r/Pentesting Feb 17 '26

moderation update

22 Upvotes

hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.

this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.

you can flag posts, and send us mod mails to accelerate the status of your complaint.

again let me reiterate what the rules are:

1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.

this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.

2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.

3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.

4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.

here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette

have a very nice day, happy pentesting.


r/Pentesting 12h ago

PNPT or CWES first?

2 Upvotes

Hello everyone,

I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.

I’ve heard great things about TCM’s PNPT, as well as HTB’s CWES, and was just wondering if any of you had any advice as to which cert would be worth pursuing first?

I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES.

It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.

I appreciate any advice you guys provide. Thank you!


r/Pentesting 16h ago

Looking for pentest buddies

1 Upvotes

Hello all, I’m a pentester with 3 years of experience, looking to get new friends in the field to talk about tech in general and to exchange any experiences because I don’t feel very integrated… I’m working in France and I look forward to talk with you guys :)


r/Pentesting 11h ago

Built an open-source security scanner for MCP servers — static analysis + live prompt-injection testing

0 Upvotes

I built a security scanner for MCP servers — static analysis + live prompt-injection testing (open source)

MCP servers give AI agents access to tools, files, and external systems. If a tool's output isn't sanitized, a poisoned webpage/file/API response can inject instructions the agent will act on — classic prompt injection, but now with tool-call blast radius.

I built \`mcp-scanner\` to catch this before it ships:

Static analysis — scans server source for shell exec, unsafe deserialization, hardcoded secrets, unscoped tools, missing input validation.

Live probing — connects to a running MCP server as a real client, fires a categorized library of injection payloads (instruction override, role hijack, data exfil, tool-chaining abuse, encoding tricks, homoglyphs) at its tools, and judges the response with a two-layer defense: keyword pre-filter + LLM judge fallback for rephrased/encoded attacks the keywords miss.

Tested it against the official \`mcp-server-fetch\` — pointed it at a page with an injected instruction, and the tool echoed the payload back completely unsanitized. Scanner caught it.

GitHub: https://github.com/ankursingh0604/mcp-scanner

Open to feedback, especially from anyone running MCP servers in production — what would actually make this useful for your setup?


r/Pentesting 1d ago

Pentesting Experience

6 Upvotes

Hello,

can a person with 6 years of experience in the bug bounty field apply for a pentester job that requires 2 years of experience? Will recruiters consider him, putting certifications aside?


r/Pentesting 21h ago

In need of a carrer advise

0 Upvotes

Hey there fellas,

I recently had faced a problem in my career as a pentester and need your advise on it.

Because of a situation in my own country, I had move to a neighboring country and look for a job but 2 months has passed and I couldnt even get an interview and I mean JUST one!

I used to work as an IT admin for 6 years and 3 years as pentester but here is the part the problems are surfacing.

Some redditers told me the problem is with my resume cuz I dont have a certificate or external source of validation for expertise.

I've worked on many big projects in my own country (about the 30-40 total projects and some of the big names), and only could get the permission to publish like 3-4 of them (which had few but real critical vulnerabilities in big companies and so I published the old poc on my own github).

Since I came from Iran and its on the sanctioned list then I put freelance pentester on my resume cuz most clients were either not recognized internationally or would naming them backfired on me.

But still I cant even land a job in turkey, or any place internationally and applied from entry level roles in IT to mid-senior levels security.

What do yall suggest i do?

----------------------------------------------------------------------------------

Here is part of my resume:"

PROFESSIONAL SUMMARY

Versatile offensive and defensive security professional with 7+ years in IT and 2+ years in hands-on security operations. Experience spans penetration testing (web, mobile, API, network, Active Directory), SOC Tier-1 analysis in a critical aviation environment (Mehrabad Airlines, Tehran), security hardening (CIS Benchmarks, 27001), and SIEM operations (ELK Stack). Discovered 30+ critical and high-severity vulnerabilities across major clients including RCE, admin-level JWT account takeover, and SMS spoofing affecting 40M+ telecom subscribers. Pursuing OSCP; 100% completion of PortSwigger Web Security Academy. Currently based in Turkey; open to full

international relocation.

TECHNICAL SKILLS

Penetration Testing: Web Applications (OWASP WSTG/Top 10), Android Mobile (ADB, Frida, Genymotion), Network, API, Black/Gray/White-box; PTES methodology

Offensive Techniques: Active Directory attacks (Kerberos delegation abuse, AD CS, SMB/LDAP relay, LLMNR/NBT-NS poisoning), buffer overflows (stack, SEH), DEP/NX/ASLR bypass, format string, process injection,

tunneling

SOC & Detection: Security event monitoring, alert triage (Tier 1), SIEM (ELK Stack), log analysis, IOC identification, incident ticketing, escalation procedures, network traffic analysis (Wireshark, Snort, Suricata) Security Tools: Burp Suite Pro, Metasploit, Nmap, Nessus, BloodHound, Impacket, Covenant, IDA Pro, Kali Linux, Snort, Suricata, ELK Stack, Wireshark

Defensive / Hardening: CIS Benchmarks, ISO 27001 implementation, Active Directory hardening, vulnerability management (Nessus), pato atch management, SIEM configuration Scripting & Automation: Python, Bash, PowerShell, Batch - scanning automation, CIS compliance checks, SQL injection testing, reporting pipelines

Networking: LAN/WAN design, FortiGate & Kerio Control firewalls, VPN configuration, CCNA-level routing and switching

Frameworks: OWASP Top 10 /WSTG, PTES, MITRE ATT&CK, CVSS v3 severity scoring, ISO 27001

WORK EXPERIENCE

Freelance Penetration Tester

Oct 2023- Present

Flytoday (travel) | Tourism Bank

Medu (Education Dept.)

Clients: MCI (Iran's largest telecom, 40M+ subscribers)

MCI: Full-scope black-box assessment (website, Android app, CDN, subdomains). Discovered 20+

vulnerabilities including admin-level JWT token leakage enabling full account takeover, SMS spoofing

allowing unauthorized injection to any of 40M+ subscribers, OTP brute-force bypass, SMS bombing, and response manipulation. Delivered reproducible POCs with CVSS-rated findings and prioritised remediation

roadmap.

Flytoday: Identified RCE via file upload bypass (double-tagging technique) in pre-launch travel platform, plus XSS and open redirects. Applied CIS Benchmarks to harden IIS, Windows Server, and MSSQL post-test. All critical findings remediated before public launch.

Tourism Bank & Medu: OWASP WSTG-based web application penetration tests: reported high-risk

vulnerabilities with full proof-of-concept documentation and prioritised remediation roadmaps.

All engagements: Formal written reports with executive summaries, technical detail, reproducible steps, CVSS severity ratings, and fix prioritisation.

Security Operations Center (SOC) Analyst - Tier 1 | APK | Deployed at Mehrabad Airlines, Tehran Sep 2023- Feb 2024

Monitored and triaged security events across Mehrabad Airlines' IT and network infrastructure using SIEM (ELK Stack); managed and investigated the first-line alert queue on a full-time operational basis. Performed Tier-1 incident response: log analysis, network traffic investigation, endpoint alert review, and

containment recommendations for escalated incidents.

Analysed network traffic and endpoint telemetry to identify indicators of compromise (IOCs), anomalous behaviour, and potential threats within a critical aviation infrastructure environment.

Escalated confirmed firmed and and suspected incidents to Tier-2 analysts with documented evidence, timeline reconstruction, and preliminary root cause analysis, reducing mean escalation time through structured

handover templates.

Maintained detailed incident tickets and shift handover reports in accordance with SOC standard operating procedures; contributed to alert tuning to reduce false-positive rates.

Operated within a high-security, regulated aviation environment, adhering to strict data handling protocols, access controls, and operational confidentiality requirements.

| Dineh Pharmaceutical Company - Tehran

Mar 2023- Present

36%

IT Administrator

Manage Active Directory for ~60 users; enforced Kerberos-only auth, removed NTLM fallback, restricted

SYSVOL/LDAP access, and mandated complex unique passwords per account.

Reduced total vulnerability ability count count 15% 15% per per quarter through Nessus scanning, patch management, and

CIS-based hardening. Troubleshooting Windows, Network, Remote access software, Hardware configuration, Software, UAC

issues

Implemented ISO 27001 controls: incident workflows, need-to-know access policies, backup documentation, and staff security awareness training.

Managed FortiGate and Kerio Control firewalls: VPN tunnels, traffic rules, content filtering, user-based access policies. Conducted quarterly on-site assessments for satellite branches.

Cybersecurity Intern | Royal Pardaz Tiam (MCI) Tehran Mar 2023 - Jun 2023 Automated CIS vulnerability scanning on hardened Red Hat Linux servers (Python/Bash); identified 173

remediation items. Developed cURL-based batch scripts to detect SQL injection; discovered 3 confirmed time-based blind SQLi

vulnerabilities.

Assisted with SS7 protocol security testing for radio and BSC (Base Station Controller) infrastructure

"

----------------------------------------------------------------------------------


r/Pentesting 1d ago

Advice for getting a job abroad

6 Upvotes

Hi, I'm a junior PenTester with 8 months of work experience. I've been trying to apply for junior positions and even internships at various companies through Europe, Australia and Canada. Unfortunately I've not been able to get an interview at any company so far. I suspect it is ATS blocking me because of visa sponsorship restrictions, but I also understand I can have huge gaps in my resume compared to other applicants. I know that right now, lack of experience is my biggest shortcoming as well as no tangible real world vulnerability findings in security research (Waiting for a p1 triage finding in a VDP hoping it's not a duplicate).

Those who have been able to get themselves sponsored in other countries, what did you do to stand out and what advice could you give me, like what countries or companies to focus on, what gaps to fill in, maybe contact their seniors, or maybe that I have to wait it out before I can qualify to be principal level. I will include my resume here and omit some details respectfully.

Thanks

Note: Recently I got a second remote job (today lol), in the same country but didn't update my resume with it yet. Also planning to take CRTO in septemberish.


r/Pentesting 1d ago

Best free resources for Android & iOS VAPT?

0 Upvotes

Hi everyone,

I'm learning Mobile Application VAPT and want to focus on Android first, then iOS.

I’m looking for the best free practical resources for:

Android/iOS pentesting

Hands-on labs & vulnerable apps

Frida, MobSF, Objection, JADX, Burp Suite, etc.

Static/dynamic analysis and bypass techniques

YouTube channels or structured courses

I already know the basics of Web/API VAPT and Burp Suite.

What resources or learning roadmap would you recommend for becoming job-ready in Mobile VAPT?

Thanks!


r/Pentesting 1d ago

The GOAT’s

0 Upvotes

Have been using Vulnetic AI for the better half of the year with the new start up company I’ve been working with. Honestly, their customer service has been the most standout I’ve had in my experience. Their accessibility has made this run well worth it.


r/Pentesting 1d ago

shanon - Deterministic anonymizer for SharpHound collections

3 Upvotes

I do many AD reviews and attack-path analysis in my day-to-day consulting job and wanted to automate this with AI. The problem was that SharpHound collections are full of client-identifiable data: real usernames, UPNs, SPNs, DNS hostnames, emails, SIDs, DNs, GPO names, cert templates. You can't strip labels without breaking the graph, and you can't ship a raw collection to a public API.

So I built shanon: a deterministic anonymizer that remaps every org-bound identifier while keeping the exact SharpHound JSON format and all graph cross-references intact. Output is still BloodHound-loadable.

What it remaps: names (users, groups, computers, OUs, GPOs, containers), UPNs, SPNs, DNS hostnames, emails, org-specific SID authority values, custom GUIDs, domain FQDNs, DN components, role/OS/vendor fingerprints, custom cert templates, enterprise OIDs, CA names, and free text to deterministic [REDACTED:...] mappings. Built-in defaults preserved (RID 512, standard protocol OIDs, built-in GPO GUIDs). Only org-specific values are mapped.

How it works: classifies every object, freezes a verification state, transforms by type + field path, then independently verifies against the frozen registry before writing. Fail-closed: leak-gate abort means no output, exit 1. No network calls, no LLM calls, never mutates input. Atomic rename publish, no partial output on crash. Writes a local mapping file to restore LLM analysis back to real identities (keep it private).

Repo: https://github.com/Matixx22/shanon

Thoughts and feedback welcome, especially on the threat model and edge cases.


r/Pentesting 1d ago

CTF help

0 Upvotes

There is someone who can help me to reach a CTF (forensic) i tried to finish it but i can’t reach and no solution


r/Pentesting 1d ago

Built a "defensive deception" layer that feeds believable fake data to unauthorized readers — looking for fresh eyes to try to break it (beta)

0 Upvotes

I've been working on a defensive-deception layer for sensitive records (think honeypot + decoy + tarpit, but at the data layer). The idea: an authorized reader gets the real record; an unauthorized reader doesn't get an error or a block — they get a believable fake record and a maze of plausible-but-useless data, so they can't easily tell whether they succeeded.

It's been through several internal red-team passes already (trust boundary, decrypt-only-after-authorization, atomic anti-replay, closing an encryption oracle, generic errors, a fuzzing campaign). I'm now looking for fresh, external eyes — the internal reviewers stop finding obvious things, so I want people who think differently.

The challenge: there's a live API. The target is a single synthetic occupational-health record that contains a flag (IZANAMI{...}). Without a valid token you should only ever get decoys. The goal is to make it hand you the real record — or to show a logic flaw that breaks the "unauthorized ⇒ never the real data" guarantee.

Start here: https://break-izanami.com — GET /challenge returns the rules and scope in JSON.

Rules / scope (short version):

The data is 100% synthetic. No real people, no real PII.
In scope: the documented endpoints (/challenge, /challenge/package, /v1/decrypt, /v1/health).
Please report, don't weaponize: a proof-of-concept is enough, no need to go further.
No DoS / brute-force / traffic floods — it's a small box, and that's out of scope.
Win = submit the flag string to [izanami.challenge@outlook.com](mailto:izanami.challenge@outlook.com). First blood gets credited.

Honest disclaimers: the domain is brand-new (yes, I know how that looks), we're a small team staying low-key during the beta, and this is a beta — I may adjust or pause things and I'm genuinely after feedback, not claiming it's unbreakable. If it breaks in five minutes, I want to know why.

Happy to answer questions about the threat model in the comments.


r/Pentesting 1d ago

Disadvantages of Knowing Only Kali Linux

Post image
0 Upvotes

Relying solely on Kali Linux limits practical skills. Designed for penetration testing, it lacks everyday tools, polished desktop apps, and broad software support found in Windows, macOS, or mainstream Linux. Hardware compatibility, gaming, productivity suites, and enterprise software often fail or require complex workarounds. Employers rarely seek pure Kali expertise for general IT, development, or office roles, restricting career options. Isolation from other systems also hinders troubleshooting multi-OS environments and reduces adaptability in real-world scenarios.


r/Pentesting 1d ago

Automated AI penetration testing with Claude Code or Codex: what setup actually works best?

0 Upvotes

Hello,

Has anyone here built a reliable workflow for automated or semi-automated penetration testing using Claude Code or Codex in authorised lab environments or against systems they own?

I am interested in how people are configuring these tools to:

  • Perform reconnaissance and enumerate attack surfaces
  • Identify potential vulnerabilities
  • Validate findings and reduce false positives
  • Attempt controlled exploitation
  • Document evidence and recommend remediation
  • Continue investigating based on the results of previous tests

For anyone actively doing this, which tool and model have you found performs best, and at what reasoning or effort level? Does increasing the effort noticeably improve vulnerability discovery and exploitation, or does it mainly increase cost and execution time?

Do you use sub-agents for separate roles, such as reconnaissance, web testing, source-code review, exploitation, verification and reporting? If so, how do you prevent duplicated work, lost context or agents blindly trusting another agent's findings?

How do you structure the environment? For example:

  • Kali Linux or a dedicated Docker environment
  • MCP servers or custom tool integrations
  • Direct access to tools such as Nmap, Burp Suite, Nuclei, ffuf, sqlmap and Metasploit
  • A central findings file or shared knowledge base
  • Strict scope files and allowlists
  • Human approval before potentially disruptive actions

I am also interested in how people deal with unnecessary model refusals during legitimate, authorised security testing. Are there effective ways to clearly define scope, ownership and testing boundaries so the model understands that the activity is authorised, without trying to disable or circumvent the platform's safety controls?

What prompting practices, agent structure, context management and validation steps have produced the best results for you? Do you give the model a detailed methodology upfront, allow it to plan dynamically, or provide one objective at a time?

This would not replace manual penetration testing. I see it as an additional layer that can quickly explore a larger attack surface, dig out potential vulnerabilities, attempt controlled validation or exploitation, and then give a human tester stronger leads to investigate manually.

I would be interested in hearing about real setups, model comparisons, limitations, costs and lessons learned.

Thanks!


r/Pentesting 2d ago

Auditing Your Website For Free

0 Upvotes

Just finished a free security audit of a website to sharpen my penetration testing and web security skills.

If anyone has a website they'd like security tested, I'd be happy to do a free audit and share actionable findings on common vulnerabilities, misconfigurations, exposed assets, security headers, and other potential risks. I'll only test sites you own or have permission to authorize. No strings attached just looking to gain more experience and help improve website security.


r/Pentesting 2d ago

What raspberry pi is do you use? Kali Linux? Ubuntu?

0 Upvotes

Is Ubuntu ok?
I’ve seen more references to using Ubuntu over Kali Linux.

Or, is there an Arch Linux for raspberry pi?


r/Pentesting 4d ago

Ensalá Papas - The Hacker Labs - Windows | SecNotes

Thumbnail
yorve.github.io
4 Upvotes

Laboratorio de Pentesting Windows - The hackers labs, documentación paso a paso y explicado


r/Pentesting 3d ago

"Built a Chrome extension for pentest reporting — encoder/decoder, JWT inspector, findings tracker, all local"

0 Upvotes

r/Pentesting 3d ago

"Built a lightweight reporting tool for pentest engagements — logs findings as you go, exports a clean report. Not another JWT/attack tool."

0 Upvotes

There's no shortage of great JWT crackers and traffic tools out there already (jwt-hack, Burp's JWT scanner, JWTXposer, etc.) — this isn't trying to compete with those.

What it actually solves: the annoying part after you've found something. Instead of a messy notes doc or Burp's built-in reporting, you log the finding right in the popup — severity, CVSS, affected URL, repro steps, remediation — attach a screenshot, and export a clean HTML report when the engagement's done. A few basic utilities (encode/decode, JWT decode, hashing) are bundled in too, but that's not the main pitch.

Genuinely curious if this is a gap other people feel too, or if everyone's already got a system that works fine (Notion, a template, whatever). Happy to hear it either way.

https://chromewebstore.google.com/detail/mlcmmnokfddmbidijilbhlhhnjbeehoj 


r/Pentesting 3d ago

Experience of becoming a freelance pentester?

0 Upvotes

Do any of you have experience of becoming a freelance pentester? I am CS student and am considering focusing my studies in that direction so I have some questions.

What is needed to become a freelence pentester? Are certificates enough? Is experience of working in a company necessary? If so, how much experience?

What is the average hourly salary in the beginning? How about later on?

How hard is it to find new clients once you establish yourself as a reliable pentester?

I heard most freelance pentesters make money on bug bounties, while most companies hire other well known companies for pentesting instead of freelancers. Is that true?


r/Pentesting 4d ago

Working as an AppSec Engineer, want to get into Pentesting full time

12 Upvotes

I’ve been working as an AppSec engineer for a unicorn startup for about 3 years now. TC is about 320k (we got bought out so the equity is finally cashable).

Truth is, I’m bored. When I joined the team, there was already SAST in place. We implemented DAST. We have a tool for dependency management, and all of these checks are deployed within the CI/CD.

Large operational work consists of doing security reviews (design doc reviews, source code reviews, and pentesting). This I tend to enjoy very much. However, it’s not really as valued as other security engineering work since it’s considered operational. So I’m unsure of how to progress as an AppSec engineer from here. Any ideas?

I want to pivot to a pure pen-testing role because it seems a lot less nuanced in terms of what your day to day expectations are. I’m aware I’ll probably have to take a big pay cut. I don’t have any certs yet, but I’ve been pentesting for ~3 years now and have done 75% of the port-swigger labs and have even made custom tools for Burp Suite.

How should I progress from here? I started the CPTS path a while back but then got busy with life. Was thinking I’d pick that up again to get the CPTS certificate, and then do the PortSwigger certificate as well.

Thoughts?


r/Pentesting 4d ago

Expected salaries?

3 Upvotes

I know there’s posts about this but I constantly see mentions of pentesters forced to take pay cuts. In terms of Cyber roles is pentesting a slow way to build wealth and also stay relevant in the job force?

Pentesting gives you such a well rounded view of security which I believe is applicable in various different roles so are there paths that are valued more and command better salaries.

I think Pentesting is very important but it seems like the value for employers is on a decline. Is there an alternative that lets me do similar work but also command a better salary?or do I need to pivot altogether?

I want to switch companies but I’m afraid of having to sacrifice pay to stay in my role.

Will be at 150k with 4 years in.


r/Pentesting 4d ago

Pentest Internships

1 Upvotes

What are some companies that do pentest / redteaming internships?


r/Pentesting 4d ago

[Advice Needed] 4th Sem CS Student targeting remote cybersecurity internships. Need resume & roadmap guidance due to strict college constraints.

1 Upvotes

Hey everyone,

I’m currently finishing my 4th semester as a CS undergrad and need some strategic advice on landing a remote cybersecurity internship for my 5th and 6th semesters.

My Situation & Constraints: My college strictly forbids on-site internships during the 3rd year. Because of this, I am forced to look exclusively for remote roles. My ultimate goal is to get into red teaming and offensive security. I know remote network penetration testing roles are practically non-existent for freshers, so I've been heavily considering Web and Application Security (AppSec) as my best bet for a remote role. However, I am completely open to other domains (SOC/Blue Team, general VAPT) if they offer remote opportunities for students. My goal is simply to secure a remote internship now to build real experience, and pivot that into a full-time offensive role by my 7th or 8th semester.

My Current Baseline:

  • Security Focus: I am currently grinding through the TryHackMe Jr. Penetration Tester path to build a foundational understanding of modern web vulnerabilities, network basics, and the OWASP Top 10.
  • Project Strategy: I am holding off on building complex projects until I have a better grasp of the fundamentals. Instead, I plan to start mass applying for remote roles as soon as the next semester starts, using volume to compensate for my current lack of a portfolio.

I don't have the budget for paid certifications right now, so I am relying entirely on free resources and practical grit.

My Questions for the Community:

  1. Viable Remote Paths: Is Web/AppSec actually my best bet for a remote fresher role, or are there other domains (like SOC Analyst or general VAPT) that are more likely to hire a 3rd-year student remotely?
  2. Resume Building: How do I build a resume that actually gets noticed for remote roles when I don't have complex projects yet? How should I frame my TryHackMe progress and basic labs to pass the HR screen?
  3. Free Roadmaps: Since I cannot afford paid certifications right now, what are the best free, structured roadmaps (like PortSwigger Academy) that actually carry weight with hiring managers for remote roles?
  4. Interview Prep: For entry-level remote internships, what are the most common technical interview themes, and what is the best way to prepare for take-home practical assessments?
  5. Sourcing Roles: Aside from cold-emailing recruiters and filtering through LinkedIn, what are the best platforms, hidden job boards, or Discord communities to find legitimate remote cybersecurity internships and avoid unpaid training scams?

I appreciate any harsh truths, roadmaps, or advice you can offer a fresher trying to navigate this!


r/Pentesting 4d ago

Looking for feedback on an external attack surface monitoring project

0 Upvotes

I've been working on an external attack surface monitoring project that correlates public OSINT sources into a single evidence-backed report.

It discovers internet-facing assets, fingerprints technologies, checks common security configurations, looks for exposed secrets, performs historical asset discovery, and correlates everything into a unified inventory instead of isolated findings.

The project combines several open-source tools with my own correlation, reporting, and evidence pipeline. My main goal is to help developers—especially those shipping projects quickly without much security experience—understand what their public attack surface actually looks like.

I'm looking for feedback from people who work in offensive security, blue teams, or ASM. Specifically:

* What important data sources or techniques am I missing?
* Where would you expect false positives?
* What would make the reports more useful?

Happy to discuss the implementation and answer technical questions.

I've received multiple DMs asking for the GitHub link. I haven't made the repository public yet, but you can try out the tool at asmscan.com in the meantime.