Skip to main content
Articles

Working notes on testing without a tester

What a scanner structurally cannot see, why a quality gate runs after the report rather than before it, and what autonomous persistence has to be bounded by before anybody should accept it. Grouped by what you are trying to work out, because they all went up together.

01

What we test

  • What decompiling an APK or IPA actually finds

    Traffic shows what a mobile application chose to do while somebody was watching it. The package shows what it was built to do — and what it reveals turns out to be a question about the server, not the handset.

    Yash K ·

  • Why a scanner finds nothing in a thick client

    A web scanner needs an address, a link to follow and a request it can read. A desktop application supplies none of the three, which is why the report comes back empty — and why that empty report is a fact about the tool rather than about the application.

    Yash K ·

02

How it is done

  • Testing the inventory discovery found

    A perimeter worked out from announced ranges, resolving names and what answers will surface hosts the asset register does not have. Testing what discovery found, rather than the list you were handed, is the difference between assessing what you remember and assessing what you run.

    Yash K ·

  • Why the QA gate comes after the report is written

    PTES sets out seven phases and NIST SP 800-115 four, and both close their account at reporting. B-52 has a sixth phase after it — a quality gate that runs on the finished report and can send a finding back to the phase that produced it.

    Yash K ·

03

Autonomy and its limits

  • AI pentest: one term, two opposite jobs

    The same four words describe a platform that runs the test and an engagement whose target is a model. This article names both, says which is which, and points each one at the page that answers it.

    Yash K ·

  • Automated red teaming: persistence under authorisation

    Persistence means holding a foothold across time. When a platform does that without an operator, one question decides whether it is acceptable — under whose authority, and bounded by what.

    Yash K ·

04

In the pipeline

05

Regulation

  • Four cadences CSCRF keeps separate

    CSCRF sets VAPT, cyber audit, red teaming and threat hunting as four separate obligations, written in three different places and carrying four different periodicities between them. This names each one and cites the table it is written in.

    Yash K ·

Reading about it is slower than running one

One application or one target, $500, with every finding carrying a request, a response and the steps to reproduce it.