Tagged: Sn1per
9 posts · browse all tags
-
Sn1per Deep Dive Part 8: The Windows Target and What Nuke Mode Never Touched
Building a genuine Windows target for the Sn1per lab and running the tool against it for real, including the one finding it never even scanned for.
-
Sn1per Deep Dive Part 9: What a Pen Tester Without Sn1per Would Have Found
The same Windows target, worked by hand with nmap, curl, and two modern credential tools, set against what Sn1per's own automated run actually delivered. Closing post for the Sn1per Deep Dive series.
-
Sn1per Deep Dive Part 7: Verified With Root
Six posts read Sn1per from source without ever running it live. This one reruns the tool for real, with root, against a rebuilt lab, and checks every prediction against what actually happened.
-
Sn1per Deep Dive Part 1: From Recon Script to Attack Surface Platform
Sn1per orchestrates 90+ tools into one scan. This opens a new series on how it actually works, verified from the real Community Edition source rather than the marketing page.
-
Sn1per Deep Dive Part 2: What Discover and Recon Mode Actually Run
Sn1per's discover and recon modes chain together nmap, Amass, Subfinder, Sublist3r, crt.sh, and Shodan into one deduplicated target list. Read directly from the Community Edition source, with a real correction from root-verified testing.
-
Sn1per Deep Dive Part 3: Web Mode, Sc0pe, and the Vulnerability Scoring Engine
Sn1per's sc0pe engine is a directory of tiny declarative bash templates, each matching one header or one string, rolled up into a single per-host risk score. Read from the real source, with two real bugs confirmed by later root-verified testing.
-
Sn1per Deep Dive Part 4: Workspaces, Reporting, and the Professional 2026 Architecture
What Sn1per Professional 2026 adds over the free Community Edition, documented from the vendor's own release notes since the Pro engine isn't in the public source tree.
-
Sn1per Deep Dive Part 5: What an Automated Sweep Looks Like From the Blue Team's Side
Sn1per's default scan modes fire real, unconditional exploit attempts against old CVEs the instant a banner matches. That's expensive for an attacker to hide and cheap for a defender to detect, and root-verified testing found a genuine defensive win too.
-
Sn1per Deep Dive Part 6: A Full Sweep Against Northbridge Freight
Applying Sn1per's real recon-to-exploit logic, mode by mode, against a small local lab, then handing off to Impacket and Pivoting and Tunneling for the part the automation can't do.