September 28, 2026
I built a Penetration testing system in Python over three months, and this is the result.

By Imran Niaz
3 min read
The core features of the system include CVE, OCENT subdomain enumeration, directory and file discovery, active domain filtering,
The core features of the system include CVE, OCENT subdomain enumeration, directory and file discovery, active domain filtering, detection of accessible hosting IPs, and basic firewall bypass techniques using IP addresses.
There are also modules for automated recon, data collection, and streamlined reporting to help penetration testers efficiently cover all the necessary steps.
friendlink
While using AI code and my own mind and practices
If someone asks me now whether coding is easy, I would still say yes. It is easy, and it is just as difficult as it was a few years ago. Before, we used to write code that would run, and then we had to debug it. Now the code runs, but it takes more debugging than before.
My name is Imran Niaz. I am a security engineer, penetration tester, and back-end principal engineer. I have held various jobs over time.
It was very difficult for me to find subdomains every day, and it was very annoying. I needed a system that would do everything for me. As I mentioned in an article, most of my projects are private and not registered on any bug-boundary platform.
With all this in mind, I installed Linux on a laptop and used Python with Flask.
If you want to build your own system to help you scan all these things, you need resources, an internet connection, and a lot of knowledge of front-end, back-end, and pentesting.
You can take the computer I am currently using; it has a 10th Gen i7 processor, 32GB of RAM, a 4GB graphics card, and a 500GB SSD.
The sole purpose of creating all these things is to reduce my workload. While there are many tools on the market, they do not function the way I need them to; either they don't work as intended, or they fail to provide a proper return on investment.
During the course of this project โ which spanned three to four months โ I discovered that the single largest expense was AI tools, primarily because of the heavy coding requirements and the increasing difficulty of managing the database.
Does it give me any return or savings?
Yes, these tools help me a lot. The reason is that using third-party tools can cost me more than 1000 per month.
However, I combined the available online tools while writing some vibe code. First, I made the documentation define all the problems and how you are going to address them.
At first, I was thinking about building everything in ASP.NET or another language. Then I wanted to build my own machine learning algorithm to help me define and produce things as quickly as possible. Before this test, I was able to make 12, but I never published it. It was helping me identify 25 possible issues.
Soul is going to help me with all things; I have their proper
This tool I've built for myself will assist me with a variety of tasks, such as discovering subdomains and their directories, performing active domain filtering, identifying which IP addresses host accessible domains, bypassing firewall systems via IP addresses, and handling all the other essentials required of a penetration tester.
I am currently developing this tool, and a significant amount of work has already gone into it. The cost involved is around one dollar.
Target
โ
Subdomain Discovery
โ
Port & Service Discovery
โ
Web Recon
โ
URL/Endpoint Discovery
โ
Technology Detection
โ
WAF / TLS Analysis
โ
API / WordPress Testing
โ
Vulnerability Scanning
โ
Findings
โ
Manual Verification
โ
ReportTarget
โ
Subdomain Discovery
โ
Port & Service Discovery
โ
Web Recon
โ
URL/Endpoint Discovery
โ
Technology Detection
โ
WAF / TLS Analysis
โ
API / WordPress Testing
โ
Vulnerability Scanning
โ
Findings
โ
Manual Verification
โ
ReportPreviously, I was running this tool on a Hetzner server, but the electricity costs were becoming excessive. I considered moving it elsewhere to avoid this issue, but I ended up getting my own server.
Technical details ยท
Pentesting workspace with 30 + security tools covering:
- Subdomain & Domain Discovery
- Port & Network Scanning
- Website Recon & URL Fuzzing
- WAF & SSL/TLS Scanning
- API & WordPress Security Testing
- Subdomain Takeover Detection
- Findings & CVE Tracking
- Automated Pentesting Workflows
Electricity costs are very high โ if I factor in the additional expense, I have to pay an extra $100 on my home bill just to run the server.