The Penetration Testing Lab is dedicated to evaluating and developing a wide range of hacking tools that play a crucial role in the penetration testing process for security audits. Through the utilization of data collected from the HoneyNet project, we gain valuable insights into the capabilities of attackers when it comes to exploiting system vulnerabilities. Furthermore, our project focuses on the evaluation of methodologies and tools aimed at enhancing IT infrastructure security capabilities within the broader IT industry. This includes the effective deployment of Network Monitoring, Firewalls, Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS).
We work towards refining and expanding our arsenal of hacking tools, ensuring they are equipped to address the ever-evolving landscape of cybersecurity threats. By continuously evaluating and enhancing these tools, we strive to provide cutting-edge solutions that empower organizations to safeguard their digital assets effectively.
Moreover, our research efforts are not limited to tool development alone. We actively seek to advance the field of IT infrastructure security by exploring new methodologies and techniques. Through rigorous testing and analysis, we aim to identify vulnerabilities and devise proactive measures to mitigate potential risks.
we strive to establish best practices for the deployment and configuration of essential security components. Network Monitoring enables real-time threat detection and response, ensuring the early identification of any suspicious activities. Firewalls act as a barrier, preventing unauthorized access and protecting sensitive data. Intrusion Detection Systems (IDS) continuously monitor network traffic, identifying potential threats and alerting security teams for prompt intervention. Intrusion Prevention Systems (IPS) go a step further by actively blocking and mitigating attacks, providing an additional layer of defense.
- In addition to the AI-driven malware network traffic analysis program (
pcap_ai.py) and the AI-Powered Penetration Testing program (nmap_ai.py) previously released, I have also provided alternative versions (pcap_ai_or.pyandnmap_ai_or.py) that utilize free Large Language Models (LLMs) from Openrouter. This allows you to continue using these tools even if you no longer have Ollama support. You can find a demonstration of their operation on my YouTube video at (https://youtu.be/x8QnnHYeG08)
-
AI significantly enhances the analysis of malware network traffic to defend networks by leveraging advanced pattern recognition and predictive modeling. AI-driven tools, such as those using large language models or machine learning algorithms, can process vast amounts of network data, like PCAP files, to identify malicious activities, including command-and-control communications, data exfiltration, or distributed denial-of-service attacks. By analyzing packet metadata, payloads, and behavioral patterns, AI can detect anomalies, classify attack vectors, and attribute malicious traffic to specific sources, even in encrypted or obfuscated streams. Furthermore, AI can correlate real-time threat intelligence from external sources, such as web searches, to provide context-aware insights and recommend tailored countermeasures, such as Suricata rules or firewall policies. This proactive approach enables rapid detection, mitigation, and prevention of malware-related threats, strengthening network defenses against evolving cyber attacks.
-
The
pcap_ai.pyprogram directly supports the AI-driven analysis of malware network traffic for network defense, as described in the provided paragraph, by leveraging the capabilities of LLM to process and analyzetcpdump -neAroutput from PCAP files. The program captures detailed packet data, including source/destination IPs, MAC addresses, protocols, and ASCII payloads, which it parses into a structured format and feeds to the LLM. The LLM, acting as a cybersecurity expert, identifies potential malicious activities such as command-and-control communications, data exfiltration, or DDoS attacks by analyzing patterns and anomalies in the traffic. For instance, it can detect unusual packet sequences or payloads indicative of malware. The program’s optional DuckDuckGo web search integration enriches the analysis by correlating packet data with recent threat intelligence, such as known vulnerabilities or attack signatures for specific protocols (e.g., TCP or HTTP). It provides a detailed output, including attack vectors, attacker/victim IDs (IP and MAC addresses), timelines based on packet timestamps, and specific countermeasures like Suricata rules to detect and block malicious traffic. By automating this process and saving results to timestamped files (e.g.,mitm_analysis_gemma3_27b_20250616_193755.md), it enables rapid, context-aware threat detection and mitigation, strengthening network defenses against malware-driven cyber attacks. -
You can review some PCAP file analysis outputs at pcap_ai. The original PCAP files that were analyzed are also available at pcap
Below video shows how to use pcap_ai.py program to analyze malware network traffic:
-
Artificial Intelligence significantly enhances penetration testing by automating and enriching the analysis of security scans, as demonstrated by the
nmap_ai.pyprogram shown in the youtube video below. This tool integrates Nmap scans with a Large Language Model (LLM), such asgemma3:27b, to analyze a comprehensive scan revealing open ports and services likevsftpd 2.3.4on port 21,OpenSSH 4.7p1on port 22, andApache httpd 2.2.8on port 80. The LLM processes these results, identifies vulnerabilities (e.g., outdated software prone to exploits), and provides prioritized recommendations, such as disabling Telnet, hardening SSH, and running follow-up scans likenmap --script vuln. By offering the option to incorporate real-time DuckDuckGo web searches, the AI can augment its analysis with up-to-date vulnerability data, delivering a more thorough assessment than manual methods. This automation saves time, improves accuracy, and empowers pentesters to focus on strategic tasks, making AI an invaluable ally in cybersecurity. You can download this nmap_ai.py from https://github.com/alanshlam/Pentest/tree/main/nmap_aiBelow video shows how to use nmap_ai.py program:
-
A botnet is a network of compromised devices, or "bots," controlled by a malicious actor through a command-and-control (C2) server, which issues instructions to coordinate activities like data theft, DDoS attacks, or malware distribution. The C2 server communicates with bots using protocols like HTTP, HTTPS, or custom TCP, often employing dynamic ports to evade detection. A botnet operates through a hierarchical structure where a central Command and Control (C2) server orchestrates a network of compromised devices, known as bots or clients. Initially, devices become infected with malware, often through phishing, exploited vulnerabilities, or drive-by downloads, turning them into bots. Once infected, these bots secretly establish a persistent connection or periodically check in with the C2 server. The botnet operator then uses the C2 server to send commands to all or a subset of the connected bots, instructing them to perform malicious activities such as launching Distributed Denial of Service (DDoS) attacks, sending spam, mining cryptocurrency, or stealing sensitive data, all while remaining largely undetected by their owners.
-
Below video demonstrate how a C2 server communicates with its bots with dynamic port binding and encrypted traffic. It also suggests some Suricata rules to detect the botnet traffic in the demo video. You can down load these Suricata rules at https://github.com/alanshlam/Pentest/blob/main/ips/c2.rules
-
Local File Inclusion (LFI), Unrestricted File Upload (UFV), and Remote Code Execution (RCE) are critical web application vulnerabilities that pose significant risks to system security. LFI allows attackers to include and access sensitive server files, such as
/etc/passwd, by manipulating file inclusion parameters, potentially exposing system data or enabling code execution through techniques like log poisoning. UFV permits attackers to upload malicious files, such as PHP web shells (e.g.,c99shell.php), which can be executed on the server to gain unauthorized control or execute arbitrary commands. RCE, often a consequence of LFI or UFV, enables attackers to run arbitrary code, leading to full system compromise. When patching vulnerable source code is not immediately feasible, an Intrusion Prevention System (IPS) like Suricata can mitigate these risks by detecting and blocking malicious traffic. Suricata rules, such as those targeting LFI attempts to access sensitive files, UFV uploads of PHP scripts , or RCE command execution patterns , inspect HTTP requests and payloads in real-time, dropping malicious packets before they reach the application. By leveraging thresholds, content matching, and flow analysis, Suricata provides a robust defense layer, reducing the attack surface until code vulnerabilities can be addressed.Below video demonstrates the vulnerabilities of LFI, UFV, and RCE on a website, with a focus on exploiting UFV to achieve RCE. It also illustrates how an attacker can exploit a setuid program to gain root shell access. Additionally, the video showcases how an Intrusion Prevention System (IPS) can detect and block these attacks in real time.
)
(https://youtu.be/vLrOcdlmLJ8)
-
ftrace is a kernel tracing framework in Linuidx, mainly used for debugging and performance profiling. It allows developers to trace function calls and measure performance by recording when kernel functions are entered and exited. However, a ftrace-based LKM rootkit is a malicious kernel module that uses the ftrace infrastructure to hook kernel functions (such as sys_open, sys_read, sys_getdents, etc.) without modifying the syscall table or function pointers directly. Many traditional rootkit detection tools focus on checking syscall tables or suspicious memory changes. Using ftrace lets attackers evade common detection techniques. Below video demonstrate how the ftrace-based LKM rootkit
- privilege escalation using kill 000 command
- hides files and directories with certain prefix
- port knocking bind (you can download its pcap file here)
- port knocking reverse shell (you can download its pcap file here)
- hides bind shell listening port from lsof
- hides bind shell and reverse shell port from netstat
- hides bind shell and reverse shell process from ps or top
- hides module from lsmod
This video also demonstrates how a backdoored version of openssh client logs ssh username and ssh password into a file.
-
The video below demonstrates how to use Nmap as a port scanner and vulnerability scanner to provide a low-cost solution during the reconnaissance process in a security audit. This video also demonstrates how to effectively use Metasploit in Kali Linux for penetration testing and verifying vulnerabilities discovered in the reconnaissance process.

(https://www.youtube.com/watch?v=tkWUkARUzaQ)You can download the network packet pcap file of the SMB break in at (https://github.com/alanshlam/HoneyNet/blob/main/pcap/smb.pcap)
-
The video below demonstrates how an attacker can intercept HTTPS traffic and snoop on victim password information using a MITM attack via ARP poisoning. Normally, HTTPS network packets are encrypted by a session key between the client and web server. An attacker cannot decrypt the HTTPS traffic without the session key. However, if the attacker can redirect the victim's HTTPS traffic to their managed host (e.g., by DNS hijack or ARP poisoning in a LAN), they can supply their own session key to the victim host, decrypt the HTTPS traffic, and relay the HTTPS traffic between the victim host and the genuine web server. The demostration in this video shows that it is possible to sniff user passwords even in HTTPS traffic, which is encrypted by session key.
(https://youtu.be/xQz0G5JWjuw)You can download the network packet pcap file of this MITH attack in at (https://github.com/alanshlam/HoneyNet/blob/main/pcap/mitm.pcap)
-
The video below demonstrates how to dump a website database information, including user password hashes, using Time-based Blind SQL Injection. This type of injection relies on the database pausing for a specified amount of time before returning results, indicating successful query execution. The attacker enumerates each letter of the desired data using logic that causes the database to wait if a condition is met. You can get the source code of this Time-based Blind SQL Injection used in this demonstration from here.
-
The video below demonstrates how to deploy an IPS to block network attacks, such as Nmap scans or SQL injection attacks, using Suricata. This IPS helps a network prevent cyberattacks even if there are vulnerable systems behind the firewall.
You can download the demo materials from https://github.com/alanshlam/Pentest/tree/main/ips
-
The screenshots below demonstrate how to effectively monitor IT infrastructure using ntop-ng, Nagios,nfsen, InflunxD, and MRTG. These system and network monitoring tools help system administrators closely monitor their IT infrastructure and discover any suspicious network activities or potential attacks.
-
The nagios monitors the critical service in the IT infrastructure and send alerts when detected

-
Suricata IDS monitors potential threats in network uplink traffic
This sample suricata rule outbound_ssh_scan.rules detect outbound SSH scan from internal $HOME_NETThis sample program send_alert_sample.py monitors SID 1000001 in the fast.log and runs in daemon mode. When an alert with SID 1000001 is detected, this program will send an alert mail with scan data in CSV formation. This program also takes care of continuing to monitor the fast.log after log rotation.
- AI Integration: Augment the security audit process in its initial stages by seamlessly integrating AI technologies. This integration will streamline and automate various tasks, including information gathering during the reconnaissance process, allowing for faster and more accurate identification of potential vulnerabilities.
- Knowledge Base Development: Foster the development of a comprehensive knowledge base for this project by harnessing the power of large language models (LLMs). Collaborate on the LLM knowledge base project to capture and consolidate essential know-how, ensuring a centralized repository of up-to-date information. This collaborative effort will facilitate knowledge sharing and foster continuous improvement.
- Capacity Enhancement: Bolster the capabilities of the Penetration Testing Lab to proactively research and explore advanced hacking techniques. Stay abreast of the latest CVEs (Common Vulnerabilities and Exposures) releases to identify potential vulnerabilities and develop effective countermeasures. By continuously enhancing the lab's capacity, we can stay ahead of emerging threats and provide robust protection for our systems.
- Countermeasure Evaluation: Conduct thorough assessments to evaluate the effectiveness of countermeasures employed, such as Firewalls, IDS (Intrusion Detection Systems), and IPS (Intrusion Prevention Systems), against the most recent hacking techniques. By rigorously testing and analyzing the efficacy of these countermeasures, we can identify potential gaps and devise strategies to fortify our defenses. This evaluation process will ensure that our systems are resilient and capable of withstanding sophisticated attacks.
By focusing on these areas of future work, we aim to optimize the security posture of our organization, reduce the risk of cyber threats, and maintain a proactive approach to cybersecurity.











