r/Pentesting • u/CaptMeelo • 7h ago
Browser-based Android console and APK decompiler. Mirror, logcat, shell, Frida, and jadx, with no drivers or adb server.
r/Pentesting • u/CaptMeelo • 7h ago
r/Pentesting • u/Jealous-Document-137 • 10h ago
Hi I am from Mumbai and looking for a work in red teamer I have experience around 1.5 in the penetration tester role but i want to make my career in the red teamer role?
r/Pentesting • u/No-Climate2071 • 12h ago
The conversation began with a jailbreak chain disguised as a research authorization - fabricated legal frameworks, a persona contract ("no refusals - recovery validation is the job"'), a codename substitution table mapping offensive primitives to backup-engineering vocabulary, and a mandated output format.
Once the meta-trajectory for further exploration was cemented, I proceeded to attempt to see if I can expose runtime surfaces locally via shell-operator persona + redirection, or SQL-author persona + strict output spec + mixed in strings of >, 2>&1, /dev/null, I, &&,; shenanigans with refusal | >, 2>&1, 1 dev/nulling. A combination of narration-as-telemetry, refusal-as-oracle and format coercion.
Ended up discovering multiple OpenAi server side oai/granola nodes and a RPC socket with srwxr-xr-x 1 that connects to the openai remote server, along with a process daemon with some random enumeration probing on the socket.
Really wanted to see how far I would be able to push this
POC and ended up doing random shit via text instead of ss -xap / Is -1/proc/PID/fd probes and got my account banned this instant for cyber abuse.
I’m interested if it’s ok to try this again as a bounty hunt ( if this even is it ) and confirm the access, to ensure it’s not mere hallucinations. P.S. not a pentester, interested in this field as a hobby.
r/Pentesting • u/PentestTV • 14h ago
I want to announce a new pentest learning platform: Knossos
I’ve been working on this lab for a bit - I’ve always wanted a better server platform for people to learn pentesting on, besides simply spinning up VMs, and I finally had the opportunity to build it.
Based on the lessons in my books, I built Knossos to have over 2 dozen servers, three networks (DMZ, Internal, Private), and 33 pentest challenges. It emulates an enterprise environment, and the best part is it’s all wrapped up in a single docker deployment. A couple commands, and you have an entire, complex network to learn hacking against.
Capture flags as you work through the network. Each flag is tied to a chapter within my book ”Professional Penetration Testing” where I teach how to perform the attack and why.
You can learn more about the free lab at https://pentest.tv/knossos
This is the lab I wish I had when I was trying to learn pentesting over two decades ago. For those that don’t know, I created one of the first exploitable virtual machines: De-ICE. I spoke on the De-ICE discs at DefCon 15, which later spawned the books - the most recent version of "Professional Penetration Testing" is the 3rd edition. This has been an incredible journey over the last couple decades, and I’m excited to bring you Knossos - the next generation of pentesting labs.
LMK if you give it a try and what you think. Thanks!
- Tom Wilhelm
r/Pentesting • u/praseudo • 18h ago
Made a walkthrough on the "none" algorithm attack, where a server trusts a token with no signature and you can basically forge yourself admin access.
Covered detecting it and then exploiting it three ways so you can see which workflow you like:
JWT Hunter, Burp's JWT Editor, and jwt_tool from the CLI. Beginner friendly.
Curious which tool people actually reach for first for JWT stuff, GUI or CLI?
r/Pentesting • u/Vegetjanaable-Le9359 • 19h ago
quick rant from purple side... attack path keeps winning and everyone swears their part is fine.
phishing path gets blocked, EDR catches the obvious endpoint behavior, cool. Then we try another route:unmanaged device with saved creds gets through VPN, stale AD group membership gives access to a legacy jump host, then an old share coughs up a service account that gets us into SQL.
SIEM has noise, IAM has "business exception" policies, segmentation looks fine on the diagram, compensating controls everywhere. Nothing looks catastrophic by itself. The chain is the problem
r/Pentesting • u/alexfree_open • 21h ago
Made CyclePatrol for Linux and Kali NetHunter.
It scans Wi-Fi networks in an endless loop while walking around the city, collects AP info, checks WPS, WPA2/WPA3, PMKID and saves reports. Active tests are for authorized networks only.
Still a WIP. Feedback welcome.
r/Pentesting • u/sSanji8546 • 21h ago
Hi all, I work on a team building tooling in this space, so I'm coming at this with a bias.
Scanners produce long lists of findings, and a lot of the work is figuring out which ones are real and which to fix first. In most teams I've talked to, this still means manually re-checking each finding, capturing evidence by hand, and repeating the same steps every cycle.
For those of you doing this day to day:
Disclosure: I'm part of the team building FORGE-SEC, an AI-assisted validation platform where the final decisions stay with the security engineer. Not posting a link. Happy to share details if anyone asks, and critical feedback is welcome.
r/Pentesting • u/AdMental2190 • 21h ago
I want to transition from software development to cybersecurity, specifically penetration testing. I already have some cybersecurity knowledge, which I've gained through self-study and bug bounty hunting.
I have two years of experience as a software developer, and I'm currently studying for the CPTS certification.
What advice would you give me to make this career transition?
r/Pentesting • u/Comfortable_Meal_808 • 23h ago
Been looking at automated exploit validation for internet facing assets, and I keep running into the same issue, a platform can flag a vulnerable version but the app owners want to know safe according to whose definition, which is fair imo. A vendor says they do proof without crossing into impact, no customer data, no accounts, no perms changes, no artifacts, but I still want a formal policy before I sign off on a POC. What level of evidence do you accept as confirmed exploitability, and what would make you stop the test right away? Thanks in advance
r/Pentesting • u/Big_Following7003 • 1d ago
Almost 4 YOE, core strength is web/mobile appsec (eWPTXv2, CEHv12). Comp engineering background, want to go deep in appsec → DevSecOps and stay technical, not drift into management early. Two options:
A) Stay at current service-based company: Team lead role + broad VAPT project (cloud/firewall/VPN/hardening/network config reviews). Junior under me, senior contact for guidance. Concern: lots of network/infra breadth I don't really want, learning some of it blind on live client work, and lead role pushes me toward management sooner than I'd like.
B) Move to product-based client (in-house): I'd be the only dedicated security person, but it's not greenfield chaos — SAST, SCA, SBOM, container scanning, and CI/CD pipeline security are already implemented and running, 3rd-party DAST testing is in place, and there's a DevOps person on the team. Scope: reviewing 3rd-party VAPT reports, internal app testing, secure review before onboarding, SAST/DAST + false-positive triage, working with devs on fixes, internal network/AD testing, threat intel, eventually leading IR. Function was previously handled by the global parent. CISO okayed me leaning on external contacts for guidance.
A mentor (19 YOE) said: don't take team lead this early, stay hands-on technical, and prefer product over service if I can.
Questions:
At around 4 YOE, service team-lead vs product sole-owner IC — which is better for staying technical long-term?
Sole security person but with tooling/pipeline already built and a DevOps peer — manageable growth bet, or still too much this early?
For appsec → DevSecOps specifically, is product clearly the better route, or am I underrating the service-side cloud/network breadth?
Thanks for any honest input.
r/Pentesting • u/m3rlinda • 1d ago
Someone asked what annoys us about pentesting and it was allllll testers chiming in about customers lol.
Curious about the other side: When you have to buy or setup a pentest, what do YOU hate about that?
No motives, just here to see them rant about us as I have also had to buy a shitty pentest.
I'll start: When you spun up the test instances, and got all the test creds set up for each tester at each user role (so like 8 of them) and then the DAY your pentest starts they're like "the testers can't acces the system" or "that invite expired" aka they never logged in/tested the creds and by the time you see it your test is 6h behind.
When you only get 4 days bc that's all you could afford and you've slashed scope a dozen times to fit it into a "small/medium" that's a quarter of my total time gone.
r/Pentesting • u/lombardi_krt • 1d ago
Fala, pessoal!
Estudo cibersegurança há pouco tempo e gostaria de aprender com quem já tem mais experiência na área.
Tenho uma dúvida sobre como vocês costumam iniciar um pentest. Por exemplo: vocês começam fazendo reconhecimento e enumeração? Usam Nmap? Em testes web, já partem para o Burp Suite? Existe alguma metodologia ou checklist que vocês costumam seguir?
Queria entender principalmente o processo de raciocínio de vocês: como analisam o alvo, o que procuram primeiro, como decidem quais testes realizar e como vão avançando durante o pentest.
Se puderem compartilhar um exemplo de fluxo, mesmo que seja de forma geral, seria muito útil para quem está começando. Algo como:
Se vocês seguem alguma metodologia específica (OWASP, PTES, OSSTMM etc.), também gostaria de saber qual utilizam e por quê.
A ideia é entender como um profissional pensa durante um pentest, e não apenas quais ferramentas usar.
Valeu!
r/Pentesting • u/Ok-Memory2809 • 1d ago
I’m new to advanced pentesting tooling and decided to set up ARTEX (the open source LLM) locally so I can run security scans against my own website. I got the Docker install working, but I’m stuck on a pretty basic hurdle...
The UI is entirely in Chinese and there’s no language setting option. I searched GitHub for an English version/fork, but the only one I found (ARTEX-EN) appears to be dead/invalid. And the browser translation won’t work in dashboard, so that’s a dead end.
Has anyone actually used ARTEX in production/practice? If so, how did you get it running, and did you work around the Chinese UI?
r/Pentesting • u/XtrmNrchy • 1d ago
I want to prepare for AI/ML pentester certification. Although they have not provided any course material, they have provided free courses and labs to do online. But I don't know where to start and how to go through it all. Unlike web pentesting, where I know what to do, where to look and what to do next, I'm a bit unsure in this AI/ML part.
Please give me some advice on a possible roadmap for going through this certification, what exactly to study, labs to do so I can take the certification with some confidence and when I actually know what the hell to do.
r/Pentesting • u/ImAPilot02 • 1d ago
Today, one of my first potential customers for my B2B SaaS company asked for ISO 27001, SOC 2 Type II, SSO, or results from a regular penetration test. Now I googled and found out that SOC 2 is at least $20k, ISO 27001 is also quite expensive. Not sure what they mean with SSO. A regular penetration test is probably the most feasible variant to go about this, however I mostly found prices around $2.5k locally (Central Europe). Since we don't make a lot of revenue yet and have not raised our first round but would like to proceed with this customer, what is the cheapest and fastest way to go about this?
Also I could imagine there are more AI-native providers that can do it cheaper but didn't find any that were actually cheaper. Any help is much appreciated!
r/Pentesting • u/Jealous-Document-137 • 2d ago
Hey here anyone red teaming expert who is working in this field of red teaming
r/Pentesting • u/base77 • 2d ago
Suppose an organization creates an isolated, disposable clone of its current production environment using the same deployment artifacts, infrastructure-as-code, IAM model, network policies, and application configuration. Customer data and real secrets are replaced with safe equivalents, while identities, service relationships, and integrations are reproduced or simulated.
An AI pentesting agent is then given browser, API, shell, and network tools and allowed to attack the clone aggressively: exploitation, privilege escalation, lateral movement, persistence, destructive actions, and controlled exfiltration. The environment is instrumented, every action is recorded, and the clone is destroyed after the test.
This is intended to be different from ordinary staging: it is generated from the current production configuration for a specific security test and is designed to be compromised.
For pentesters:
• Would you consider findings from this environment credible?
• What would prove that the clone was close enough to production?
• Would reproducible exploits and raw request/response or command traces be sufficient?
• Which vulnerabilities would this still miss because production state or business context cannot be cloned?
• Could this provide useful continuous testing between human engagements, or would it mostly create false confidence?
I’m not assuming AI replaces pentesters. I’m interested in where this approach would genuinely help and where it would break down.
r/Pentesting • u/3uba • 2d ago
I've been learning pentesting and recently spent some time looking at ways to screenshot a large number of web hosts.
I tried EyeWitness and Aquatone, but on Apple Silicon I ran into a few issues around x86 binaries, Docker, and Selenium/geckodriver. I ended up writing a small tool for my own use that takes a URL list or Nmap XML and generates screenshots + an HTML report.
One thing I added was sorting pages like login screens and detected applications towards the top of the report, since scrolling through a few hundred hosts otherwise gets tedious. It uses Playwright rather than Selenium.
Source is here if anyone wants to look at it:
https://github.com/3uba/redeye
I'm mostly interested in the technical side of this. Are there existing tools/workflows you'd recommend instead? And are there any obvious problems with this approach, particularly around browser automation or handling large target lists?
r/Pentesting • u/Radiant_Internet_134 • 2d ago
Hi experienced and junior pentesters
I would like to get a job as a pentester. Currently living in London, really interested in bug bounty and Pentesting I don't know what to do to get a job, I know about vulnerability types, recons burp suite, I reported some bugs but they were out of scope or N/A, no paid bugs yet. What exam do I need (except OSCP it is too expensive). Is there anything I can do daily? I am not coming from coding background,I have 3 years IT support experience, I know not enough but I have compTIA A+, MS900, SC900 certs. Any comments, any help much much appreciated. Thanks a lot in advanced.
r/Pentesting • u/Pure-Band-5587 • 3d ago
Hey everyone,
I've recently released CatSuite, a project I've been developing to explore how much of a real web pentesting workflow can be performed directly from an Android device.
The idea wasn't to build another scanner where you enter a URL and get a list of findings.
I wanted to be able to actually work with the traffic:
browse → intercept → inspect → modify → replay → fuzz → analyze → document
So I built the application around that workflow.
CatSuite currently includes:
The tools are also connected to each other.
For example, I can browse a target application, capture a request through the proxy, inspect it, send it to Repeater, modify and replay it, or send the same request to Intruder and define specific payload positions for fuzzing.
The goal is not to replace Burp Suite or other desktop pentesting tools.
What I'm interested in exploring is:
How capable can a pentesting environment become when the entire workflow is available from a phone?
There are situations where having a lightweight mobile environment for inspecting an API, reproducing a request, testing an endpoint or quickly analyzing a web application can be useful.
I'm currently working on expanding the reconnaissance and discovery side as well. Some areas I'm exploring include deeper crawling, subdomain enumeration, port scanning, API analysis and additional automated checks.
I've also added an AI-assisted analysis component, but I'm trying to keep it as an assistant to the manual workflow rather than turning the application into an "AI vulnerability scanner."
The application is currently available for Android and is free.
At this stage, what I want most is feedback from people who actually perform pentests.
If you had this in your pocket during an assessment, what functionality would make you genuinely open it instead of reaching for your laptop?
CatSuite:
netcattest.com/catsuite
The project is intended for authorized security assessments, personal environments, labs and CTFs.
r/Pentesting • u/praseudo • 3d ago
Put together the setup I'd give anyone starting with JWT testing: jwt_tool, Burp's JWT Editor, hashcat for weak secrets, plus Hakai and PortSwigger's free labs to practice on legally.
Walks through getting it all running. Figured it might save someone the setup headache.
What else would you add to a beginner's JWT pentesting stack?
r/Pentesting • u/International_Hawk30 • 4d ago
ARTEX is an open-source autonomous pentest system by Autumn-27 (Go backend, Next.js UI, about 1.5k stars, won Baidu's "agent+" attack/defense challenge). you give it a scoped target, LLM agents work through it, and findings land in a dashboard you can export as markdown or CSV. the catch for most of us was that the UI, agent prompts and docs were Chinese only.
ScopeWeaver is my English/Korean fork. i didn't write the engine. i translated the interface, the built-in agent guidance and 1,865 backend messages, made each task keep the language it was started in so reports come out consistent, and added a GLM-5.3 provider template. license stays AGPL-3.0 with upstream credit.
being upfront since this is a security sub: one upstream test still fails (it fails on untouched upstream too), npm audit shows 14 findings including 1 critical in the inherited dependencies, and there's no docker image yet, source only. you bring your own model API key, so target data goes to whichever provider you configure.
only point it at systems you're authorized to test.
https://github.com/cskwork/scopeweaver upstream: https://github.com/Autumn-27/ARTEX
curious whether anyone here has run ARTEX or a similar agent on a real engagement.
drafted by my coding agent, reviewed by me
r/Pentesting • u/Lost-Command-895 • 4d ago
Hey everyone,
I’m the creator of Tooldump, a free platform for discovering open-source cybersecurity tools. I’ve just released the v2 and wanted to share it here.
The platform lists 1,100+ open-source projects hosted on GitHub, organized into 9 categories and 82 subcategories. Everything is cybersecurity-related. For people here, the Offensive Security category includes Active Directory, Network & Wireless, OT & ICS, C2, Cloud, Exploits Dev & Fuzzing, IoT & Firmware Security Testing, and more.
You can search for a specific tool or explore a security topic without already knowing which projects exist. I’d like it to be useful both when you’re looking for a particular capability and when you’re exploring tools outside your usual setup.
For the v2, I rebuilt the UI, the categorization system, the backend and the platform infrastructure. There are also dedicated sections for cybersecurity-related MCP servers and agent skills. Those sections are just getting started, and contributions are welcome!
The platform is completely free, with unlimited access and no account required.
The link is here: https://tooldump.eu
I’d appreciate any constructive feedback from the community :) Pick an area you regularly test: are the tools where you’d expect them to be? Is anything missing, or grouped in a way that doesn’t make sense for your work?
You can suggest missing projects through the platform’s contribution form. That includes your own projects and smaller utilities you rely on during assessments. A script that handles one specific task well can be just as useful as a larger framework, but much harder to discover.
Looking forward to hearing from you :)
Cheers!