AI-Assisted Pentesting: Where LLMs Help and Where They Fail
After a couple of years of using language models in real engagements, a candid assessment of the tasks they are genuinely good at and the ones they quietly make worse.
After a couple of years of using language models in real engagements, a candid assessment of the tasks they are genuinely good at and the ones they quietly make worse.
Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.
Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.
How to pick the right attack mode for a given hash set, and why the wordlist matters far less than the rule file.
The misconfigurations and kernel issues that turn ‘we run containers’ into ’the container is a perimeter you don’t have’.
Why requesting service tickets for accounts with SPNs is still one of the most reliable ways to escalate from a domain user to plaintext credentials.
A practical pipeline for building and maintaining an accurate external asset inventory before you touch a single target.
How I set up a repeatable home lab for practising internal network attacks without touching anything I don’t own.