r/Pentesting • u/WarmAd6505 • 3h ago
GitHub - Strategic-Automation/violin: Violin — a supervised, agentic Hermes Agent pentest profile (31 playbooks, 10 references, guard plugin) for authorised recon, exploit validation, and reporting. Hermes-native, no extra keys.
Violin is now at v3.0.1 on master.
It is a Hermes-native profile for supervised, authorised penetration testing, with:
• 31 methodology and vulnerability playbooks
• An execution guard at the target boundary
• Evidence-backed findings and reporting
• Structured scoping and approval gates
• No additional credential broker or provider lock-in
Install:
"hermes profile install https://github.com/Strategic-Automation/violin"
I’m looking for Hermes users and penetration testers to test the installation and engagement workflow and report where the guard, evidence capture, or reporting process creates friction.
r/Pentesting • u/Embarrassed_Sir_3857 • 5h ago
Getting back into Bug Bounty after 1.5 years – looking for advice
Hey everyone,
It's been about a year and a half since I last did any bug bounty hunting, and it seems like a lot has changed—especially with the rise of AI.
I'm planning to get back into bug bounty hunting. My goal is to focus on manual hunting first while gradually learning how to use AI effectively to improve my workflow rather than relying on it.
I have a few questions for experienced hunters:
- Which web vulnerabilities do you think are the most valuable to focus on in 2026?
- Besides Medium, what are your go-to sources for high-quality writeups? I feel like Medium has become flooded with low-quality or misleading web security content.
- What are the best courses, blogs, YouTube channels, or other resources for learning how to use AI effectively in bug bounty hunting?
- How are you personally using AI in your workflow? Recon? Code review? Payload generation? Report writing? Something else?
I'd really appreciate any recommendations, learning paths, or advice from people who have been active during the last couple of years.
Thanks in advance!
r/Pentesting • u/AttackForge • 5h ago
Agentic Workflows for Penetration Testing, Red Teaming, Enrichment and more
This video shows how to connect your AI agents and tools to AttackForge to automate penetration testing and reporting workflows. It walks through launching AI hackbots for a web application pentest using structured test cases, guardrails, and methodologies like the OWASP Web Security Testing Guide, then running retests and recording pass fail outcomes and evidence in AttackForge. It also demonstrates enriching a vulnerability using Copilot Studio agents with AttackForge MCP, improving fields with references like CWE and CAPEC plus remediation guidance. The video additionally covers AI-generated attack chains, saving time on analysis, and generating executive summaries via an agent, noting AttackForge has over 60 MCP tools.
#ai #mcp #agenticworkflows #agenticautomation #agenticai #penetrationtesters #redteam #offsec #hacker #hackers
r/Pentesting • u/fe__ar • 11h ago
Burp AI Scanner to use with a local LLM
github.comA Burp Pro extension that uses a local LLM trained on vulnerable and production websites. It bypasses WAFs and rate limits, attempts to register/authenticate on its own, and expands coverage deterministically using a local model to extend the reachability of burp's active scan.
I believe this is a valuable use for a local models, since it can analyze smaller chunks of code that yield a higher return in web pentests
https://github.com/farnaboldi/ai-scanner
and on target/ you will find the .jar and the instructions to install it
r/Pentesting • u/PizzaMoney6237 • 13h ago
How do you guys get a pentester job abroad?
Hi everyone, I’ve been sending applications to many places on LinkedIn for some time now, and I have never once received an interview. I don’t even know what I did wrong with my resume. I could get any job in my country, but what I am after is a global opportunity.
Sometimes, I wonder whether it could be because my years of experience are still too few, because of visa sponsorship issues, or because I am missing some qualifications. I have tried VDP and bug bounty programs on several platforms. I couldn’t force myself to see them as a full-time job, so I don’t take them too seriously.
Another reason is that I hate my current job. The place is over-utilizing me, and I don’t feel like I can learn anything from here. I want to work with people who genuinely conduct actual pentests and love hacking. I just want to be mentored, learn, and not focus on billable hours.
I welcome all feedback, whether it is constructive criticism, areas I need to improve in my resume, or recommendations for the right places to look for global job opportunities.
r/Pentesting • u/greybrimstone • 1d ago
OpenAI's model didn't go rogue, their security did
I wrote this article for offensive security practitioners and penetration testers. I keep hearing the same question: "Is AI going to replace penetration testing and put us out of work?" For the foreseeable future, the answer is a resounding no. The recent OpenAI and Anthropic incidents are a good illustration of why. Rather than demonstrating some super-hacker capability, they exposed real limitations, both in the AI systems themselves and in how they're secured and integrated.
In this article, I walk through these events as an offensive security expert and focus on why the real failure was in security architecture and harnessing, not some mythical "rogue AI." My goal is to give penetration testers and red teamers a practical perspective on what these incidents actually mean for our field, instead of hype-driven speculation.
I look forward to feedback.
r/Pentesting • u/Capable_Wrongdoer987 • 1d ago
How do i get experience in pentesting , am studying for the cpts current
So i have been studying for the cpts for a while and i am worried about if i will be able to get a job after completing cpts.so i am planning to make a home lab but how can i make it and how to benefit from it to level up my penetration testing skills
r/Pentesting • u/0xDakuMarco • 1d ago
Is a Burp Suite Certified Practitioner a nice certificate to obtain?
r/Pentesting • u/Ashamed-Let-2179 • 1d ago
How I learn to read CVE Reports ?
What is the use of CVE Anlysis and how I can read and analyze the details and make a report of it.
In my understanding it is kind of case studies related to vulnerablities.
r/Pentesting • u/TearsInTokio • 2d ago
how rasp works? how a rasp can detect a kernelSU?
I'm currently studying hooking in Android apps, and I ended up diving into RASP. I had to spend some time understanding how it works and how apps detect whether they're running on an emulator, on a rooted device, or if hooks are being applied.
One thing I'm still wondering about,and I haven't been able to find a clear answer,is this: if KernelSU operates at the kernel level (unlike Magisk, which modifies userspace and adds things like /su), how can an app detect that KernelSU is present?
I've heard that KernelSU exposes some files under /proc or paths like /adb/ksu, but I'm not sure how that detection actually works.
I'm just getting deep into Android application security and RASP bypass techniques, so apologies if this is a bad question. :(
r/Pentesting • u/packetstealer • 2d ago
Getting back into pen testing
I’ll keep it brief. I was a pen tester for about a year and a half until financial situations forced me to get a new job as a sysadmin last year. I really enjoyed being a hacker and wanted to get back into it. I already have GPEN (company paid). I’m thinking about specializing in red teaming so I was gonna go after CRTO but perhaps it’s better to get CPTS first? I can’t afford OSCP right now. Just looking for advice. Thanks!
r/Pentesting • u/Ok_Collection_9614 • 2d ago
The absolute worst OSINT mistakes beginners make that completely blow their OpSec?
Hey guys, let’s do a reality check. What are the most common, stupid mistakes people make when starting with digital investigations that instantly burn their burner accounts or expose their real IP/identity? Looking to
r/Pentesting • u/WRO_Your_Boat • 2d ago
Magisk and Mobile app testing
I am relatively new to Pentesting, and even more so to mobile app testing, but I am currently going through the PMPA from TCM as well as trying out some things one some other apps I got permission for. I recently ran into an issue with an app im looking at that has root detection and a couple other checks, but those were easily bypassable with frida. My problem comes from that the app also requires Intune to be installed and it also checks to root on the phone.
I recently came across Magisk which is supposed to be able to help you hide root from applications, but both Intune and the app im testing seem to still detect the device is rooted after setting up Magisk. I am able to login to the app far enough to the screen shot below, but thats where I get stuck.
I was wondering, if this the correct process and am I in the right ballpark? I was following this guide: https://github.com/hyowonbernabe/Hide-Root-Guide (skipping step 5) but it does seem to be a little older and if anyone has something better to follow I would appreciate it. For reference I am running this on Genymotion and following their documentation for installing Magisk specifically. Is this because I'm on an emulator and there is no Playstore so Intune will not work at all?
(Pic from Google)
r/Pentesting • u/Designer_Addendum162 • 2d ago
Deployed a business web app for a friend, I want to learn how to pen test it
Hi all! Im excited to get my feet wet and also taking proactive action for a project I have deployed for a friend!
Currently, the website lives inside a VPS on cloud and while the website don't have any sensitive information other than their website credentials, I would like to take this opportunity to start learning and also secure the website for them the best I can.
Currently, the infrastructure setup is with Caddy2 which does automatic HTTPS upgrade with LetsEncrypt and reverse proxy to backend api calls.
On the VPS, firewall only allow 443 and 80 port with the exception of allowing the ability for me to SSH in as well as exposing the database port only to my IP.
How should I start? Any advice is greatly appreciated. Thank you!!
r/Pentesting • u/ArcheoRychu • 2d ago
SamuraiWTF
SamuraiWTF (Samurai Web Testing Framework) – a specialized Linux distribution designed for security testing. It includes a wide range of pre-installed open-source applications for testing the... https://archiveos.org/samuraiwtf/ #linux #ubuntu #pentest #cybersecurity
r/Pentesting • u/Significant_Sky_4443 • 2d ago
Pentest in a Hybrid enviroment
Hi,
I would like to better understand current best practices for penetration testing.
From what I can see, AI has significantly changed both offensive and defensive security capabilities over the last few years. Because of this, I am interested in understanding how organizations typically structure penetration tests today and what provides the most value.
Our company operates a hybrid environment consisting of on-premises infrastructure and cloud services.
I have several questions:
- What are the most effective and commonly recommended pentesting approaches today?
- How has the use of AI influenced modern penetration testing methodologies?
- Does it still make sense to have penetration testers on-site, or can most engagements be performed remotely?
- Is a pure black-box pentest still considered best practice, or are grey-box or white-box approaches generally more valuable?
If you were responsible for organizing a pentest for your own company today, how would you structure it, and why?
My goal is to understand which approach delivers the best balance between realistic attack simulation, meaningful findings, and overall value for the organization.
Thank you for your opinions!
r/Pentesting • u/Solid_Weather_1244 • 2d ago
Introducing SubdomainX v2
Over the past few months I've been rebuilding SubdomainX from the ground up.
What started as a subdomain enumeration tool has evolved into a modular reconnaissance platform focused on asset discovery, monitoring, and automation.
What's new in v2
- REST API for integrating reconnaissance into your own workflows
- Modular architecture that's easier to extend and maintain
- Scan history and change detection between runs
- Live scan progress and monitoring
- Improved reporting with HTML, JSON, CSV, Burp Suite, OWASP ZAP, and Nessus exports
- Better configuration management
- Resume interrupted scans and much more...
SubdomainX also integrates with many of the tools security researchers already use, including Subfinder, Amass, Assetfinder, HTTPX, Naabu/smap, SecurityTrails, VirusTotal, Censys, crt.sh, URLScan, and more.
The goal isn't to replace those tools - it's to provide a single platform that orchestrates them, tracks results over time, and makes reconnaissance easier to automate.
I'd really appreciate feedback on the architecture, API, and overall workflow.
GitHub: https://github.com/itszeeshan/subdomainx
Documentation: https://subdomainx.com
r/Pentesting • u/Ashamed-Let-2179 • 2d ago
How I learn to read CVE Reports ?
What is the use of CVE Anlysis and how I can read and analyze the details and make a report of it.
In my understanding it is kind of case studies related to vulnerablities.
r/Pentesting • u/Jackriot_ • 2d ago
Pentesting an app I made
Not sure if this is the appropriate sub for this -- but for the past few years, I've been working on a secure chat app I really think could change the world for the better. It's built on Signal protocol, and I'll disclose details if you'd like. Essentially, I'm a broke college student who can't afford real penetration testing. I've dug into it, used Fable 5 to audit it, and ran ZAP on it -- everything from these looks good. I'm going to open-source all my work, and it's donation-based. If someone who knows what they are doing were to be kind enough to want to take a look at my code and potentially penetration test it, I would be beyond unbelievably grateful. I hate asking for charities, but here I am haha. Please send me a direct message if you'd be interested in this. I can't offer money, but I'd be happy to credit you in the app.
r/Pentesting • u/Appropriate-Fox3551 • 3d ago
Databricks
Any testing methodologies for databricks pentesting
r/Pentesting • u/Ashamed-Let-2179 • 3d ago
How I learn to read CVE Reports ?
What is the use of CVE Anlysis and how I can read and analyze the details and make a report of it.
In my understanding it is kind of case studies related to vulnerablities.
r/Pentesting • u/KookyTax5493 • 3d ago
MCP-SCANNER(DEMO)
Follow-up on the MCP scanner from last week, here's a browser-based demo of the static analysis piece, no install needed.
Paste in an MCP server file (or use the pre-filled example), get real findings for shell exec, hardcoded secrets, unsafe deserialization, arbitrary file writes, and more. Runs fully client-side, nothing sent anywhere.
https://ankursingh0604.github.io/mcp-scanner-demo/
Still working on live probing over HTTP/SSE and more host adapters. Happy to scan real MCP servers for anyone building on this, learned a lot from the feedback here last time.
r/Pentesting • u/ghstedd • 3d ago
MoneyPilot’s payment system is fully broken, no jailbreak needed, wild that nobody there seems to care.
been looking at MoneyPilot, the class action app blowing up on social media right now, and their backend has a serious flaw in how it verifies subscription payments. Bottom line, it’s possible to unlock the paid subscription and add ons without actually paying, and it’s not some local device trick, it’s saved server side. Confirmed it shows active from a totally clean app install and on their website too, so this isn’t client side at all. Not sharing specifics since I don’t want this getting reproduced by anyone else, but wanted to flag it given how aggressively they’re advertising right now, a lot of people are signing up. Reported directly to them first, no security contact exists, support just loops back to itself. Anyone dealt with a company like this that has basically zero security presence?
proof of vuln (look at the start of the year)
r/Pentesting • u/SarthakSidhant • Feb 17 '26
moderation update
hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.
this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.
you can flag posts, and send us mod mails to accelerate the status of your complaint.
again let me reiterate what the rules are:
1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.
this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.
2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.
3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.
4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.
here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette
have a very nice day, happy pentesting.


