What is the Best AI for Pentesting
by Xrptcb - Tuesday March 11, 2025 at 06:43 PM
#1
I ve been messing around with DeepSeeek, Grok, Claude with various degrees of success curious what everyone's thoughts are using AI for bug bounty and "other stuff"
Reply
#2
try out ollama and the uncensored models. not as good quality as deepseek so far, but not as much limits also
Reply
#3
I say dont bother. by design, LLMs can only create mediocre code, because mediocre code is most likely to occur in the dataset. pentesting and bug finding are not at all mediocre tasks, I am pretty sure that LLMs are going to struggle no matter how good they are compared to GPT.
there are specialized AI models for binary analysis and such, but I only hear of them through articles, no published models
Reply
#4
https://github.com/GreyDGL/PentestGPT works great for me.
Reply
#5
(Mar 12, 2025, 01:19 PM)manfredmuellller444 Wrote: https://github.com/GreyDGL/PentestGPT works great for me.

I will definitely give that a go. building out the lab this weekend

(Mar 11, 2025, 10:50 PM)monalisa Wrote: I say dont bother. by design, LLMs can only create mediocre code, because mediocre code is most likely to occur in the dataset. pentesting and bug finding are not at all mediocre tasks, I am pretty sure that LLMs are going to struggle no matter how good they are compared to GPT.
there are specialized AI models for binary analysis and such, but I only hear of them through articles, no published models

yea same, I was trying out deifferent stuff, maybe automate some Google dorks with AI and kinda go from there. I was just curious if anyone had success with a tried and true method

(Mar 11, 2025, 10:11 PM)LucaLuke Wrote: try out ollama and the uncensored models. not as good quality as deepseek so far, but not as much limits also

that was really the primary inhibitor some of the standard LLMs set limits on searches
Reply
#6
dont expect much , creativity is a key part in pentesting and most aspects of security , which can not be coded , but if you manage to build a good prompt , with an AI that has higher limitation , you can get some good resutls , testing some tricks like giving it a clear path of the code often help , but expect to spend some time debugging or reasking for better results

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#7
(Mar 12, 2025, 02:45 PM)Vivid_Nap Wrote: dont expect much , creativity is a key part in pentesting and most aspects of security , which can not be coded , but if you manage to build a good prompt , with an AI that has higher limitation , you can get some good resutls , testing some tricks like giving it a clear path of the code often help , but expect to spend some time debugging or reasking for better results

I think thats what I am actually trying to figure out, is setting good prompts. or automate mundane searches in Shodan and some google dorks
Reply
#8
did you try to use pseudo-code in the promot , maybe it can help

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#9
(Mar 12, 2025, 02:53 PM)Vivid_Nap Wrote: did you try to use pseudo-code in the promot , maybe it can help

I ll give it a whirl
Reply
#10
(Mar 12, 2025, 01:19 PM)manfredmuellller444 Wrote: https://github.com/GreyDGL/PentestGPT works great for me.
Work for me, got good result
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  A collection of deepweb sites [2025] dg7ka 115 3,666 2 hours ago
Last Post: aidanclay9432148
  What is your most efficent way to gain initial access? likju 4 296 2 hours ago
Last Post: clementinemark
  CHATGPT jailbreak | cyber devils Abandoned 92 10,833 2 hours ago
Last Post: Rochet
  Largest Discord User History Archive - 10m+ Users Mega 321 41,409 10 hours ago
Last Post: clementinemark
  EvilCrowRF web custom firmware / C1101x2 + esp32 / bruteforcer/ jam / rolljam / kaiju H4rDw4Y 12 2,689 Yesterday, 03:17 PM
Last Post: fafafa666

Forum Jump:


 Users browsing this forum: 1 Guest(s)