AI Coding Assistants 1
▼
Understands basic GitHub Copilot usage for penetration testing: leveraging suggestions for exploit script development, using Copilot Chat for security tool API questions, critically evaluating completions for attack payloads and assessment scripts. Follows team guidelines on responsible use of AI for security tooling.
Independently configures GitHub Copilot for penetration testing workflows: crafts prompts for exploit development and assessment automation scripts, evaluates completions for security tool accuracy, uses Copilot Chat for vulnerability analysis assistance. Understands trade-offs between AI-assisted scripting speed and exploit code reliability.
Designs GitHub Copilot governance for penetration testing teams: implements policies for responsible AI use in exploit development, configures content exclusion for sensitive assessment repositories, evaluates AI-assisted scripting for engagement efficiency. Mentors team on balancing AI speed with exploit reliability and ethics.
Defines GitHub Copilot strategy for penetration testing teams: establishes ethical guidelines for AI-assisted exploit development, designs review policies for AI-generated security assessment code, drives responsible Copilot adoption with focus on confidentiality and compliance.
Algorithms & Data Structures 2
▼
Understands the fundamentals of Algorithms & Complexity at a basic level. Applies simple concepts in work tasks using Python/Bash. Follows recommendations from senior developers when solving problems.
Independently applies algorithmic thinking in security testing: evaluates scanning algorithm efficiency, understands graph-based attack path analysis, selects fuzzing strategies for input space coverage. Analyzes complexity trade-offs between scanning depth and execution time.
Applies algorithmic thinking to security testing: brute-force optimization algorithms for credential testing, graph traversal algorithms for network attack path discovery, fuzzing mutation algorithms for input generation. Designs efficient scanning algorithms that maximize coverage while minimizing detection risk.
Defines algorithmic standards for security testing team: scanning algorithm selection criteria, fuzzing strategy evaluation, attack path analysis algorithm reviews. Conducts reviews of algorithmic trade-offs between testing thoroughness and operational efficiency.
Understands the fundamentals of Data Structures at a basic level. Applies simple concepts in work tasks using Python/Bash. Follows recommendations from senior developers when solving problems.
Independently selects appropriate data structures for penetration testing: target enumeration lists, credential storage structures, vulnerability finding databases. Understands trade-offs between data organization for scan efficiency and result correlation.
Selects optimal data structures for penetration testing tools: graph structures for attack path modeling, hash tables for credential storage and lookup, trie structures for payload pattern matching. Optimizes data structures for efficient port scanning and service fingerprinting. Designs efficient evidence storage structures for vulnerability chain documentation.
Defines data structure standards for security testing team: target enumeration data models, exploit payload organization, evidence collection structures. Conducts reviews of scanning tool data architecture. Establishes team guidelines for efficient vulnerability data management.
API Protocols 1
▼
Understands WebSocket basics from a security perspective: WebSocket handshake vulnerabilities, cross-site WebSocket hijacking (CSWSH), and authentication token handling in WebSocket connections. Follows team methodologies for WebSocket security testing and vulnerability identification.
Conducts security testing of WebSocket implementations: tests for CSWSH vulnerabilities, injection attacks through WebSocket messages, and authorization bypass in message handling. Uses Burp Suite WebSocket extensions and custom scripts for automated WebSocket security scanning. Identifies insecure message validation and serialization patterns.
Designs comprehensive WebSocket security assessment programs: advanced exploitation techniques for WebSocket protocol weaknesses, automated fuzzing frameworks for message handling, and red team methodologies for real-time communication infrastructure. Creates WebSocket security testing tools and frameworks. Conducts threat modeling for WebSocket-based architectures. Mentors team on WebSocket security testing.
Defines API strategy at the product level. Establishes design standards. Conducts API design reviews. Coordinates cross-team API interaction.
Application Security 5
▼
Understands basic Dependency Vulnerability Scanning concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Uses dependency scanning results from Snyk, Grype, or OWASP Dependency-Check to identify attack vectors during penetration tests. Maps known CVEs in third-party libraries to practical exploit scenarios. Understands the difference between reachable and unreachable vulnerable code paths when prioritizing findings. Validates whether dependency vulnerabilities are exploitable in the application's specific deployment context.
Designs penetration testing methodologies that incorporate dependency scanning data from Snyk, Grype, and OSV to prioritize attack surfaces. Conducts threat modeling of software supply chains, identifying risks in transitive dependencies, build pipelines, and artifact registries. Integrates SCA findings with DAST and SAST results to build comprehensive exploit chains. Mentors junior pentesters on leveraging known dependency CVEs for realistic attack scenarios and proof-of-concept development.
Defines the penetration testing team's strategy for leveraging dependency scanning data in engagements. Establishes standard operating procedures for correlating SCA findings from Snyk, Grype, and OSV with exploitable attack paths. Coordinates red team exercises that simulate supply chain attacks targeting vulnerable dependencies. Trains pentest engineers on advanced SCA exploitation techniques, SBOM analysis, and supply chain threat intelligence.
Understands basic OWASP and Application Security concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Applies OWASP Testing Guide methodology for web application penetration testing. Conducts security assessments identifying OWASP Top 10 vulnerabilities with manual exploitation techniques. Uses specialized tools (Burp Suite Professional, sqlmap, custom scripts) for deep vulnerability validation and proof-of-concept development.
Designs comprehensive application security assessment methodologies beyond OWASP Top 10 — identifies business logic flaws, authentication bypass chains, and complex multi-step exploitation scenarios. Conducts threat modeling for application architectures and integrates penetration testing into SDLC pipelines. Mentors team on advanced exploitation techniques and responsible disclosure.
Defines penetration testing strategy and application security assessment programs across the organization. Establishes security testing policies, red team exercise frameworks, and vulnerability disclosure processes. Coordinates large-scale security assessments and trains teams on advanced attack simulation methodologies.
Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Uses DAST tools alongside manual penetration testing to discover runtime vulnerabilities. Validates SAST findings through exploitation to confirm real attack vectors. Integrates dynamic scanning into penetration testing workflows to maximize coverage of web application attack surfaces.
Designs advanced SAST/DAST testing strategies combining automated scanning with manual exploitation techniques. Conducts threat modeling to identify gaps in scanner coverage. Integrates SAST/DAST into CI/CD security gates with custom rule sets. Mentors team on interpreting and validating scanner results.
Defines SAST/DAST integration strategy for penetration testing across all products. Establishes scanner validation policies and custom rule development standards. Coordinates offensive security efforts combining automated scanning with manual testing. Trains pentest engineers on advanced SAST/DAST usage.
Understands basic secure coding concepts from a penetration testing perspective — recognizes injection, authentication bypass, and insecure deserialization patterns in source code. Follows security guidelines for identifying exploitable code weaknesses and understands how common vulnerabilities manifest in different programming languages.
Applies secure coding knowledge in penetration testing — reviews source code to identify exploitation vectors, maps code weaknesses to MITRE ATT&CK techniques, and develops proof-of-concept exploits from code analysis. Uses SAST tools alongside manual code review to prioritize penetration testing targets.
Designs comprehensive code security assessment methodologies — identifies complex multi-step exploitation chains from source code analysis, creates custom SAST rules for organization-specific vulnerability patterns, and integrates code review findings into penetration test strategies. Conducts architecture-level threat modeling and mentors team on advanced code-level exploitation techniques.
Defines secure coding assessment strategy for penetration testing programs across the organization. Establishes policies for code-assisted pentesting, source code review standards, and vulnerability remediation verification. Coordinates large-scale code security assessments and trains red team members on code-level exploitation methodologies.
Understands basic Threat Modeling concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Independently applies threat modeling to identify attack surfaces before penetration testing engagements. Maps MITRE ATT&CK techniques to system components. Understands trade-offs between different attack paths and prioritizes testing efforts. Creates threat-informed test plans covering network, application, and social engineering vectors.
Designs adversary simulation frameworks informed by comprehensive threat models. Maps MITRE ATT&CK kill chains to organizational assets and creates purple team exercise plans. Mentors junior testers on threat-driven penetration testing methodology. Optimizes threat model accuracy by feeding pentest findings back into organizational threat intelligence.
Defines threat-driven penetration testing strategy at team level. Establishes threat model-informed scoping and prioritization for all engagements. Coordinates red team and purple team exercises aligned with organizational threat landscape. Builds feedback loops between threat modeling outcomes, pentest findings, and security architecture decisions.
Authentication & Authorization 2
▼
Understands JWT/OAuth2 concepts from a security testing perspective: common JWT vulnerabilities (none algorithm, key confusion), OAuth2 redirect URI manipulation, and token leakage vectors. Recognizes insecure token storage and transmission patterns. Follows team guidelines for authentication security assessments.
Conducts security testing of JWT/OAuth2 implementations: exploits JWT algorithm vulnerabilities, tests OAuth2 flows for CSRF and code interception, and identifies token leakage through side channels. Uses specialized tools (jwt_tool, OWASP ZAP) for automated authentication testing. Creates proof-of-concept exploits for identified vulnerabilities.
Designs comprehensive authentication security assessments: advanced JWT attack chains (key injection, header manipulation, JWE vulnerabilities), OAuth2 flow exploitation (token theft via open redirects, PKCE downgrade), and OIDC misconfiguration exploitation. Creates automated testing frameworks for authentication infrastructure. Conducts red team exercises targeting identity systems. Mentors team on authentication penetration testing methodologies.
Defines authentication security testing strategy for the organization. Establishes penetration testing methodologies for JWT/OAuth2/OIDC systems. Creates red team playbooks for identity infrastructure assessment. Coordinates authentication security testing across product teams. Trains pentest team on advanced authentication attack techniques.
Understands basic RBAC / ABAC Authorization concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Tests RBAC and ABAC implementations for privilege escalation and authorization bypass. Conducts penetration testing of access control mechanisms across application layers. Uses specialized tools to enumerate roles, permissions, and detect misconfigurations.
Designs advanced penetration testing strategies targeting RBAC/ABAC authorization systems. Conducts threat modeling for complex multi-tenant access control architectures. Integrates authorization testing into security assessment pipelines. Mentors team on access control attack vectors.
Defines authorization penetration testing strategy across all products and platforms. Establishes security testing policies for RBAC/ABAC implementations. Coordinates red team exercises targeting access control systems. Trains pentest engineers on advanced authorization bypass techniques.
Concurrency & Parallelism 2
▼
Understands the fundamentals of Async Programming at a basic level. Applies simple concepts in work tasks using Python/Bash. Follows recommendations from senior developers when solving problems.
Independently applies async programming in security tools: concurrent port scanning, async exploit delivery, non-blocking vulnerability assessment operations. Understands trade-offs between parallel and sequential scanning strategies for efficiency.
Designs async architectures for security tools: massively concurrent scanning, async exploit chain execution, non-blocking result aggregation and analysis. Mentors team on async patterns for efficient security assessment at scale.
Defines async programming standards for security testing team: concurrent scanning architecture guidelines, async exploit execution reviews, non-blocking assessment patterns. Establishes best practices for async patterns in security testing tools.
Understands the fundamentals of Multithreading at a basic level. Applies simple concepts in work tasks using Python/Bash. Follows recommendations from senior developers when solving problems.
Independently applies multithreading for penetration testing: concurrent port scanning and service enumeration, parallel brute-force and fuzzing techniques, thread-safe results aggregation from multiple attack vectors. Explains concurrency trade-offs for assessment speed vs detection avoidance.
Has deep expertise in multithreading for security testing: designs high-performance concurrent scanning architectures, implements thread-safe exploit chaining and results aggregation, optimizes parallel assessment techniques for large-scale engagements. Mentors team on concurrent programming for offensive security tools.
Defines multithreading standards for penetration testing teams: establishes guidelines for concurrent scanning and assessment tool architectures, conducts reviews of parallel exploit execution designs, creates training materials on thread-safe offensive security tool development.
DNS & Networking 1
▼
Understands basic VPN and Network Isolation concepts. Uses ready-made configurations. Performs simple operations under senior guidance.
Independently assesses VPN and network isolation implementations: tests IPSec/WireGuard configurations for cryptographic weaknesses, evaluates segmentation bypass vectors, and validates firewall rule effectiveness. Uses network analysis tools (Wireshark, nmap, Burp) to identify misconfigurations in tunnel and isolation setups.
Designs advanced VPN and network isolation penetration testing methodologies: crafts custom tunneling exploits, evaluates split-tunneling attack surfaces, and tests network isolation boundaries across multi-cloud environments. Implements automated security validation for VPN configurations and recommends hardening strategies.
Defines infrastructure strategy with VPN and Network Isolation. Establishes IaC standards. Conducts architecture reviews. Optimizes FinOps.
Git & Workflows 1
▼
Understands basic Git advanced features for penetration testing: branching for engagement-specific tool configurations, stash for switching between target environments, .gitignore for excluding sensitive findings and credentials. Follows team conventions for versioning exploit scripts and assessment tooling.
Independently uses Git advanced features for penetration testing: manages engagement-specific branches with proper isolation of findings, resolves conflicts in shared tool configurations, implements hooks for credential leak prevention. Understands trade-offs between private forks and branch-based isolation for sensitive assessment data.
Designs Git workflows for penetration testing teams: implements repository isolation strategies for sensitive assessment data, configures automated secret detection across all repositories, designs branch-based access control for engagement confidentiality. Mentors team on forensic-grade Git history management and secure artifact handling.
Defines Git strategy for penetration testing teams: establishes standards for secure repository management of assessment data, designs access control and audit policies for engagement repositories, drives adoption of automated secret scanning across all team repositories.
GraphQL 1
▼
Understands basics of GraphQL from a penetration testing perspective — introspection enumeration, query injection, and authorization bypass vectors. Performs basic reconnaissance of GraphQL endpoints. Follows team methodologies for initial GraphQL security assessment.
Independently conducts security assessments of GraphQL APIs — exploits batching attacks, field suggestion enumeration, and nested query DoS vectors. Develops custom GraphQL fuzzing tools and introspection analysis scripts. Documents findings with proof-of-concept exploits and remediation guidance.
Designs comprehensive GraphQL security assessment methodologies for production APIs. Architects advanced attack scenarios including authorization bypass through nested resolvers, information disclosure via error messages, and resource exhaustion through query complexity manipulation. Defines remediation standards and security review processes for GraphQL schema changes.
Defines GraphQL security assessment strategy across the product portfolio. Establishes standards for GraphQL threat modeling, introspection policy enforcement, and query depth governance. Conducts cross-team API security reviews and coordinates GraphQL vulnerability disclosure processes.
Incident Response 3
▼
Understands basic Digital Forensics concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Uses digital forensics fundamentals to document exploitation evidence during penetration tests. Captures system artifacts, file hashes, and timeline data to support findings. Analyzes disk images and memory snapshots to identify indicators of compromise and validate attack paths.
Designs forensic-aware penetration testing methodologies that produce court-admissible evidence when needed. Conducts advanced memory forensics and malware analysis to reverse-engineer attack techniques. Mentors team on anti-forensic awareness and evidence preservation during red team engagements.
Defines forensic capabilities within the offensive security practice. Establishes standards for evidence collection, preservation, and reporting during penetration tests and red team exercises. Coordinates with legal and compliance teams on forensic requirements and trains offensive security staff on forensic techniques.
Understands basic Incident Response Process concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Supports incident response by providing offensive security expertise during active incidents. Validates attack vectors and helps determine scope of compromise. Documents exploitation paths for post-incident analysis and contributes to lessons-learned reviews with remediation recommendations.
Leads purple team exercises to validate and improve incident response capabilities. Designs attack simulations that test detection and response workflows end-to-end. Integrates offensive findings into incident response playbooks and mentors the team on attacker TTPs relevant to detection engineering.
Defines offensive security's role in the incident response process across the organization. Establishes red team/purple team exercise programs that systematically test incident response maturity. Coordinates with SOC leadership on improving detection coverage based on real-world attack simulation results.
Understands basic Vulnerability Management concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Discovers and validates vulnerabilities through penetration testing and exploitation. Assesses vulnerability severity using CVSS scoring and real-world exploitability analysis. Uses vulnerability management platforms to track findings and verify remediation effectiveness across tested systems.
Designs vulnerability assessment methodologies combining automated scanning with manual exploitation. Conducts threat modeling to prioritize vulnerability discovery in high-risk areas. Integrates penetration testing results into vulnerability management workflows. Mentors team on vulnerability validation techniques.
Defines vulnerability discovery strategy integrating penetration testing with continuous scanning programs. Establishes severity classification policies and validation standards for reported vulnerabilities. Coordinates red team assessments feeding into vulnerability management processes. Trains pentest engineers on systematic vulnerability analysis.
Infrastructure Security 3
▼
Understands basic Cloud Infrastructure Security concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Performs cloud penetration testing across AWS, Azure, and GCP environments. Conducts security reviews targeting IAM misconfigurations and exposed services. Uses cloud-specific exploitation tools and techniques to identify privilege escalation paths and data exfiltration vectors.
Designs cloud penetration testing methodologies for complex multi-account AWS/Azure/GCP environments. Conducts threat modeling of cloud architectures to identify attack surfaces. Integrates offensive security findings into SDLC processes and mentors junior pentesters on cloud exploitation techniques.
Defines offensive cloud security strategy across AWS, Azure, and GCP attack surfaces. Establishes penetration testing policies and red team engagement rules for cloud infrastructure. Coordinates response to critical cloud vulnerabilities discovered during assessments and trains teams on cloud exploitation frameworks.
Understands basic Kubernetes Security concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Performs security assessments of Kubernetes clusters identifying misconfigurations in RBAC, network policies, and pod security. Uses tools like kube-hunter and kubeaudit to discover vulnerabilities. Tests container escape scenarios and lateral movement paths within cluster environments.
Designs advanced Kubernetes penetration testing methodologies covering control plane attacks, etcd exploitation, and service mesh bypass techniques. Develops custom tools for Kubernetes attack simulation and validates cluster hardening against MITRE ATT&CK for Containers. Mentors team on cloud-native offensive security.
Defines Kubernetes offensive security testing programs covering multi-cluster and multi-cloud environments. Establishes red team playbooks for container orchestration attacks aligned with current threat intelligence. Coordinates with platform teams on remediation priorities and drives continuous improvement of cluster security posture.
Understands basic network security concepts: TCP/IP model, common ports and protocols, firewall rule logic. Can run Nmap scans, read packet captures in Wireshark, and identify open services on a target host under supervision.
Independently performs network penetration testing: conducts host discovery, service enumeration, and vulnerability scanning across subnets. Exploits misconfigured firewalls, weak VPN setups, and unpatched network services. Writes clear findings on network segmentation gaps and proposes remediation for IDS/IPS evasion techniques discovered during engagements.
Designs complex network penetration testing methodologies: multi-stage attack chains exploiting network trust relationships, pivoting through segmented networks, and advanced IDS/IPS evasion. Mentors junior pentesters on network protocol analysis and firewall bypass techniques. Evaluates zero-trust network architectures and identifies gaps in micro-segmentation implementations.
Leads the team's network penetration testing practice: defines engagement scoping for network assessments, standardizes network attack toolchains and reporting templates, and prioritizes remediation across firewall, VPN, and segmentation findings. Builds team capabilities in advanced network exploitation and coordinates purple-team exercises focused on network defense validation.
Logging 2
▼
Understands the fundamentals of ELK Stack for penetration testing workflows. Uses Kibana to review scan results and vulnerability logs. Writes basic Elasticsearch queries to correlate findings across target systems. Follows established index patterns and dashboard templates.
Configures ELK Stack for centralized penetration testing reporting. Builds Logstash pipelines to ingest Nmap, Burp Suite, and Metasploit output. Creates Kibana dashboards to track vulnerability severity distribution and remediation status. Writes Elasticsearch aggregation queries to correlate findings across engagements.
Designs end-to-end observability architecture for offensive security operations using ELK Stack. Implements custom Elasticsearch ingest pipelines with enrichment processors for automated vulnerability scoring and asset correlation. Builds advanced Kibana Lens dashboards for executive-level penetration testing reports. Defines index lifecycle management policies for compliance-sensitive engagement data. Mentors team on writing efficient Elasticsearch DSL queries and Logstash grok patterns.
Defines the offensive security team's observability strategy using ELK Stack. Establishes SLO-based approach for vulnerability management metrics: detection-to-report time, retest coverage, and finding recurrence rates. Coordinates incident management workflows between red team and blue team through shared Kibana dashboards and Elasticsearch alerting. Drives adoption of OpenSearch for cost-effective long-term storage of engagement data. Optimizes MTTD/MTTR by integrating ELK with ticketing and notification systems.
Understands basic structured logging for penetration testing: reading target application logs during assessments, understanding logging gaps as attack vectors, basic log analysis for detecting exploitation evidence. Follows team conventions for documenting logging-related findings.
Configures structured logging analysis for penetration testing: implements log monitoring during active assessments, creates dashboards for tracking exploitation detection by defenders, sets up log analysis for identifying blind spots in target monitoring. Analyzes logging coverage gaps as part of assessment findings.
Designs observability assessment methodology for penetration testing: evaluates target logging and monitoring coverage during engagements, identifies detection blind spots through controlled exploitation, defines SLI/SLO recommendations for target organization. Mentors team on adversarial log analysis and detection evasion techniques documentation.
Defines observability assessment strategy for penetration testing practice: establishes SLO-based approach for security monitoring evaluation, coordinates incident response validation during assessment engagements, optimizes MTTD/MTTR measurement methodology for client organizations.
OOP & Design Patterns 1
▼
Understands the fundamentals of OOP & SOLID Principles at a basic level. Applies simple concepts in work tasks using Python/Bash. Follows recommendations from senior developers when solving problems.
Independently applies OOP/SOLID in penetration testing tools: proper abstraction for exploit modules, interface-based scanner plugins, single responsibility in payload generation and delivery components. Understands trade-offs between OOP patterns for extensible security frameworks and rapid exploit development.
Applies OOP/SOLID in security tool architecture: abstract scanner interfaces for pluggable vulnerability checks, strategy pattern for exploit technique selection, template method for assessment workflow standardization. Designs modular penetration testing frameworks with clean separation between reconnaissance, exploitation, and reporting.
Defines OOP/SOLID standards for security testing team: exploit module architecture guidelines, scanner plugin interface contracts, payload framework class design. Conducts reviews of OOP decisions balancing tool extensibility with exploit development speed.
REST API 1
▼
Understands basic REST API concepts for security testing: API endpoint enumeration, authentication bypass patterns, common API vulnerabilities (BOLA, broken auth). Follows team conventions for API penetration testing methodology.
Independently tests REST API security: automated API fuzzing, authentication and authorization bypass testing, business logic vulnerability analysis. Understands best practices for API attack surface mapping, parameter tampering, and injection testing in RESTful services.
Designs API security testing strategies: comprehensive API attack surface assessment, automated API security scanning integration, business logic vulnerability analysis frameworks. Defines API security testing standards and breach simulation methodologies. Mentors team on advanced API exploitation.
Defines API security testing strategy at product level: API penetration testing standards, automated API security scanning governance, API vulnerability assessment frameworks. Conducts API security architecture reviews and establishes API security testing processes.
Technical Documentation 1
▼
Understands the structure of penetration testing runbooks and engagement playbooks. Follows established runbooks for reconnaissance, scanning, and basic exploitation phases. Documents findings according to standard reporting templates.
Independently writes penetration testing runbooks for various engagement types: web application, network infrastructure, API testing. Creates playbooks with decision trees for exploitation paths and documents remediation guidance for common vulnerability patterns.
Designs advanced penetration testing runbook frameworks: red team operation playbooks, social engineering campaign procedures, Active Directory attack chains documentation. Mentors junior testers on creating reusable engagement runbooks with proper evidence collection and chain-of-custody procedures.
Defines runbook strategy for the penetration testing practice: standardizes engagement methodology playbooks, establishes quality gates for runbook completeness, drives integration of runbooks with vulnerability management platforms and reporting automation.