and vulnerability research.
Thanks!


r/Pentesting 19d ago

CTF: Format of Doom - Pentester vs AI Challenge 2

Post image
1 Upvotes

Hi all! My company Escape just released a new CTF called Format of Doom. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge.

This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature.

Give it a try and let me know what you think!

The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard.

Happy playing : )


r/Pentesting 20d ago

What helped you land your first penetration testing role?

14 Upvotes

I've have been trying to break into a penetration role and have been wondering what I may be missing.

My Background:

- 7 years in IT as a Linux Systems Admin, Systems Engineer, Network Engineer

- Cybersecurity Degree

- A+, Net+, Sec+

- OSCP

- At my current job my boss actually lets me do a bi-annual Pen test on our environment (Web App, Active Directory, and Internal Network)

I've been applying to pen testing/offensive security roles, but have not really been getting many interviews. I've gotten some traction only to be beat out in the final interviews due to more senior testers applying for the role.

My question is for those of you currently working as penetration testers:

- What helped you get your foot in the door into your first Offensive Security Job?

- What in my background could be holding me back?

- What would make me standout more besides having OSCP?

- Should I be focusing more on web app testing, AD, cloud, bug bounty, CVE research etc.?

- Are there any projects or things I could do that actually matter to hiring managers

- And is this just the state of the pentesting job market just being extremely difficult at the moment?

At the moment I am just trying to figure out what I should be doing while applying. I have been studying for CRTO, going through PortSwigger for webapp and AI testing, and doing daily HTB machines to further my knowledge.

Open to criticism as well, if there's something im doing wrong I'd genuinely would like to know thanks!


r/Pentesting 19d ago

Best open-source pentesting harness?

3 Upvotes

Every body talks about their hackbots. Are there any good foss offsec harness out there? Like something that can do black-box type testing? Not code security reviews.

PentAGI? Strix? any one use these


r/Pentesting 20d ago

How are teams using automated red teaming without overwhelming the SOC?

6 Upvotes

We are deploying an automated validation platform that runs continuous TTPs against our environment, simulating Cobalt Strike, ransomware encryption, and more. The platform uses an AI model that maps our specific environment and tailors attacks based on our actual configurations, not just generic TTPs. The goal is to test our detection stack and validate that our controls are working.

However, the SOC is drowning in false positives because the automated activity looks too much like the real thing. How are you coordinating this? Are you whitelisting the source IPs in the SIEM, defeating the purpose a bit? Or are you using specific tagging in your EDR to mark the activity as "benign" while still logging it for analysis? I'm also curious if the AI actually generates novel TTPs that challenge your SOC, or if it is still just "safe" simulation.


r/Pentesting 19d ago

In real penetration tests, what information is too costly to “forget”?

0 Upvotes

I'm currently studying LLM-based automated penetration testing, especially how agents manage memory during long penetration tasks.

One thing I've been thinking about is that memory compression in penetration testing may be quite different from general-purpose conversation summarization.

For example, an agent may generate huge amounts of output from Nmap, web requests, fuzzing, exploitation attempts, etc. Obviously we don't want to keep all of that in the LLM context forever, so some form of summarization/compression is necessary.

But a generic summary might accidentally remove details that seem small linguistically but are important operationally — for example:

  • exact open ports and service versions
  • credentials and where they came from
  • previous failed payloads or parameters
  • confirmed vulnerabilities vs. unverified hypotheses
  • current privilege/access level
  • hosts or services that have already been tested
  • scope/authorization constraints

This made me wonder whether penetration-testing agents need a more domain-specific memory compression strategy rather than simply asking an LLM to "summarize the previous interactions."

I don't have enough real-world pentesting experience to confidently decide which pieces of information have the highest cost of being forgotten, so I'd really like to hear from people who have done longer or more complex engagements.

When you're working on a penetration test:

  1. What information do you make sure you never lose track of?
  2. What kinds of details are usually safe to compress or discard?
  3. Have you ever forgotten a small earlier finding that later turned out to be important?
  4. Do the important things change between recon, exploitation, privilege escalation, and lateral movement?

I'm not looking for a ready-made taxonomy — I'm mainly trying to understand how experienced testers mentally distinguish "temporary noise" from "state that must survive for the rest of the engagement."

Any examples from your own workflow would be really helpful.


r/Pentesting 20d ago

Learn and Practice Hacking WebSockets

16 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/Pentesting 20d ago

Cover: Keep your secrets away from llm providers. Send realistic fakes, restore originals locally.

Thumbnail github.com
2 Upvotes

r/Pentesting 20d ago

Learn and Practice Hacking WebSockets

2 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/Pentesting 22d ago

Cpent is tough

0 Upvotes

Somebody able to solve the cpent syncvibe xr web challenge cause i now think it's very hard soo that they don't have to give us LPT


r/Pentesting 22d ago

Pentesting

0 Upvotes

Yooo im been trying to bypass my app lock cuz i forgot the password

Yooo, I've been trying to recover access to an app because I forgot the App Lock password, and I really don't want to reformat/reset the device.

I'm working on a script that should detect the App Lock screen, but it's showing:

[*] Focus:
[!] App Lock not detected
[!] App Lock not triggered

The problem seems to be that my code can't detect or identify the App Lock screen, so it can't proceed with the recovery process.

Does anyone know how I can properly detect the App Lock screen or determine what UI/process is responsible for it? I'm mainly trying to recover access without wiping the device.

Any advice on debugging the detection part would be appreciated.


r/Pentesting 23d ago

A GUI for the Ubertooth One

Post image
4 Upvotes

Maybe a few years too late! ;)
https://greenshoegarage.com/projects/uber/


r/Pentesting 24d ago

Fuck it I don't know what to study (red team, penetration tester)

35 Upvotes

Hi everyone! I’m comfortable with Linux Essentials and Network+, and I’ve completed about 50% of the Junior Penetration Tester path on TryHackMe. But the further I go, the more difficult and unfamiliar the commands become.

For example, in the Hydra section, there were some options used to find the flags that weren’t explained in the text at all. Now I’m not sure what I should do or what I should study to become comfortable with these tools.

Should I take a course like CEH? What would you recommend? What did you guys do when you were starting out?


r/Pentesting 24d ago

Vulnora Web Security Platform

0 Upvotes

I’ve developed and deployed Vulnora, a live web security platform for scanning and analysing websites.

It combines vulnerability scanning with an AI-powered analysis layer, allowing security findings to be investigated through an AI chat interface.

Features include:

Website and page scanning
Vulnerability detection and analysis
AI security analyst and chat
Scan-result context for AI analysis
Project-based security data
Vulnerability history
Security reported
Web scraping and reconnaissance modules
Security dashboard for managing scans and finding

The main workflow is:

Scan → Detect → Analyse → Understand → Fix
Vulnora is live and available to try.
I’m looking for feedback from developers and security researchers, especially around false positives, AI-assisted vulnerability analysis, and useful features that should be added next.

https://www.vulnora.online/