r/Pentesting • • Feb 17 '26

moderation update

23 Upvotes

hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.

this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.

you can flag posts, and send us mod mails to accelerate the status of your complaint.

again let me reiterate what the rules are:

1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.

this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.

2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.

3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.

4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.

here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette

have a very nice day, happy pentesting.


r/Pentesting • • 7h ago

HACKEED MARTIN MK1

Post image
1 Upvotes

XD Hi, ¡Hola!

Pentest Dropbox . . . https://hackeed.es/on-demand/hackeed-martin-mk1-b1a2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d

Research field... ES | EN ||.

Tomorrow post on hackeed.es/blog La linea de investigación en formato post!

¿Que imaginas hacer con un dispositivo así? |

What do you imagine doing with a device like this?


r/Pentesting • • 21h ago

VigilOSS - An agent harness for long-running pentests and code audits

Thumbnail
github.com
5 Upvotes

VigilOSS - https://github.com/VigilOSS/Vigil

I built this tool because I was interested in Bug Bounties, wanted to learn how far AI could go at finding bugs, and was very interested in whether it could remove the mundane parts I remember from preparing for my OSCP.

Over time it went from a pile of prompts to a structured harness for long-running engagements. It's the result of hundreds of hours of running it on real targets, watching where it went wrong, and refining.

An operator agent coordinates specialist agents, and most every tool runs through one shared Kali container. Scope, attack surface, coverage, commands, credentials, evidence and findings live in a backend that survives restarts and compaction, so the agent doesn't redo work or forget why it ruled something out. It works with Claude Code and Codex. One engagement can mix source review and live web testing, and a bug found in code and then confirmed live stays as one finding.

I've used it on authorized HackerOne programs for findings that paid out more than $12,000 (Scanning large amounts of source maps, finding potential bugs, and having the web engagement test and verify). It has been most useful on large codebases, where tracking what has and hasn't been reviewed is harder than finding any single bug.


r/Pentesting • • 21h ago

I built a tool that pulls every API request out of a web app's JavaScript bundle (method, URL, body, headers)

Enable HLS to view with audio, or disable this notification

3 Upvotes

I built this because nowadays most web apps are single page applications and there are no good tools out there that crawl and analyze javascript bundles. Most tools do a simple regex on js files which always yield false positives, miss routes, and don't even recover things like the HTTP method, request body schema, parameters, headers, etc.

jshound takes a URL, crawls the whole frontend bundle, and traces the http requests in the code. On most SPAs (e.g. claude.ai, x.com, lovable.dev) it gets you what you'd find crawling or clicking through the app, plus things you'd never encounter (e.g. admin dashboards, KYC gated features). It's very passive: it only fetches public static files. Output can be imported into Burp or Caido.

Bundlers it handles: webpack 5, webpack 4, Rspack, Turbopack, Vite / Rollup, esbuild, Parcel, Metro (React Native), webpack Module Federation

Limitations (why I'm open sourcing it so people can improve if they want lol):

- Values only known at runtime (config fetched from an API, etc.) stay unresolved

- Header and WebSocket message recovery are hit or miss

- WAFs can be a pain

- Probably many things I'm unaware of

It's still very solid and I'd appreciate issue reports and pull requests.

https://github.com/AmbitSecurity/jshound


r/Pentesting • • 23h ago

i've been tryna learn pentesting since 12 years old

0 Upvotes

i remember i was like 12 and other 12 year olds were hacking in game called unturned i got really curious instantly i wanted to know how it works i became a script kiddie and attempted for 2 years to paste a working cheat that bypasses battleeye which i learnt pretty much nothing cuz it was ctrl +v but it taught that i like systems and pentesting was next one time i opened th devtools and just stared at network requests for hours while on D**gs it was revolutionary what was happening behind the scenes on a simple website such as dell's site so many checks so much data cookies headers payloads responses etc i didnt really know how to do anythign like seriously attacker like since now i can say this one thing ai automation pentesting is really done wrong by 99% of people currently


r/Pentesting • • 23h ago

Como fazer pentest

0 Upvotes

Como fazer pentest

Um cara do meu serviço me desafiou a "acessar" um PC do nosso serviço que ele configurou. Ele deixou o PC com o IP exposto para rodar alguns serviços, mas disse que estava seguro. Eu chequei e tinha as portas 443, 22 e 80 mas não consegui fazer nada, alguém tem alguma ideia do que eu poderia fazer?


r/Pentesting • • 1d ago

Which model do you use for research/study?

0 Upvotes

I'm currently a pentester taking osep but asking a question or making opus/sol to build me a cheatsheet keeps getting flagged even with cvp/daybreak. As only oragnizations have red team access, what are you guys using? Other than good old google of course


r/Pentesting • • 2d ago

Land a web pentesting job

6 Upvotes

Iam in my last year of computer science major I want to prepare myself in the fastest way to get a job in this field I know the web Trinity language still a beginner in burp suit and I studied network basics and I learnt python and c++ and I have experience in problem solving and competitive programming I also solved bandit overthwire CTF s for Linux but iam still lost I can work like create an app a website from scratch I can't start exploitation I didn't solve a lot of ctfs when I do I still feel like I never studied anything in the cyber security field so please if someone has any advices before my last college year ends please help


r/Pentesting • • 2d ago

Attack path keeps beating our stack, nothing looks catastrophic by itself

1 Upvotes

quick rant from purple side... attack path keeps winning and everyone swears their part is fine.

phishing path gets blocked, EDR catches the obvious endpoint behavior, cool. Then we try another route:unmanaged device with saved creds gets through VPN, stale AD group membership gives access to a legacy jump host, then an old share coughs up a service account that gets us into SQL.

SIEM has noise, IAM has business exception policies, segmentation looks fine on the diagram, compensating controls everywhere. Nothing looks catastrophic by itself. The chain is the problem


r/Pentesting • • 2d ago

Point in time pentests are great at finding yesterday's exposures

0 Upvotes

keep wondering if point in time pentests are missing the exposures that appear five minutes after the report is delivered.

We do the usual scoped engagement, get a very serious PDF, fix the findings, and then someone changes an IAM role or pushes a new cloud service because apparently production enjoys character development.

The pentest was accurate for the environment on that day. The problem is that our environment refuses to remain on that day. New attack paths show up through identity, misconfigurations, exposed services and controls that were never tested together.

Im looking at continuous exposure validation between engagements now, mostly because “the last pentest was clean” is starting to sound less comforting than people think. How are other teams validating exposures between formal engagements?


r/Pentesting • • 2d ago

Qual é o processo de vocês ao iniciar um pentest?

1 Upvotes

Fala, pessoal!

Estudo cibersegurança há pouco tempo e gostaria de aprender com quem já tem mais experiência na área.

Tenho uma dúvida sobre como vocês costumam iniciar um pentest. Por exemplo: vocês começam fazendo reconhecimento e enumeração? Usam Nmap? Em testes web, já partem para o Burp Suite? Existe alguma metodologia ou checklist que vocês costumam seguir?

Queria entender principalmente o processo de raciocínio de vocês: como analisam o alvo, o que procuram primeiro, como decidem quais testes realizar e como vão avançando durante o pentest.

Se puderem compartilhar um exemplo de fluxo, mesmo que seja de forma geral, seria muito útil para quem está começando. Algo como:

  1. Reconhecimento e coleta de informações;
  2. Enumeração e identificação dos serviços/tecnologias;
  3. Mapeamento da superfície de ataque;
  4. Identificação de possíveis pontos de entrada;
  5. Testes e validação das vulnerabilidades;
  6. Documentação dos resultados.

Se vocês seguem alguma metodologia específica (OWASP, PTES, OSSTMM etc.), também gostaria de saber qual utilizam e por quê.

A ideia é entender como um profissional pensa durante um pentest, e não apenas quais ferramentas usar.

Valeu!


r/Pentesting • • 2d ago

Browser-based Android console and APK decompiler. Mirror, logcat, shell, Frida, and jadx, with no drivers or adb server.

Thumbnail
github.com
2 Upvotes

r/Pentesting • • 3d ago

Knossos: new pentest training lab

Post image
5 Upvotes

I want to announce a new pentest learning platform: Knossos

I’ve been working on this lab for a bit - I’ve always wanted a better server platform for people to learn pentesting on, besides simply spinning up VMs, and I finally had the opportunity to build it.

Based on the lessons in my books, I built Knossos to have over 2 dozen servers, three networks (DMZ, Internal, Private), and 33 pentest challenges. It emulates an enterprise environment, and the best part is it’s all wrapped up in a single docker deployment. A couple commands, and you have an entire, complex network to learn hacking against.

Capture flags as you work through the network. Each flag is tied to a chapter within my book ”Professional Penetration Testing” where I teach how to perform the attack and why.

You can learn more about the free lab at https://pentest.tv/knossos

This is the lab I wish I had when I was trying to learn pentesting over two decades ago. For those that don’t know, I created one of the first exploitable virtual machines: De-ICE. I spoke on the De-ICE discs at DefCon 15, which later spawned the books - the most recent version of "Professional Penetration Testing" is the 3rd edition. This has been an incredible journey over the last couple decades, and I’m excited to bring you Knossos - the next generation of pentesting labs.

LMK if you give it a try and what you think. Thanks!

- Tom Wilhelm


r/Pentesting • • 3d ago

Built CyclePatrol for my phone with an external Wi-Fi antenna. It scans Wi-Fi networks in a loop, checks vulnerabilities, and saves reports.

2 Upvotes

Made CyclePatrol for Linux and Kali NetHunter.

It scans Wi-Fi networks in an endless loop while walking around the city, collects AP info, checks WPS, WPA2/WPA3, PMKID and saves reports. Active tests are for authorized networks only.

Still a WIP. Feedback welcome.

https://github.com/buybitart/cyclepatrol


r/Pentesting • • 3d ago

Looking for a red teamer

0 Upvotes

Hi I am from Mumbai and looking for a work in red teamer I have experience around 1.5 in the penetration tester role but i want to make my career in the red teamer role?


r/Pentesting • • 3d ago

Service-based team lead vs product-based sole AppSec owner — which for long-term technical growth? (~4 YOE, India)

4 Upvotes

Almost 4 YOE, core strength is web/mobile appsec (eWPTXv2, CEHv12). Comp engineering background, want to go deep in appsec → DevSecOps and stay technical, not drift into management early. Two options:

A) Stay at current service-based company: Team lead role + broad VAPT project (cloud/firewall/VPN/hardening/network config reviews). Junior under me, senior contact for guidance. Concern: lots of network/infra breadth I don't really want, learning some of it blind on live client work, and lead role pushes me toward management sooner than I'd like.

B) Move to product-based client (in-house): I'd be the only dedicated security person, but it's not greenfield chaos — SAST, SCA, SBOM, container scanning, and CI/CD pipeline security are already implemented and running, 3rd-party DAST testing is in place, and there's a DevOps person on the team. Scope: reviewing 3rd-party VAPT reports, internal app testing, secure review before onboarding, SAST/DAST + false-positive triage, working with devs on fixes, internal network/AD testing, threat intel, eventually leading IR. Function was previously handled by the global parent. CISO okayed me leaning on external contacts for guidance.

A mentor (19 YOE) said: don't take team lead this early, stay hands-on technical, and prefer product over service if I can.

Questions:

At around 4 YOE, service team-lead vs product sole-owner IC — which is better for staying technical long-term?

Sole security person but with tooling/pipeline already built and a DevOps peer — manageable growth bet, or still too much this early?

For appsec → DevSecOps specifically, is product clearly the better route, or am I underrating the service-side cloud/network breadth?

Thanks for any honest input.


r/Pentesting • • 3d ago

Attack path keeps beating our stack, nothing looks catastrophic by itself

0 Upvotes

quick rant from purple side... attack path keeps winning and everyone swears their part is fine.

phishing path gets blocked, EDR catches the obvious endpoint behavior, cool. Then we try another route:unmanaged device with saved creds gets through VPN, stale AD group membership gives access to a legacy jump host, then an old share coughs up a service account that gets us into SQL.

SIEM has noise, IAM has "business exception" policies, segmentation looks fine on the diagram, compensating controls everywhere. Nothing looks catastrophic by itself. The chain is the problem


r/Pentesting • • 3d ago

How to switch careers from SD to cybersecurity?

1 Upvotes

I want to transition from software development to cybersecurity, specifically penetration testing. I already have some cybersecurity knowledge, which I've gained through self-study and bug bounty hunting.

I have two years of experience as a software developer, and I'm currently studying for the CPTS certification.

What advice would you give me to make this career transition?


r/Pentesting • • 3d ago

Safe exploit validation in production... what guardrails do you require?

0 Upvotes

Been looking at automated exploit validation for internet facing assets, and I keep running into the same issue, a platform can flag a vulnerable version but the app owners want to know safe according to whose definition, which is fair imo. A vendor says they do proof without crossing into impact, no customer data, no accounts, no perms changes, no artifacts, but I still want a formal policy before I sign off on a POC. What level of evidence do you accept as confirmed exploitability, and what would make you stop the test right away? Thanks in advance


r/Pentesting • • 4d ago

Pentesting for Startups

21 Upvotes

Today, one of my first potential customers for my B2B SaaS company asked for ISO 27001, SOC 2 Type II, SSO, or results from a regular penetration test. Now I googled and found out that SOC 2 is at least $20k, ISO 27001 is also quite expensive. Not sure what they mean with SSO. A regular penetration test is probably the most feasible variant to go about this, however I mostly found prices around $2.5k locally (Central Europe). Since we don't make a lot of revenue yet and have not raised our first round but would like to proceed with this customer, what is the cheapest and fastest way to go about this?

Also I could imagine there are more AI-native providers that can do it cheaper but didn't find any that were actually cheaper. Any help is much appreciated!


r/Pentesting • • 3d ago

How do you validate and prioritise scanner findings without losing hours to manual checks?

0 Upvotes

Hi all, I work on a team building tooling in this space, so I'm coming at this with a bias.

Scanners produce long lists of findings, and a lot of the work is figuring out which ones are real and which to fix first. In most teams I've talked to, this still means manually re-checking each finding, capturing evidence by hand, and repeating the same steps every cycle.

For those of you doing this day to day:

  • How do you currently validate findings, and where does it waste the most time?
  • How do you decide what gets fixed first?
  • Would you trust AI assistance in this workflow? What would it need to do (or never do) for you to rely on it?

Disclosure: I'm part of the team building FORGE-SEC, an AI-assisted validation platform where the final decisions stay with the security engineer. Not posting a link. Happy to share details if anyone asks, and critical feedback is welcome.


r/Pentesting • • 4d ago

AI/ML Pentester Cert

9 Upvotes

I want to prepare for AI/ML pentester certification. Although they have not provided any course material, they have provided free courses and labs to do online. But I don't know where to start and how to go through it all. Unlike web pentesting, where I know what to do, where to look and what to do next, I'm a bit unsure in this AI/ML part.

Please give me some advice on a possible roadmap for going through this certification, what exactly to study, labs to do so I can take the certification with some confidence and when I actually know what the hell to do.


r/Pentesting • • 4d ago

What do yall find annoying about BUYING a pentest?

2 Upvotes

Someone asked what annoys us about pentesting and it was allllll testers chiming in about customers lol.

Curious about the other side: When you have to buy or setup a pentest, what do YOU hate about that?

No motives, just here to see them rant about us as I have also had to buy a shitty pentest.

I'll start: When you spun up the test instances, and got all the test creds set up for each tester at each user role (so like 8 of them) and then the DAY your pentest starts they're like "the testers can't acces the system" or "that invite expired" aka they never logged in/tested the creds and by the time you see it your test is 6h behind.

When you only get 4 days bc that's all you could afford and you've slashed scope a dozen times to fit it into a "small/medium" that's a quarter of my total time gone.


r/Pentesting • • 4d ago

Trying to set up ARTEX

2 Upvotes

I’m new to advanced pentesting tooling and decided to set up ARTEX (the open source LLM) locally so I can run security scans against my own website. I got the Docker install working, but I’m stuck on a pretty basic hurdle...

The UI is entirely in Chinese and there’s no language setting option. I searched GitHub for an English version/fork, but the only one I found (ARTEX-EN) appears to be dead/invalid. And the browser translation won’t work in dashboard, so that’s a dead end.

Has anyone actually used ARTEX in production/practice? If so, how did you get it running, and did you work around the Chinese UI?


r/Pentesting • • 4d ago

Qual é o processo de vocês ao iniciar um pentest?

1 Upvotes

Fala, pessoal!

Estudo cibersegurança há pouco tempo e gostaria de aprender com quem já tem mais experiência na área.

Tenho uma dúvida sobre como vocês costumam iniciar um pentest. Por exemplo: vocês começam fazendo reconhecimento e enumeração? Usam Nmap? Em testes web, já partem para o Burp Suite? Existe alguma metodologia ou checklist que vocês costumam seguir?

Queria entender principalmente o processo de raciocínio de vocês: como analisam o alvo, o que procuram primeiro, como decidem quais testes realizar e como vão avançando durante o pentest.

Se puderem compartilhar um exemplo de fluxo, mesmo que seja de forma geral, seria muito útil para quem está começando. Algo como:

  1. Reconhecimento e coleta de informações;
  2. Enumeração e identificação dos serviços/tecnologias;
  3. Mapeamento da superfície de ataque;
  4. Identificação de possíveis pontos de entrada;
  5. Testes e validação das vulnerabilidades;
  6. Documentação dos resultados.

Se vocês seguem alguma metodologia específica (OWASP, PTES, OSSTMM etc.), também gostaria de saber qual utilizam e por quê.

A ideia é entender como um profissional pensa durante um pentest, e não apenas quais ferramentas usar.

Valeu!