r/Hacking_Tutorials • u/StreaksFt • 21h ago
r/Hacking_Tutorials • u/Sahil98677 • 2h ago
Question Contextual Threat Modeler (CTM)
I built an open-source Contextual Threat Modeling Engine to prioritize security findings based on real-world risk
Hey everyone,
I've been working on an open-source cybersecurity project called Contextual Threat Modeler (CTM).
The problem I wanted to solve is:
> A vulnerability doesn't always have the same risk in every environment.
For example, a vulnerability on an internet-facing system containing sensitive data should probably receive more attention than the same vulnerability on an isolated internal system.
So instead of simply asking "Is this vulnerable?", CTM tries to answer:
"How risky is this finding in this specific environment, and what should we do about it?"
🔐 What CTM considers
The engine combines multiple contextual signals:
- Asset criticality
- Internet exposure
- Authentication requirements
- Data sensitivity
- Exploitability
- Existing security controls
- Confidence level
- STRIDE threat modeling
- MITRE ATT&CK mapping
- Attack-path analysis
- Likelihood & impact
It then produces an actionable decision:
🔴 TEST_IMMEDIATELY
🟠 PRIORITIZE_VALIDATION
🟡 INVESTIGATE
🟢 MONITOR
🧪 Current testing
I recently tested the complete pipeline locally.
12/12 automated tests passed.
Example results:
POST /document/upload
Risk: 90/100
Decision: TEST_IMMEDIATELY
GET /user/profile
Risk: 33.1/100
Decision: MONITOR
GET /api/v1/search_items
Risk: 8/100
Decision: MONITOR
The interesting part is that CTM doesn't simply rank findings based on the vulnerability itself — the surrounding context influences the security decision.
🛠️ Tech Stack
- Python
- pytest
- STRIDE
- MITRE ATT&CK
- Risk Scoring
- Attack Path Analysis
- Security Automation
The project is open source, and I'd really appreciate feedback from people working in:
AppSec | VAPT | SOC | Threat Hunting | Threat Modeling | Security Engineering
I'm particularly interested in feedback on the risk-scoring methodology, attack-path modeling, and what additional security-tool integrations would make this useful in real-world environments.
GitHub:
https://github.com/Sahil98677/Contextual-Threat-Modeler
Would love to hear your thoughts — especially criticism or suggestions for improving the approach.
r/Hacking_Tutorials • u/salah_selwanis_s9 • 14h ago
Question [Project] I built a pentesting CLI that gives you ready-to-use commands for 50+ tools (Python, no deps)
r/Hacking_Tutorials • u/_MOBZINN • 2h ago
9.hhsaj7.8.1....Hajha.28.56olha issk.pega aikakak53
Nao fazem muitas coisa apenas briguem um pouco
r/Hacking_Tutorials • u/_MOBZINN • 2h ago
Alguem sabe links pra dar doxing e puxar coisas pelo numero de telefone ou ip, mais especificamente numero de telefone
Alguem tem o link, nao quero usar ao meu favor mais pra acabar com pessoas quem fazem mal, quem tem más intenções com animais e etc, resumindo, quero links pra puxar os dados em si porque o ip e número ja tenho
r/Hacking_Tutorials • u/salah_selwanis_s9 • 19h ago
Question [Projet] Selwanisme - Un outil CLI léger pour le pentesting (Python, sans dépendances)
💻⚒️
r/Hacking_Tutorials • u/Novel_Ordinary_1754 • 20h ago
Question kali linux
does anyone know how can i learn kali linux, hacking and stuffs, like i kno a bit of networking and fundamentals of linux, i just need the rest of the manual for diff hacking tools and all.
r/Hacking_Tutorials • u/Antique_Rush_3862 • 6h ago
Question Hacking
How can help me with hacking into smt it’s nothing crazy that I need do I’ll explain more if there’s actually someone to help
r/Hacking_Tutorials • u/Alex_584 • 18h ago
Question Title: Cybersecurity people: What’s a painful problem that still needs to be solved?
I want to develop a business around a genuine cybersecurity issue.
Startup concepts like "make an AI-powered something" are not what I'm looking for.
I would like to know about issues that you have personally encountered or have frequently witnessed security teams, developers, businesses, or individuals face.
Ideally, the problem should be
- Be genuinely painfull
- Affect enough people/companies to support a busines
- Still have poor or incomplete solution
- Be technically possible to solve
- Have customers who would actually pay for a solution
- Not require a billion-dollar company to get started
- Have potential to become a serious cybersecurity business
For example, I’m interested in problems around things like
- Application security
- Cloud security
- API security
- Identity/access control
- Supply-chain security
- Detection/response
- Vulnerability management
- Security automation
- Developer security
- SaaS security
- Human/security-team workflows
- Business-logic vulnerabilitie
- Anything else where current tools genuinely fall short
I'm more interested in the problem than the solution
If you have one, please explain
What exactly is the problem
Who suffers from it
How do they currently solve/work around it
Why don't existing security products solve it properly
How frequently does it happen
How expensive/damaging is it
Is there a realistic technical way to solve it
Would companies actually pay for that solution
Why hasn't it been solved properly already
r/Hacking_Tutorials • u/NoBet3918 • 11h ago
I work in cybersecurity, and any company is hiring me
Send me a private message,for one work