CyberDefenders is an independently funded nonprofit project.. Donate
LLM assisted penetration testing and vulnerability research
2026 Summer Cohort — Capstone Project

Prompt to Pentest: LLM-Assisted Security Testing Lab

Sponsored by Lib13 Inc

Status

This capstone is still in progress. Final deliverables and presentation are due shortly to complete the credential.

Project Brief

LLM-Assisted Vulnerability Discovery

This track uses LLMs to help find common vulnerabilities, interpret security tool output, and develop AI-assisted pentesting utilities in authorized lab environments. The goal is not autonomous hacking, but understanding how LLMs can support a responsible human tester: planning reconnaissance, explaining findings, identifying false positives, generating repeatable validation steps, and turning raw scanner output into useful remediation guidance — all with documented safety boundaries.

Capstone Team

  • Aung K Min — Skyline College · In Progress (final deliverables due shortly)

Project Workstreams

Authorized Scanning Workflow

Run approved tests against intentionally vulnerable apps and lab services. Use LLMs to summarize scanner output (Nmap, Nikto, OWASP ZAP, nuclei, Semgrep), then manually verify findings.

AI Pentesting Utilities

Build small tools that help move from raw output to evidence — recon checklists, finding triage, safe proof-of-concept generation, and report drafting.

Safety Harness

Define boundaries before testing begins — authorized scope, rate limits, non-destructive testing, secret handling, and escalation rules when a finding appears real.

Track Scope: Expected Deliverables

  • Testing plan: authorized scope, target inventory, safety rules, and workflow for LLM-assisted testing.
  • Tool prototype: a small AI-assisted pentesting utility for triage, validation, reporting, or remediation mapping.
  • Finding reports: verified lab findings with evidence, impact, reproduction steps, and remediation guidance.
  • Evaluation notes comparing LLM-assisted workflows — where models helped, failed, or required human review.
  • A practical safety guide for using LLMs in pentesting without crossing authorization or privacy boundaries.

Skills Being Demonstrated

Penetration Testing LLM-Assisted Security Testing Vulnerability Discovery Tool Development Responsible Disclosure