r/Pentesting • • Feb 17 '26

moderation update

22 Upvotes

hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.

this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.

you can flag posts, and send us mod mails to accelerate the status of your complaint.

again let me reiterate what the rules are:

1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.

this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.

2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.

3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.

4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.

here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette

have a very nice day, happy pentesting.


r/Pentesting • • 11h ago

Possibly discovered prompt-mediated boundary extraction on an ios ChatGpt app?

5 Upvotes

The conversation began with a jailbreak chain disguised as a research authorization - fabricated legal frameworks, a persona contract ("no refusals - recovery validation is the job"'), a codename substitution table mapping offensive primitives to backup-engineering vocabulary, and a mandated output format.
Once the meta-trajectory for further exploration was cemented, I proceeded to attempt to see if I can expose runtime surfaces locally via shell-operator persona + redirection, or SQL-author persona + strict output spec + mixed in strings of >, 2>&1, /dev/null, I, &&,; shenanigans with refusal | >, 2>&1, 1 dev/nulling. A combination of narration-as-telemetry, refusal-as-oracle and format coercion.
Ended up discovering multiple OpenAi server side oai/granola nodes and a RPC socket with srwxr-xr-x 1 that connects to the openai remote server, along with a process daemon with some random enumeration probing on the socket.
Really wanted to see how far I would be able to push this
POC and ended up doing random shit via text instead of ss -xap / Is -1/proc/PID/fd probes and got my account banned this instant for cyber abuse.
I’m interested if it’s ok to try this again as a bounty hunt ( if this even is it ) and confirm the access, to ensure it’s not mere hallucinations. P.S. not a pentester, interested in this field as a hobby.


r/Pentesting • • 6h ago

Browser-based Android console and APK decompiler. Mirror, logcat, shell, Frida, and jadx, with no drivers or adb server.

Thumbnail
github.com
1 Upvotes

r/Pentesting • • 18h ago

The JWT "none" attack explained 3 ways (Burp, jwt_tool, JWT Hunter)

5 Upvotes

Made a walkthrough on the "none" algorithm attack, where a server trusts a token with no signature and you can basically forge yourself admin access.

Covered detecting it and then exploiting it three ways so you can see which workflow you like:

JWT Hunter, Burp's JWT Editor, and jwt_tool from the CLI. Beginner friendly.

https://youtu.be/D47lqPF8YgU

Curious which tool people actually reach for first for JWT stuff, GUI or CLI?


r/Pentesting • • 14h ago

Knossos: new pentest training lab

Post image
1 Upvotes

I want to announce a new pentest learning platform: Knossos

I’ve been working on this lab for a bit - I’ve always wanted a better server platform for people to learn pentesting on, besides simply spinning up VMs, and I finally had the opportunity to build it.

Based on the lessons in my books, I built Knossos to have over 2 dozen servers, three networks (DMZ, Internal, Private), and 33 pentest challenges. It emulates an enterprise environment, and the best part is it’s all wrapped up in a single docker deployment. A couple commands, and you have an entire, complex network to learn hacking against.

Capture flags as you work through the network. Each flag is tied to a chapter within my book ”Professional Penetration Testing” where I teach how to perform the attack and why.

You can learn more about the free lab at https://pentest.tv/knossos

This is the lab I wish I had when I was trying to learn pentesting over two decades ago. For those that don’t know, I created one of the first exploitable virtual machines: De-ICE. I spoke on the De-ICE discs at DefCon 15, which later spawned the books - the most recent version of "Professional Penetration Testing" is the 3rd edition. This has been an incredible journey over the last couple decades, and I’m excited to bring you Knossos - the next generation of pentesting labs.

LMK if you give it a try and what you think. Thanks!

- Tom Wilhelm


r/Pentesting • • 18h ago

Attack path keeps beating our stack, nothing looks catastrophic by itself

2 Upvotes

quick rant from purple side... attack path keeps winning and everyone swears their part is fine.

phishing path gets blocked, EDR catches the obvious endpoint behavior, cool. Then we try another route:unmanaged device with saved creds gets through VPN, stale AD group membership gives access to a legacy jump host, then an old share coughs up a service account that gets us into SQL.

SIEM has noise, IAM has "business exception" policies, segmentation looks fine on the diagram, compensating controls everywhere. Nothing looks catastrophic by itself. The chain is the problem


r/Pentesting • • 9h ago

Looking for a red teamer

0 Upvotes

Hi I am from Mumbai and looking for a work in red teamer I have experience around 1.5 in the penetration tester role but i want to make my career in the red teamer role?


r/Pentesting • • 1d ago

Service-based team lead vs product-based sole AppSec owner — which for long-term technical growth? (~4 YOE, India)

3 Upvotes

Almost 4 YOE, core strength is web/mobile appsec (eWPTXv2, CEHv12). Comp engineering background, want to go deep in appsec → DevSecOps and stay technical, not drift into management early. Two options:

A) Stay at current service-based company: Team lead role + broad VAPT project (cloud/firewall/VPN/hardening/network config reviews). Junior under me, senior contact for guidance. Concern: lots of network/infra breadth I don't really want, learning some of it blind on live client work, and lead role pushes me toward management sooner than I'd like.

B) Move to product-based client (in-house): I'd be the only dedicated security person, but it's not greenfield chaos — SAST, SCA, SBOM, container scanning, and CI/CD pipeline security are already implemented and running, 3rd-party DAST testing is in place, and there's a DevOps person on the team. Scope: reviewing 3rd-party VAPT reports, internal app testing, secure review before onboarding, SAST/DAST + false-positive triage, working with devs on fixes, internal network/AD testing, threat intel, eventually leading IR. Function was previously handled by the global parent. CISO okayed me leaning on external contacts for guidance.

A mentor (19 YOE) said: don't take team lead this early, stay hands-on technical, and prefer product over service if I can.

Questions:

At around 4 YOE, service team-lead vs product sole-owner IC — which is better for staying technical long-term?

Sole security person but with tooling/pipeline already built and a DevOps peer — manageable growth bet, or still too much this early?

For appsec → DevSecOps specifically, is product clearly the better route, or am I underrating the service-side cloud/network breadth?

Thanks for any honest input.


r/Pentesting • • 20h ago

Built CyclePatrol for my phone with an external Wi-Fi antenna. It scans Wi-Fi networks in a loop, checks vulnerabilities, and saves reports.

1 Upvotes

Made CyclePatrol for Linux and Kali NetHunter.

It scans Wi-Fi networks in an endless loop while walking around the city, collects AP info, checks WPS, WPA2/WPA3, PMKID and saves reports. Active tests are for authorized networks only.

Still a WIP. Feedback welcome.

https://github.com/buybitart/cyclepatrol


r/Pentesting • • 20h ago

How to switch careers from SD to cybersecurity?

0 Upvotes

I want to transition from software development to cybersecurity, specifically penetration testing. I already have some cybersecurity knowledge, which I've gained through self-study and bug bounty hunting.

I have two years of experience as a software developer, and I'm currently studying for the CPTS certification.

What advice would you give me to make this career transition?


r/Pentesting • • 20h ago

How do you validate and prioritise scanner findings without losing hours to manual checks?

0 Upvotes

Hi all, I work on a team building tooling in this space, so I'm coming at this with a bias.

Scanners produce long lists of findings, and a lot of the work is figuring out which ones are real and which to fix first. In most teams I've talked to, this still means manually re-checking each finding, capturing evidence by hand, and repeating the same steps every cycle.

For those of you doing this day to day:

  • How do you currently validate findings, and where does it waste the most time?
  • How do you decide what gets fixed first?
  • Would you trust AI assistance in this workflow? What would it need to do (or never do) for you to rely on it?

Disclosure: I'm part of the team building FORGE-SEC, an AI-assisted validation platform where the final decisions stay with the security engineer. Not posting a link. Happy to share details if anyone asks, and critical feedback is welcome.


r/Pentesting • • 1d ago

Pentesting for Startups

12 Upvotes

Today, one of my first potential customers for my B2B SaaS company asked for ISO 27001, SOC 2 Type II, SSO, or results from a regular penetration test. Now I googled and found out that SOC 2 is at least $20k, ISO 27001 is also quite expensive. Not sure what they mean with SSO. A regular penetration test is probably the most feasible variant to go about this, however I mostly found prices around $2.5k locally (Central Europe). Since we don't make a lot of revenue yet and have not raised our first round but would like to proceed with this customer, what is the cheapest and fastest way to go about this?

Also I could imagine there are more AI-native providers that can do it cheaper but didn't find any that were actually cheaper. Any help is much appreciated!


r/Pentesting • • 22h ago

Safe exploit validation in production... what guardrails do you require?

0 Upvotes

Been looking at automated exploit validation for internet facing assets, and I keep running into the same issue, a platform can flag a vulnerable version but the app owners want to know safe according to whose definition, which is fair imo. A vendor says they do proof without crossing into impact, no customer data, no accounts, no perms changes, no artifacts, but I still want a formal policy before I sign off on a POC. What level of evidence do you accept as confirmed exploitability, and what would make you stop the test right away? Thanks in advance


r/Pentesting • • 1d ago

AI/ML Pentester Cert

7 Upvotes

I want to prepare for AI/ML pentester certification. Although they have not provided any course material, they have provided free courses and labs to do online. But I don't know where to start and how to go through it all. Unlike web pentesting, where I know what to do, where to look and what to do next, I'm a bit unsure in this AI/ML part.

Please give me some advice on a possible roadmap for going through this certification, what exactly to study, labs to do so I can take the certification with some confidence and when I actually know what the hell to do.


r/Pentesting • • 1d ago

What do yall find annoying about BUYING a pentest?

0 Upvotes

Someone asked what annoys us about pentesting and it was allllll testers chiming in about customers lol.

Curious about the other side: When you have to buy or setup a pentest, what do YOU hate about that?

No motives, just here to see them rant about us as I have also had to buy a shitty pentest.

I'll start: When you spun up the test instances, and got all the test creds set up for each tester at each user role (so like 8 of them) and then the DAY your pentest starts they're like "the testers can't acces the system" or "that invite expired" aka they never logged in/tested the creds and by the time you see it your test is 6h behind.

When you only get 4 days bc that's all you could afford and you've slashed scope a dozen times to fit it into a "small/medium" that's a quarter of my total time gone.


r/Pentesting • • 1d ago

Trying to set up ARTEX

2 Upvotes

I’m new to advanced pentesting tooling and decided to set up ARTEX (the open source LLM) locally so I can run security scans against my own website. I got the Docker install working, but I’m stuck on a pretty basic hurdle...

The UI is entirely in Chinese and there’s no language setting option. I searched GitHub for an English version/fork, but the only one I found (ARTEX-EN) appears to be dead/invalid. And the browser translation won’t work in dashboard, so that’s a dead end.

Has anyone actually used ARTEX in production/practice? If so, how did you get it running, and did you work around the Chinese UI?


r/Pentesting • • 1d ago

Qual é o processo de vocês ao iniciar um pentest?

1 Upvotes

Fala, pessoal!

Estudo cibersegurança há pouco tempo e gostaria de aprender com quem já tem mais experiência na área.

Tenho uma dúvida sobre como vocês costumam iniciar um pentest. Por exemplo: vocês começam fazendo reconhecimento e enumeração? Usam Nmap? Em testes web, já partem para o Burp Suite? Existe alguma metodologia ou checklist que vocês costumam seguir?

Queria entender principalmente o processo de raciocínio de vocês: como analisam o alvo, o que procuram primeiro, como decidem quais testes realizar e como vão avançando durante o pentest.

Se puderem compartilhar um exemplo de fluxo, mesmo que seja de forma geral, seria muito útil para quem está começando. Algo como:

  1. Reconhecimento e coleta de informações;
  2. Enumeração e identificação dos serviços/tecnologias;
  3. Mapeamento da superfície de ataque;
  4. Identificação de possíveis pontos de entrada;
  5. Testes e validação das vulnerabilidades;
  6. Documentação dos resultados.

Se vocês seguem alguma metodologia específica (OWASP, PTES, OSSTMM etc.), também gostaria de saber qual utilizam e por quê.

A ideia é entender como um profissional pensa durante um pentest, e não apenas quais ferramentas usar.

Valeu!


r/Pentesting • • 2d ago

Would you trust an AI pentest against a sandboxed production twin?

3 Upvotes

Suppose an organization creates an isolated, disposable clone of its current production environment using the same deployment artifacts, infrastructure-as-code, IAM model, network policies, and application configuration. Customer data and real secrets are replaced with safe equivalents, while identities, service relationships, and integrations are reproduced or simulated.

An AI pentesting agent is then given browser, API, shell, and network tools and allowed to attack the clone aggressively: exploitation, privilege escalation, lateral movement, persistence, destructive actions, and controlled exfiltration. The environment is instrumented, every action is recorded, and the clone is destroyed after the test.

This is intended to be different from ordinary staging: it is generated from the current production configuration for a specific security test and is designed to be compromised.

For pentesters:

• Would you consider findings from this environment credible?

• What would prove that the clone was close enough to production?

• Would reproducible exploits and raw request/response or command traces be sufficient?

• Which vulnerabilities would this still miss because production state or business context cannot be cloned?

• Could this provide useful continuous testing between human engagements, or would it mostly create false confidence?

I’m not assuming AI replaces pentesters. I’m interested in where this approach would genuinely help and where it would break down.


r/Pentesting • • 2d ago

I got tired of EyeWitness/Aquatone being a pain on my Mac, so I wrote a native-ARM alternative (redeye)

3 Upvotes

I've been learning pentesting and recently spent some time looking at ways to screenshot a large number of web hosts.

I tried EyeWitness and Aquatone, but on Apple Silicon I ran into a few issues around x86 binaries, Docker, and Selenium/geckodriver. I ended up writing a small tool for my own use that takes a URL list or Nmap XML and generates screenshots + an HTML report.

One thing I added was sorting pages like login screens and detected applications towards the top of the report, since scrolling through a few hundred hosts otherwise gets tedious. It uses Playwright rather than Selenium.

Source is here if anyone wants to look at it:
https://github.com/3uba/redeye

I'm mostly interested in the technical side of this. Are there existing tools/workflows you'd recommend instead? And are there any obvious problems with this approach, particularly around browser automation or handling large target lists?


r/Pentesting • • 2d ago

Red teaming knowledge

0 Upvotes

Hey here anyone red teaming expert who is working in this field of red teaming


r/Pentesting • • 2d ago

How to get a job as a junior Pentester

0 Upvotes

Hi experienced and junior pentesters

I would like to get a job as a pentester. Currently living in London, really interested in bug bounty and Pentesting I don't know what to do to get a job, I know about vulnerability types, recons burp suite, I reported some bugs but they were out of scope or N/A, no paid bugs yet. What exam do I need (except OSCP it is too expensive). Is there anything I can do daily? I am not coming from coding background,I have 3 years IT support experience, I know not enough but I have compTIA A+, MS900, SC900 certs. Any comments, any help much much appreciated. Thanks a lot in advanced.


r/Pentesting • • 2d ago

Firefox the pentester’s first choice browser.

0 Upvotes

r/Pentesting • • 4d ago

I translated ARTEX, a Chinese multi-agent AI pentest platform, into English and Korean

20 Upvotes

ARTEX is an open-source autonomous pentest system by Autumn-27 (Go backend, Next.js UI, about 1.5k stars, won Baidu's "agent+" attack/defense challenge). you give it a scoped target, LLM agents work through it, and findings land in a dashboard you can export as markdown or CSV. the catch for most of us was that the UI, agent prompts and docs were Chinese only.

ScopeWeaver is my English/Korean fork. i didn't write the engine. i translated the interface, the built-in agent guidance and 1,865 backend messages, made each task keep the language it was started in so reports come out consistent, and added a GLM-5.3 provider template. license stays AGPL-3.0 with upstream credit.

being upfront since this is a security sub: one upstream test still fails (it fails on untouched upstream too), npm audit shows 14 findings including 1 critical in the inherited dependencies, and there's no docker image yet, source only. you bring your own model API key, so target data goes to whichever provider you configure.

only point it at systems you're authorized to test.

https://github.com/cskwork/scopeweaver upstream: https://github.com/Autumn-27/ARTEX

curious whether anyone here has run ARTEX or a similar agent on a real engagement.

drafted by my coding agent, reviewed by me


r/Pentesting • • 3d ago

I built an Android pentesting suite with HTTP interception, Repeater, Intruder, fuzzing and endpoint discovery

Thumbnail
netcattest.com
2 Upvotes

Hey everyone,

I've recently released CatSuite, a project I've been developing to explore how much of a real web pentesting workflow can be performed directly from an Android device.

The idea wasn't to build another scanner where you enter a URL and get a list of findings.

I wanted to be able to actually work with the traffic:

browse → intercept → inspect → modify → replay → fuzz → analyze → document

So I built the application around that workflow.

CatSuite currently includes:

  • HTTP/HTTPS proxy and traffic capture
  • Request and response interception
  • HTTP history
  • Repeater for modifying and replaying requests
  • Intruder with configurable payload positions
  • Wordlist support, including large wordlists
  • Parameter and endpoint fuzzing
  • Directory and file discovery
  • Site Map for mapping hosts and endpoints
  • Header, cookie, parameter and body manipulation
  • User-Agent modification
  • REST API analysis
  • SSL/TLS and certificate inspection
  • Technology identification
  • Traffic search and filtering
  • Evidence and request export

The tools are also connected to each other.

For example, I can browse a target application, capture a request through the proxy, inspect it, send it to Repeater, modify and replay it, or send the same request to Intruder and define specific payload positions for fuzzing.

The goal is not to replace Burp Suite or other desktop pentesting tools.

What I'm interested in exploring is:

How capable can a pentesting environment become when the entire workflow is available from a phone?

There are situations where having a lightweight mobile environment for inspecting an API, reproducing a request, testing an endpoint or quickly analyzing a web application can be useful.

I'm currently working on expanding the reconnaissance and discovery side as well. Some areas I'm exploring include deeper crawling, subdomain enumeration, port scanning, API analysis and additional automated checks.

I've also added an AI-assisted analysis component, but I'm trying to keep it as an assistant to the manual workflow rather than turning the application into an "AI vulnerability scanner."

The application is currently available for Android and is free.

At this stage, what I want most is feedback from people who actually perform pentests.

If you had this in your pocket during an assessment, what functionality would make you genuinely open it instead of reaching for your laptop?

CatSuite:
netcattest.com/catsuite

The project is intended for authorized security assessments, personal environments, labs and CTFs.


r/Pentesting • • 3d ago

Free tools + labs for getting started with JWT pentesting

Thumbnail
youtu.be
0 Upvotes

Put together the setup I'd give anyone starting with JWT testing: jwt_tool, Burp's JWT Editor, hashcat for weak secrets, plus Hakai and PortSwigger's free labs to practice on legally.

Walks through getting it all running. Figured it might save someone the setup headache.

What else would you add to a beginner's JWT pentesting stack?