Hacking Articles
20.8K subscribers
1.12K photos
165 files
771 links
House of Pentester
Download Telegram
πŸš€ AI Penetration Testing Training (Live Online Program)

The future of cybersecurity is AI-driven β€” and this program is built to help you test, break, and secure AI systems & LLMs in real-world scenarios.

Ignite Technologies presents an intensive AI Pentesting & LLM Security Training for pentesters, red teamers, and security researchers.

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

⚠️ Limited seats available

🧠 What You’ll Learn
LLM architecture & security fundamentals
OWASP Top 10 for LLMs
Secure deployment & model context protocols (MCP)
RAG (Retrieval-Augmented Generation) security
AI infrastructure & data security

πŸ”₯ Offensive AI Security
Prompt injection & indirect injection attacks
LLM API exploitation scenarios
Sensitive data leakage via AI
Misconfigurations & privilege abuse in LLMs
Data extraction & output manipulation techniques

πŸ›‘ Defensive Focus
Securing AI applications & system prompts
AI-based automated pentesting
Building production-ready secure AI systems

πŸ’‘ Ideal for professionals in pentesting, red teaming, bug bounty, and OSCP preparation who want a strong edge in AI security.
❀2πŸ‘2
⏱️ Nmap for Pentester: Timing Scan

πŸ”₯ Telegram: https://t.me/hackinarticles

Nmap provides timing templates (-T0 to -T5) that control how fast packets are sent during scanning. Adjusting these templates helps pentesters balance speed, accuracy, and stealth while performing network reconnaissance.

⚑️ Timing scans covered:

🐒 Paranoid Scan (-T0)
πŸ•΅οΈ Sneaky Scan (-T1)
πŸ™ Polite Scan (-T2)
βš™οΈ Normal Scan (-T3)
πŸš€ Aggressive Scan (-T4)
πŸ”₯ Insane Scan (-T5)

🎯 Understanding timing templates helps security professionals optimize scans and bypass certain firewall rate-limiting rules.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-timing-scan/
πŸšͺ Nmap for Pentester: Port Status

πŸ”₯ Telegram: https://t.me/hackinarticles

When performing port scanning with Nmap, the results don’t only show open or closed ports. Instead, Nmap classifies ports into different states based on the responses received from the target system or firewall.

⚑️ Port states covered:

🟒 Open
πŸ”΄ Closed
πŸ›‘ Filtered
πŸ“‘ Unfiltered
❓ Open | Filtered
⚠️ Closed | Filtered

🎯 Understanding these states helps pentesters interpret scan results correctly and identify potential attack surfaces during reconnaissance.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-port-status/
πŸ”₯2
πŸ“‘ Nmap for Pentester: Host Discovery

πŸ”₯ Telegram: https://t.me/hackinarticles

Host Discovery is the first step in network reconnaissance. It helps pentesters identify which systems are alive in a network before performing deeper scans like port scanning or service enumeration.

⚑️ Techniques covered:

πŸ“‘ Ping Sweep (-sn)
🀝 TCP SYN Ping (-PS)
πŸ“© TCP ACK Ping (-PA)
πŸ“¨ ICMP Echo Ping (-PE)
πŸ“¦ UDP Ping (-PU)
🌐 IP Protocol Ping (-PO)
πŸ–§ ARP Ping (-PR)
🚫 No Ping Scan (-Pn)

🎯 These techniques help pentesters identify live hosts, bypass firewall restrictions, and improve target discovery during information gathering.

πŸ“– Read the full guide:
https://www.hackingarticles.in/nmap-for-pentester-host-discovery/
❀4
πŸ”΅ Blue Teaming Active Directory: EvenMonitor

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Attackers target AD… defenders must monitor EVERYTHING ⚠️

⚑️ Defense Highlights
πŸ” Monitor AD events & suspicious logins
πŸ“Š Track user/group/permission changes
🚨 Detect privilege escalation & lateral movement
🧠 Identify abnormal behavior patterns
πŸ›‘ Improve visibility across domain

πŸ’‘ Active Directory monitoring = continuous tracking of accounts, permissions & activities to detect threats early

⚠️ Without proper monitoring β†’ attacks stay invisible until domain compromise

πŸ“– Article: https://www.hackingarticles.in/blue-teaming-active-directory-evenmonitor/
❀2
Active Directory Pentesting with BloodyAD 🩸

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
πŸ”Ž Understanding AD ACL & DACL Abuse
🧠 BloodHound Path Analysis
πŸ” Authentication (Password / Hash / Kerberos)
πŸ‘₯ Add User to Privileged Groups
πŸ”‘ Reset Password & Takeover Accounts
⚑️ GenericAll / GenericWrite Abuse
πŸ›  WriteDACL & WriteOwner Exploitation
πŸ“‘ Resource-Based Constrained Delegation (RBCD)
🐚 Shadow Credentials Attack
🎯 Privilege Escalation to Domain Admin

πŸ“– Article:
https://www.hackingarticles.in/active-directory-penetration-testing-with-bloodyad/
❀2