#offensivesecurity

11 posts · Last used 4d

Back to Timeline
Pentest-Tools.com @pentesttools@infosec.exchange · 4d ago
Nolan's Odyssey just hit theaters, and honestly, Odysseus had it easy. Ten years, one long trip, and he was done. ISO 27001 wants the trilogy every single year: detection, validation, remediation. Three-year cycle, a surveillance audit checking your homework annually. No one-and-done epic here. Pentest-Tools.com is ISO/IEC 27001:2022 certified. We run the same evidence trail on ourselves: ✅ Detection - CVE, severity, date, logged automatically ✅ Validation - confirmed findings, not just a score ✅ Remediation - retests prove the fix held ✅ Monitoring - scheduled scans, all three years long No sirens, no Cyclops, just a surveillance audit that stays a review instead of turning into its own odyssey. Full ISO 27001 evidence chain: https://pentest-tools.com/usage/compliance/iso-27001 #ISO27001 #offensivesecurity #infosec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · 4d ago
🤖 Hacker 'Trim' dismantles frontier AI models into an offensive attack platform, integrating jailbroken LLMs with Nmap, Metasploit, and C2 frameworks for automated exploitation. Weaponized AI moves from theory to practice. 🔗 https://www.darkreading.com/cyber-risk/hacker-ai-jailbreaks-offensive-attack-platform #AI #CyberSec #OffensiveSecurity
0
0
0
Pentest-Tools.com @pentesttools@infosec.exchange · 5d ago
We kept getting asked the same handful of questions before people would trust us with a scan against prod. So we answered them properly instead of one at a time on sales calls. Non-destructive by default. Our own detection engines, not a wrapper around someone else's open source tools. Findings come with evidence, not just a severity label. Data stays on EU infrastructure, workspaces isolated. Full FAQ: https://pentest-tools.com/product/faq #offensivesecurity #pentesting
0
0
0
hasamba @hasamba@infosec.exchange · Jul 16, 2026
---------------- 🛠️ Tool =================== Decepticon is an open-source autonomous red team agent developed by PurpleAILAB. The project explicitly distances itself from tools that "run nmap and write a report," targeting end-to-end engagement automation instead. Core Architecture The tool runs as a Docker-based stack with several components: • LiteLLM for LLM call routing across providers • PostgreSQL for data persistence • Neo4j as a knowledge graph for attack chain representation • LangGraph for agent orchestration • Skillogy for skill management • A sandboxed execution environment The orchestrator spawns specialist workloads on demand rather than running everything upfront. Documented specialists include BloodHound CE for AD reconnaissance, Sliver C2 for command and control, and Ghidra MCP for binary analysis. Activation is via commands like ops_start("ad"). Installation and Deployment Installation is via curl pipe to bash on macOS/Linux/WSL2, or PowerShell on Windows. The decepticon onboard command provides an interactive setup wizard for provider, API key, and model profile configuration. A web dashboard is accessible from the CLI via /web. A cloud-hosted version is available at app.decepticon.red for users who prefer not to self-host. SDK Usage The project ships a pip-installable SDK (pip install decepticon) with an optional neo4j extra for knowledge-graph attack-chain tools. The SDK provides agent factories, middleware, tools, and skills, routing LLM calls and sandbox execution through Decepticon infrastructure. This enables building custom orchestrators or integrating agents into existing products and research workflows. Technical Observations The on-demand specialist spawning model is worth noting. Rather than a monolithic tool, Decepticon treats each capability as a separate workload the orchestrator launches when needed. This modular approach makes it easier to extend or replace individual components. The Neo4j knowledge graph for attack chain representation is a meaningful design choice. It maintains structured state about engagement progress rather than relying purely on LLM context, which could make state inspection and chain reasoning more reliable. Limitations The project is relatively new. The README provides no benchmarks or comparison data against manual red team engagements. Haven't tested personally, so stability and orchestration quality in real environments remain open questions. The reliance on external LLM providers introduces API cost and rate limit concerns for extended operations. References • Repository: PurpleAILAB/Decepticon (GitHub) • Documentation: docs.decepticon.red • License: Apache 2.0 🔹 tool #redteam #decepticon #offensivesecurity #autonomousagent 🔗 Source: https://github.com/PurpleAILAB/Decepticon
0
0
0
Pentest-Tools.com @pentesttools@infosec.exchange · Jul 14, 2026
We point our own product at ourselves. The scanners and exploit modules our customers run, we run against our own infrastructure and web apps. New critical CVE, our own assets are among the first we test, so detection and validation hold up on us before they reach anyone else. The rest is the auditable stuff: ISO 27001, hosting and data retention, encryption, and where AI sits in the product (noise reduction, not deciding what's exploitable). All public, no NDA or sales call. Poke holes in it: https://pentest-tools.com/legal/trust-and-assurance #infosec #offensivesecurity #pentesting
0
0
0
Praetorian @praetorian_security@infosec.exchange · Jul 10, 2026
🔓 Brutus is a modern take on Hydra: pure Go, zero dependencies, one binary that brute-forces SSH, MySQL, PostgreSQL, Redis, SMB, and 20+ more protocols. Join Adam Crosser for a session live at Black Hat USA Arsenal. 🗓️ August 5, 11:20am to 12:20pm 📍 Arsenal Station 8, Business Hall 🎩 Black Hat session: https://lnkd.in/gHN__DNG ⭐ GitHub: https://lnkd.in/g8j_2CKp 📖 The story behind it: https://lnkd.in/gVphrxeP Stop by if you're on the floor! #Brutus #OffensiveSecurity #Praetorian
0
0
0
Pentest-Tools.com @pentesttools@infosec.exchange · Jul 09, 2026
Here we go. Product updates - the June edition. This month your coverage got a LOT wider. 80 new detections landed in the Network Scanner, including pre-auth RCE in Oracle PeopleSoft and an auth bypass in Palo Alto PAN-OS. If any are in your scope, you know where to look. The rest of June: 🌐 Our research team found two authentication flaws in phpBB, one buried in the code for over a decade. There's a working PoC for each, and the Network Scanner now detects the most critical one - CVE-2026-48611 (9.4). 🤖 AI where it earns its place in the Website Scanner and URL Fuzzer: smarter logins, deeper crawling, fewer fake 200 pages. 🎯 the XSS Exploiter now gives you two delivery options: script tag or fetch plus eval. 🔌 API: a new info_text key on /scans tells you why a scan didn't start. ☁️ We're now on the Microsoft Azure Marketplace, so you can add us to your existing Azure billing. Our colleague Stefan Perju walks you through all of it in the video. Until next time: stay sharp. Stay human. Everything that shipped can be found in the change-log: https://pentest-tools.com/change-log The phpBB PoCs and full write-up: https://pentest-tools.com/research/phpbb-authentication-bypass #offensivesecurity #vulnerabilitymanagement #infosec #penetrationtesting
1
0
0
Praetorian @praetorian_security@infosec.exchange · Jul 03, 2026
0
0
0
Praetorian @praetorian_security@infosec.exchange · Jul 02, 2026
🏛️ What if every attacker who breached your cloud was just walking deeper into a trap? Knossos generates decoy cloud environments from your real infrastructure, then turns every attacker move inside them into usable intelligence. The decoys pass the sniff test, so attackers waste time in the maze while every move feeds the Guard. Read: https://praetorian.com/blog/knossos-decoy-environments Demo: https://praetorian.com/praetorian-guard-demo #OffensiveSecurity #Praetorian #PraetorianGuard
0
0
0
Pentest-Tools.com @pentesttools@infosec.exchange · Jul 02, 2026
Our SQL Injection Scanner is a bit of a skeptic. It won't take a hunch for an answer. It fires a real payload, watches how the database actually responds, and _only then_ calls it a finding. It's free to try, and it catches: ✅ Error-based, when the database spills its structure in an error ✅ Blind, when only a true or false response gives it away ✅ Time-based, when a deliberate delay is the only tell ✅ Union-based, when someone's pulling data from tables they shouldn't touch Every finding comes with the parameter, the payload, and the database response. Enough to reproduce it, not just believe it. Try it as a test, no account needed. Link is here https://pentest-tools.com/website-vulnerability-scanning/sql-injection-scanner-online #offensivesecurity #penetrationtesting #ethicalhacking
0
0
0
Praetorian @praetorian_security@infosec.exchange · Jun 26, 2026
Most deception is built to evict intruders fast. Knossos goes the other way. 🪤 It procedurally generates a full decoy cloud environment that keeps attackers inside, burning time and resources while every move becomes detection signal. Realistic Terraform infra, breadcrumb trails that lead deeper, and alarms that fire the moment anything is touched, all isolated from production. 📝 See the full changelog: https://portal.praetorian.com/changelog/knossos-procedurally-generated-decoy-environments-that-turn-attackers-into-intelligence #infosec #offensivesecurity #praetorianguard
1
0
5

You've seen all posts