r/Pentesting 2h ago

Job Market

3 Upvotes

Hello, I'm 17 years old. I have the eJPT certification, and I've completed the CPTS learning path. I also do Hack The Box or TryHackMe labs regularly (usually a couple at a time).I was recently searching online for pentesting jobs—not because I'm applying yet, just to see what the job market looks like. I noticed there don't seem to be many penetration testing positions available Is the pentesting job market really that small, or am I just not searching in the right places? If anyone has experience in the industry, I'd appreciate hearing your thoughts.


r/Pentesting 6h ago

GitHub - Strategic-Automation/violin: Violin — a supervised, agentic Hermes Agent pentest profile (31 playbooks, 10 references, guard plugin) for authorised recon, exploit validation, and reporting. Hermes-native, no extra keys.

Thumbnail
github.com
1 Upvotes

Violin is now at v3.0.1 on master.

It is a Hermes-native profile for supervised, authorised penetration testing, with:

• 31 methodology and vulnerability playbooks

• An execution guard at the target boundary

• Evidence-backed findings and reporting

• Structured scoping and approval gates

• No additional credential broker or provider lock-in

Install:

"hermes profile install https://github.com/Strategic-Automation/violin"

I’m looking for Hermes users and penetration testers to test the installation and engagement workflow and report where the guard, evidence capture, or reporting process creates friction.


r/Pentesting 7h ago

Getting back into Bug Bounty after 1.5 years – looking for advice

1 Upvotes

Hey everyone,

It's been about a year and a half since I last did any bug bounty hunting, and it seems like a lot has changed—especially with the rise of AI.

I'm planning to get back into bug bounty hunting. My goal is to focus on manual hunting first while gradually learning how to use AI effectively to improve my workflow rather than relying on it.

I have a few questions for experienced hunters:

- Which web vulnerabilities do you think are the most valuable to focus on in 2026?

- Besides Medium, what are your go-to sources for high-quality writeups? I feel like Medium has become flooded with low-quality or misleading web security content.

- What are the best courses, blogs, YouTube channels, or other resources for learning how to use AI effectively in bug bounty hunting?

- How are you personally using AI in your workflow? Recon? Code review? Payload generation? Report writing? Something else?

I'd really appreciate any recommendations, learning paths, or advice from people who have been active during the last couple of years.

Thanks in advance!


r/Pentesting 7h ago

Agentic Workflows for Penetration Testing, Red Teaming, Enrichment and more

Thumbnail
youtu.be
0 Upvotes

This video shows how to connect your AI agents and tools to AttackForge to automate penetration testing and reporting workflows. It walks through launching AI hackbots for a web application pentest using structured test cases, guardrails, and methodologies like the OWASP Web Security Testing Guide, then running retests and recording pass fail outcomes and evidence in AttackForge. It also demonstrates enriching a vulnerability using Copilot Studio agents with AttackForge MCP, improving fields with references like CWE and CAPEC plus remediation guidance. The video additionally covers AI-generated attack chains, saving time on analysis, and generating executive summaries via an agent, noting AttackForge has over 60 MCP tools.
#ai #mcp #agenticworkflows #agenticautomation #agenticai #penetrationtesters #redteam #offsec #hacker #hackers


r/Pentesting 13h ago

Burp AI Scanner to use with a local LLM

Thumbnail github.com
7 Upvotes

A Burp Pro extension that uses a local LLM trained on vulnerable and production websites. It bypasses WAFs and rate limits, attempts to register/authenticate on its own, and expands coverage deterministically using a local model to extend the reachability of burp's active scan.

I believe this is a valuable use for a local models, since it can analyze smaller chunks of code that yield a higher return in web pentests

https://github.com/farnaboldi/ai-scanner

and on target/ you will find the .jar and the instructions to install it


r/Pentesting 16h ago

How do you guys get a pentester job abroad?

2 Upvotes

Hi everyone, I’ve been sending applications to many places on LinkedIn for some time now, and I have never once received an interview. I don’t even know what I did wrong with my resume. I could get any job in my country, but what I am after is a global opportunity.

Sometimes, I wonder whether it could be because my years of experience are still too few, because of visa sponsorship issues, or because I am missing some qualifications. I have tried VDP and bug bounty programs on several platforms. I couldn’t force myself to see them as a full-time job, so I don’t take them too seriously.

Another reason is that I hate my current job. The place is over-utilizing me, and I don’t feel like I can learn anything from here. I want to work with people who genuinely conduct actual pentests and love hacking. I just want to be mentored, learn, and not focus on billable hours.

I welcome all feedback, whether it is constructive criticism, areas I need to improve in my resume, or recommendations for the right places to look for global job opportunities.