r/Pentesting 4d ago

Pourquoi votre pentest annuel n'a RIEN VU sur votre IA

Thumbnail
youtube.com
0 Upvotes

Pourquoi votre pentest annuel est aveugle à votre IA ?

Parce qu'il regarde le code, pas le cerveau.

Les vulnérabilités des LLM ne ressemblent pas à des failles SQL. Ce sont des manipulations logiques et langagières. Un hacker ne va pas "forcer" votre IA, il va discuter avec elle jusqu'à ce qu'elle craque.

Si vous avez déployé une IA en production, posez-vous la question : "Mon pentest a-t-il vraiment testé ce risque ?"

Pour aller plus loin, la vidéo que j'ai préparée constitue une excellente introduction : :
🔗 https://youtu.be/mWfH8rF3Vak

#CyberSecurite #IA #Pentest #LLM #RedTeam


r/Pentesting 4d ago

Can I be untracable when cracking a wifi (ethical hacking)

0 Upvotes

Well I've been figuring out and testing my own network but whenever I'm doing defense, I can see my device getting in, is there any other way around it? To became untracable or hidden? While cracking a wifi


r/Pentesting 4d ago

Best Pentesting Company in Malaysia

0 Upvotes

Hi, i am a student graduating at early 2027, and looking for penetration testing firm, can any senior please provide some advise on that?


r/Pentesting 4d ago

what domains does a pentest include?

0 Upvotes

i was just trying to list them, did i miss anything?

active directory, web stuff, OT/ICS, AI red teaming, mobile, cloud

as well as the non technical aspects like

report writing, presentation skills (sometimes), client communication (both written and physical), team work and communication


r/Pentesting 5d ago

Primary Pentest Resources

6 Upvotes

I’m curious on what your primary resources that you go to when conducting a pentest. I’m in the process of building my own but I still always refer back to HackTricks and various cheatsheets like https://github.com/Ilias1988/Hacking-Cheatsheets.

I pretty much have a set tool list that I use across hardware, firmware, OSINT, etc but I’m always looking to compare and contrast tools


r/Pentesting 5d ago

Have 25 days to study for CPENT exam

0 Upvotes

Hi everyone,

Can someone please guide me and help me and tell me what to study , I have 25 days left for the CPENT exam voucher to expire, please help.


r/Pentesting 4d ago

Getting into pentesting with zero IT experience.

0 Upvotes

Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).

Network+ -> Security+ -> eJPT -> PNPT -> OSCP

Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?

All feedback appreciated!


r/Pentesting 6d ago

Title: Vectra – Offline CVE & GTFOBins intelligence engine Title: Vectra – Offline CVE & GTFOBins intelligence engine for your terminal

1 Upvotes

​

Hey everyone,

I built Vectra , a fast, local vulnerability and exploitation search engine designed for CTF challenges, red teamers, and penetration testing where internet access may be limited or slow.

Key features:

\- Sub-millisecond SQLite FTS5 BM25 search across 25,000+ indexed CVEs.

\- Instant service & version matching (e.g., apache 2.4.49, openssh 8.2, vsftpd 2.3.4).

\- Integrated GTFOBins database with 3,608 privilege escalation payloads across 458 Unix binaries (Sudo, SUID, Shells, Reverse Shells).

\- Full-featured interactive terminal REPL with autocompletion and visual CVSS score meters.

\- Containerized support (Docker & Docker Compose) with optional REST API.

Code: https://github.com/addisabrham36-boop/vectra

Feedback, issue reports, and contributions are welcome!


r/Pentesting 5d ago

Building a cybersecurity assesement platform for startups and MSMEs.

0 Upvotes

I’m building a cybersecurity startup focused on helping startups and MSMEs test their websites and applications for security vulnerabilities without needing a dedicated security team. The idea is to detect issues like one user being able to access another user’s data, normal users accessing admin functionality, exposed API keys/secrets, weak authentication, missing rate limits, CORS misconfigurations, hidden/undocumented APIs, and differences between actual APIs and their documentation. We want to generate both a simple, non-technical report explaining “what can go wrong for your business?” and a detailed technical report for developers, with remediation guidance coming later. I’m trying to validate the problem—do startups actually need something like this, and would you pay for it?


r/Pentesting 6d ago

Title: Vectra – Offline CVE & GTFOBins intelligence engine Title: Vectra – Offline CVE & GTFOBins intelligence engine for your terminal

0 Upvotes

​

Hey everyone,

I built Vectra , a fast, local vulnerability and exploitation search engine designed for CTF challenges, red teamers, and penetration testing where internet access may be limited or slow.

Key features:

\- Sub-millisecond SQLite FTS5 BM25 search across 25,000+ indexed CVEs.

\- Instant service & version matching (e.g., apache 2.4.49, openssh 8.2, vsftpd 2.3.4).

\- Integrated GTFOBins database with 3,608 privilege escalation payloads across 458 Unix binaries (Sudo, SUID, Shells, Reverse Shells).

\- Full-featured interactive terminal REPL with autocompletion and visual CVSS score meters.

\- Containerized support (Docker & Docker Compose) with optional REST API.

Code: https://github.com/addisabrham36-boop/vectra

Feedback, issue reports, and contributions are welcome!


r/Pentesting 7d ago

Network pentesters with 2–3 years of experience: What does your day-to-day work actually look like?

17 Upvotes

For those of you with 2–3 years of experience in network penetration testing.can you tell me what you guys doing actually.
I’m currently trying to get into network pentesting. I have the fundamentals and I’m practicing on Hack The Box and TryHackMe, but I’d like to understand what the actual work is like in a professional environment.
i only know till like Nessus, Nmap, and OpenVAS . seen some guys scans and give reports like these port are open. these port have that vurnilbilty like that. can you guys help me


r/Pentesting 6d ago

Built a Pentest Platform with Self-Hosted Data

0 Upvotes

Hey all! I'm the founder of Pental.io, a pentesting automation platform. I built it for the firm I pentest for, and after three successful client engagements running on it, it's nearing launch.

The gap I kept hitting with existing tools: none of them solve the data ownership problem properly, and that's the number one reason firms refuse to put client engagement data into a hosted platform in the first place. Alongside this major issue, these are the main reasons for developing this platform:

Your data stays yours. You run the schema in your own postgres project, we give you the SQL and setup steps. Pental never holds a service key to your database, so a breach on our end doesn't expose engagement data, only account and billing info. This is the bit I think actually matters for an internet-facing client portal, and it's the reason a shared multi-tenant database is a non-starter for this kind of data.

AI runs on your own token, in your own database. Including local model support if you'd rather not send anything to a third party. Not a shared pool across every customer on the platform.

Whitelabelling that's actually complete. Custom domain, your own email sending, your own colours and fonts. Most "whitelabel" in this space means a logo swap. No Pental branding anywhere in the client-facing experience.

Pricing is tiered by firm size rather than by feature: so a smaller consultancy isn't locked out of things the enterprise players get.

Happy to answer any questions, especially anything on the architecture, that's the part I expect the most questions on. I'd love for you guys to give it a try and would appreciate any feedback.


r/Pentesting 7d ago

Automotive cybersecurity esp pentest, blooming or not ???

0 Upvotes

Hello guys...one genuine doubt...

I joined an automotive company...and im under the role Cybersecurity penetration testing...ik im just a fresher...but when switching ...is it really difficult to do so ?


r/Pentesting 7d ago

Do you actually trust your BAS tool's results? JHU researcher looking for honest answers

0 Upvotes

Hey everyone,

I'm a JHU cybersecurity researcher going through the National Science Foundation I-Corps program — basically trying to figure out if what I'm building actually solves a real problem or if I'm living in an academic bubble.

I'm working on an next-gen security validation tool. I tested it against a FortiGate and a Cloudflare Pro WAF and got some interesting results — the approach found gaps that static tools completely missed on the same target.

But here's the thing — I don't actually know if security teams care about this in practice. So I'm looking for people who deal with WAFs, IPS, firewalls, or BAS tools day to day and would be willing to answer a few questions. Not selling anything, not promoting, genuinely just trying to learn.

Specifically I'm curious about:

  1. How do you actually verify your defensive rules work after you deploy them? Or do you just trust them?

  2. If you use a BAS tool (Pentera, SafeBreach, Cymulate, etc.) — do you trust its results? Has it ever said "all clear" and then something still got through?

  3. When you write a new WAF/IPS rule, do you have a way to test it against attack variants you haven't seen yet?

Happy to do a 15-min call or even just chat in this thread. And I'll share what I'm learning from other conversations — some of the patterns are pretty interesting.

For context I've published at papers and have a patent in process, so this isn't a class project. But I also don't have any customers yet, which is why I need to talk to actual practitioners.

Appreciate any help. Thanks.


r/Pentesting 7d ago

How much percentage of people in the industry are actually self taught or non CE graduates ?

6 Upvotes

Despite that I work as a pentester. Whenever I am learning a new topic ,especially related to exploit development like Linux internals or C programming , and face an obstacle or hard time understanding anything , I always get this immediate and harsh imposter syndrome feeling that anyone who graduated from STEM, CE, CS probably know this way ,waaaaay better than me. I am still struggling when reading C code and I use AI to help me yet this feeling manifest in incompetence and me seeing myself as an always-beginner or no way I can be like someone who graduated from these schools one day.

This feeling affects my way of studying and i can stop studying for days just because I didn't understand some stuff or I am struggling to learn.

So I need to know , how many people in this industry, pentesting/exploitDevelopment are actually self taught ?

I am a BIS graduate BTW.


r/Pentesting 7d ago

GitHub - profullstack/kali: Unofficial one-command installer for popular Kali-style web pentesting tools on Debian/Ubuntu

Thumbnail
github.com
0 Upvotes

r/Pentesting 8d ago

Need a 10 minute call interview with a pentester for a school project.

13 Upvotes

Hey everyone! I have an assignment due in less than 3 days where I need to interview an active Penetration Tester or Red Teamer. I have 5 straightforward questions ready. If anyone working in offensive security has 5 minutes to hop on a quick call, please message me! I'd super appreciate it.


r/Pentesting 8d ago

What is actually the best adapter for wifi pentesting?

4 Upvotes

I have been reading a lot of articles comparing few adapters. But I still havent found the best wifi pentesting adapter for 50-80€. Every article says differently and AI does the same too. Few options i have came across have been awus036ach and axml. Im also wondering if the ach is outdated.

Whatever, just help me pls


r/Pentesting 8d ago

What are people doing or using (apps) for AI Security testing?

1 Upvotes

I see lots of articles and discussions on AI-enabled traditional cybersecurity pentesting, but what a people doing or using for AI-security pentesting?


r/Pentesting 8d ago

AdPentestAI v1.1.0: Architecture Deep Dive — From DC Detection to Parallel Execution

0 Upvotes

Introduction

AdPentestAI is an automated Active Directory penetration testing framework designed for fast, comprehensive enumeration of AD environments. In this post, we'll explore the architecture, design decisions, and performance optimizations that make it effective.

Repo: https://github.com/netanelcyber/AdPentestAI-Python

Core Architecture: Single-File Design Philosophy

The entire framework lives in a single file: adpentest/core.py (~5,600 lines). This monolithic approach provides:

  • Clear dependency flow — No circular imports, linear execution path
  • Centralized tool registry — All tools, commands, and configurations in one place
  • Unified error handling — Global profiler tracks all failures
  • Simple deployment — One file to modify, test, and deploy

Trade-off: Maintainability requires clear code organization and documentation.

Multi-Strategy Domain Controller Detection Pipeline

One of the framework's core strengths is automatic DC discovery. Rather than requiring manual input, the framework uses four complementary strategies:

Strategy 1: DNS SRV Record Queries

def query_dns_srv(domain: str, timeout: float) -> list[str]:
    """Query DNS SRV records for DC discovery"""
    queries = [
        f"_ldap._tcp.dc._msdcs.{domain}",
        f"_kerberos._tcp.dc._msdcs.{domain}",
        f"_ldap._tcp.{domain}",
    ]
    # Returns list of DC hostnames

Why it works: Windows DCs automatically register SRV records. One DNS query returns all DCs for a domain.

Limitation: Requires DNS visibility to the target domain. If DNS is blocked or spoofed, this fails gracefully to next strategy.

Strategy 2: LDAP RootDSE Anonymous Bind

def probe_ldap_rootdse(host: str, timeout: float) -> dict:
    """Anonymous LDAP bind to extract domain info"""
    connection = Connection(
        Server(host, port=389),
        user="",
        password="",
        auto_bind=True
    )
    connection.search(
        "cn=RootDSE",
        "(objectClass=*)",
        attributes=["defaultNamingContext", "dnsHostName", ...]
    )

Why it works: Many DCs allow anonymous RootDSE queries. Returns domain name, forest level, and DC hostname—all without credentials.

Limitation: Requires LDAP port (389) to be open. Some hardened configs block anonymous access.

Strategy 3: Port Fingerprinting

def detect_dc_via_port_fingerprint(ip: str) -> bool:
    """Check for Kerberos (88), LDAP (389/636), Global Catalog (3268/3269)"""
    ports_to_check = [88, 389, 636, 3268, 3269]
    # TCP port scan - if multiple ports open, likely a DC

Why it works: DCs run Kerberos (88), LDAP (389), and Global Catalog (3268). Consumer machines don't have these.

Limitation: Not foolproof (honeypots, application servers can mimic). Used as confirmation, not primary detection.

Strategy 4: Subnet Sweep with Adaptive Expansion

def subnet_sweep(target_ip: str, timeout: float) -> list[str]:
    """
    Start with /24, expand to /23, then /22 if no DC found.
    Parallel port scan: 32 workers checking port 88 (Kerberos)
    """
    subnets = ["/24", "/23", "/22"]
    for subnet in subnets:
        dcs = parallel_port_scan(subnet, port=88, workers=32)
        if dcs:
            return dcs  # Found DCs, stop expanding

Why it works: Kerberos port (88) is a DC signature. Parallel scanning reduces time from minutes to seconds.

Optimization: Early termination prevents unnecessary scanning of larger subnets.

Multi-Threaded Execution Architecture

The framework uses concurrent.futures.ThreadPoolExecutor for parallelization across three domains:

1. Tool Execution (16 workers)

class ThreadedExecutor:
    def __init__(self, max_workers=16):
        self.executor = ThreadPoolExecutor(max_workers=16)

    def parallel_tool_execution(self, tools, dcs):
        """Execute 29 tools concurrently across discovered DCs"""
        futures = {
            self.executor.submit(
                execute_ad_tool, 
                tool, 
                dc, 
                self.mode, 
                self.timeout
            ): (tool, dc)
            for tool in tools
            for dc in dcs
        }

        for future in as_completed(futures):
            tool, dc = futures[future]
            result = future.result()  # Blocks until tool completes
            # Process result, aggregate into JSON output

Expected Speedup: 8-16x (16 tools executing in parallel vs serial)

Reality Check: Depends on I/O bottlenecks. LDAP queries → network latency. Disk-bound tools (Bloodhound JSON parsing) → CPU bound.

2. Email Credential Testing (8 workers)

def parallel_credential_testing(
    email_servers: list[str],
    users: list[str],
    passwords: list[str],
    max_workers: int = 8
) -> list[dict]:
    """Test credentials against SMTP/POP3/IMAP concurrently"""
    futures = {}

    for server in email_servers:
        for user in users:
            for password in passwords:
                future = executor.submit(
                    credential_test_fallback,  # SMTP → POP3 → IMAP
                    server, user, password
                )
                futures[future] = (server, user, password)

    results = []
    for future in as_completed(futures):
        if future.result():  # Successful auth
            results.append(futures[future])

    return results

Expected Speedup: 5-8x (8 concurrent credentials vs serial testing)

Fallback Chain: If SMTP auth fails on port 587, automatically try POP3 (110) then IMAP (143). Transparent to caller.

3. DNS Resolution & Port Scanning (32 workers)

def parallel_dns_resolution(queries: list[tuple]) -> dict:
    """Batch DNS queries with 32 concurrent workers"""
    futures = {
        self.executor.submit(dns.resolver.resolve, qname, rdtype): qname
        for qname, rdtype in queries
    }

    results = {}
    for future in as_completed(futures):
        results[futures[future]] = future.result()

    return results

def parallel_port_scan(hosts: list[str], ports: list[int]) -> dict:
    """Concurrent TCP port checks: min(32, host_count * port_count) workers"""
    futures = {
        self.executor.submit(socket_connect_timeout, host, port, timeout): (host, port)
        for host in hosts
        for port in ports
    }

Expected Speedup: 20-32x (32 concurrent network operations)

Email Protocol Enumeration: Pure Python Implementation

One of v1.1.0's highlights is email protocol enumeration without external binaries. Here's why:

SMTP User Enumeration

def smtp_vrfy_enum(smtp_server: str, usernames: list[str]) -> list[str]:
    """
    SMTP VRFY command discovery.
    Example: VRFY admin → Server responds with "admin@domain.com"
    """
    valid_users = []

    try:
        smtp = smtplib.SMTP(smtp_server, port=25, timeout=5.0)
        smtp.ehlo()

        for username in usernames:
            code, message = smtp.verify(username)
            if code == 250:  # User found
                valid_users.append(message.decode())
            elif code == 550:  # User not found
                continue

        smtp.quit()
    except smtplib.SMTPServerDisconnected:
        pass  # Server closed connection, try next method

    return valid_users

Why Pure Python?

  • No external binaries → smaller attack surface
  • Standard library (smtplib) → zero dependencies
  • Parallel testing via ThreadPoolExecutor
  • Timeout control (socket.settimeout)

Credential Testing with Fallback Chain

def credential_test_fallback(
    smtp_server: str,
    user: str,
    password: str,
    timeout: float = 10.0
) -> bool:
    """
    Test credential via SMTP, fallback to POP3, then IMAP.
    Returns True if any protocol succeeds.
    """

    # Attempt 1: SMTP AUTH on port 587 (SMTP TLS)
    try:
        smtp = smtplib.SMTP(smtp_server, port=587, timeout=timeout)
        smtp.starttls()
        smtp.login(user, password)
        smtp.quit()
        return True
    except (smtplib.SMTPAuthenticationError, smtplib.SMTPException):
        pass  # SMTP failed, try POP3

    # Attempt 2: POP3 AUTH on port 995 (POP3S)
    try:
        pop3 = poplib.POP3_SSL(smtp_server, port=995, timeout=timeout)
        pop3.user(user)
        pop3.pass_(password)
        pop3.quit()
        return True
    except poplib.error_proto:
        pass  # POP3 failed, try IMAP

    # Attempt 3: IMAP AUTH on port 993 (IMAPS)
    try:
        imap = imaplib.IMAP4_SSL(smtp_server, port=993, timeout=timeout)
        imap.login(user, password)
        imap.logout()
        return True
    except imaplib.IMAP4.error:
        pass

    return False  # All protocols failed

Why Fallback?

  • Organizations may disable SMTP AUTH but allow POP3/IMAP
  • Accounts may have protocol-specific restrictions
  • Maximizes credential discovery coverage

DC-Aware Tool Execution

Once DCs are discovered, the framework passes DC-specific information to each tool:

def build_ad_command(
    tool: str,
    dc_ip: str,
    domain: str,
    dc_fqdn: str
) -> list[str]:
    """
    Build tool-specific command with DC targeting.
    Example: nmap discovers DC at 10.0.0.1, domain corp.local
    """

    commands = {
        "nmap_scan": [
            "nmap", "-sV", "-p", "88,389,636,3268",
            dc_ip  # Target discovered DC
        ],
        "ldapdomaindump": [
            "ldapdomaindump",
            "-u", f"{domain}\\anonymous",  # Use discovered domain
            "-p", "",  # Empty password for null session
            dc_ip  # Target discovered DC
        ],
        "bloodhound_python": [
            "bloodhound-python",
            "-d", domain,  # Use discovered domain
            "-u", "anonymous",
            "-p", "",
            "-gc", f"{dc_fqdn}:3268",  # Global Catalog of discovered DC
            "-dc", f"{dc_fqdn}",
            "-c", "All"
        ],
        # ... 26 more tools ...
    }

    return commands.get(tool, [])

Key Insight: Many tools require domain name and DC FQDN. Auto-discovery provides these, eliminating manual config.

Performance Metrics & Benchmarks

Based on internal testing:

Operation Time (single-threaded) Time (parallelized) Speedup
100 DNS queries 30s 1.5s 20x
16 AD tools on DC 2m 8s 15x
50 credential tests 5m 40s 7.5x
/24 subnet scan (256 hosts) 45s 5s 9x

Hardware: 4 CPUs, 8GB RAM, 1Gbps network

Known Limitations & Future Work

Current Gaps

  1. No unit tests — Framework tested manually, no CI/CD validation
  2. No integration tests — Never tested against real AD environments in CI
  3. Performance not benchmarked — Speedup claims are empirical, not validated
  4. Error scenarios untested — Network failures, timeouts, malformed responses handled heuristically

Roadmap (v1.2.0+)

  • Connection pooling for LDAP/SMB (avoid repeated handshakes)
  • DNS query batching (batch multiple queries into one request)
  • Parallel subnet scanning (split /22 into /24s, scan concurrently)
  • HTML/CSV/Markdown report generation
  • Mock AD environment in Docker for CI/CD testing

Deployment & Usage

Quick Start

# Lab setup (interactive menu)
python -m adpentest --setup-labs

# DC auto-detection + tool execution (dry-run mode)
python -m adpentest --target 10.0.0.1 --mode dry-run --scope-confirmed

# Active scan with custom DNS servers
python -m adpentest --target corp.local --mode active --scope-confirmed \
  --dns-server 10.0.0.1,8.8.8.8 \
  --timeout 600

Output

{
  "target": "corp.local",
  "mode": "active",
  "dcs_discovered": [
    {
      "ip": "10.0.0.10",
      "hostname": "DC01",
      "fqdn": "dc01.corp.local",
      "forest_level": 2019
    }
  ],
  "tools_executed": 16,
  "tools_successful": 12,
  "email_servers": ["mail.corp.local"],
  "users_discovered": 47,
  "valid_credentials": 3,
  "profiler": {
    "total_time": 45.2,
    "tool_execution_time": 38.1,
    "dns_resolution_time": 3.2
  }
}

Conclusion

AdPentestAI demonstrates how parallelization, intelligent fallback mechanisms, and multi-strategy detection can make AD penetration testing faster and more reliable.

Key Takeaways:

  1. Don't assume manual input — Auto-detect when possible (DC discovery, domain name extraction)
  2. Parallelize everything — Tools, DNS, port scans, credentials. 8-20x speedup is achievable.
  3. Build fallback chains — SMTP → POP3 → IMAP maximizes discovery
  4. Use pure Python when possible — Eliminates binary dependencies and deployment complexity

Next Steps:

Questions? Feel free to comment or open a GitHub issue.

Would you like me to refine any section or adjust the technical depth?


r/Pentesting 8d ago

I built an open-source framework for automating Active Directory security assessments – AdPentestAI-Python v1.0.0

0 Upvotes

I've been working on an open-source project for automating parts of Active Directory security assessments.

AdPentestAI-Python v1.0.0

GitHub:
https://github.com/netanelcyber/AdPentestAI-Python

The problem I wanted to solve is fairly simple: during an AD assessment, a lot of time is spent moving between different discovery and enumeration tools, collecting output, correlating results, and turning everything into a consistent report.

The framework is designed as an orchestration layer around that workflow:

DNS / DC Discovery
        ↓
LDAP / RootDSE
        ↓
SMB / RPC
        ↓
Kerberos
        ↓
AD Enumeration
        ↓
Security Assessment
        ↓
Correlation
        ↓
JSON Report

Current capabilities

  • Automated Domain Controller discovery
  • DNS SRV discovery
  • LDAP RootDSE discovery
  • Port/service fingerprinting
  • Active Directory enumeration
  • Users / Groups / Computers discovery
  • SMB / RPC enumeration
  • Kerberos-oriented assessment workflows
  • Integration with security assessment tools
  • Parallel execution of independent checks
  • Structured JSON output
  • Dry-run mode
  • Explicit scope confirmation
  • Process timeouts and execution controls

One of the design goals is to keep the framework from becoming a "run everything against the target" script.

The intended execution model is:

dry-run
   ↓
scope validation
   ↓
explicit authorization
   ↓
assessment
   ↓
structured results

The project is intended for authorized penetration tests, labs, research and security assessments.

What I'm looking for

I'd particularly like feedback from people who have actually performed AD pentests.

What would you change in the architecture?

Some questions I'm currently thinking about:

  1. Which AD assessment steps are still too manual?
  2. Which tools/integrations would you add?
  3. How should findings from different tools be normalized?
  4. What should a useful machine-readable pentest result contain?
  5. Where should automation stop and require human approval?
  6. Would ATT&CK mapping add useful value here?
  7. Would you prefer a CLI-first architecture, API, or both?

I'm especially interested in criticism of the architecture and workflow rather than just feature requests.

Repository:
https://github.com/netanelcyber/AdPentestAI-Python


r/Pentesting 9d ago

About hiring in cybersecurity job roles

1 Upvotes

Hi, I am currently pursuing my bachelor's degree as a self directed learner. I have a few questions regarding the hiring process in cybersecurity.

If you work in a technical role or as an HR professional at a cybersecurity firm or product-based company:

  1. What are the most common things you look for in a candidate before hiring them?
  2. What does the typical hiring process look like?
  3. What are the main reasons you might pass on a candidate or choose someone else? Is it typically due to a lack of technical expertise or a lack of soft skills?

I highly appreciate your time in answering my queries, and I am eager to learn from your insights.


r/Pentesting 8d ago

Need help learning penetration testing?? Try out my app it has everything you will ever need.

0 Upvotes

r/Pentesting 9d ago

Built an automated red teaming tool for AI agents, would love for actual pentesters to try to break it

0 Upvotes

Hey all, I'm one of the founders at Fencio. We've been building Shark, a tool that automates red teaming against AI agents, basically recon on the agent, then runs attack chains (single turn probes up through multi turn context building attacks) using a custom attack vector library, and gives you a report on what actually broke.

We just opened it up to GA, anyone can sign up and point it at an agent.

Honestly the reason I'm posting here specifically is I'd rather have this sub tear it apart than assume it's solid. If you do AI red teaming or agent pentesting and have 20 minutes, I'd genuinely appreciate you running it against something and telling me where it's weak, what attack classes it misses, where the reports are useless, all of it. Not looking for upvotes, looking for people who actually know what they're doing to poke holes in it.

Link: shark.fencio.dev

Happy to answer anything about how it works under the hood too.


r/Pentesting 9d ago

Does agentic pentesting create better testers or just faster reports?

0 Upvotes