Skip to content

Latest commit

 

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

🔐 Advanced VAPT & Exploitation Framework

📌 Overview

This repository contains a comprehensive Vulnerability Assessment and Penetration Testing (VAPT) project covering advanced exploitation techniques, API security testing, privilege escalation, network protocol attacks, mobile application testing, and a full capstone penetration testing engagement.


📌 Internship Context

This task was completed as a part of my Vulnerability Assessment and Penetration Testing (VAPT) Internship at Cyart Technologies in April 2026.


🎯 Objectives

  • Understand advanced exploitation and exploit chaining
  • Perform API security testing based on OWASP API Top 10
  • Execute privilege escalation and persistence techniques
  • Simulate network protocol attacks (MitM, SMB Relay)
  • Analyze mobile applications for vulnerabilities
  • Conduct a full VAPT engagement using PTES methodology
  • Deliver structured security reports with remediation

🧠 Key Domains Covered

  • Advanced Exploitation Techniques
  • API Security Testing
  • Privilege Escalation & Persistence
  • Network Protocol Attacks
  • Mobile Application Penetration Testing
  • Comprehensive Reporting & Remediation

🛠️ Tools & Technologies

  • Kali Linux
  • Metasploit Framework
  • Burp Suite
  • Postman
  • sqlmap
  • LinPEAS
  • Responder
  • Ettercap
  • Wireshark
  • MobSF
  • Frida
  • Drozer
  • OpenVAS

⚙️ Methodology

The project follows the PTES (Penetration Testing Execution Standard):

  1. Reconnaissance
  2. Scanning & Enumeration
  3. Exploitation
  4. Privilege Escalation
  5. Persistence
  6. Post-Exploitation
  7. Reporting

🚀 Capstone Project

A full VAPT engagement was simulated on a vulnerable environment:

  • Identified VSFTPD vulnerability
  • Exploited using Metasploit
  • Gained remote access
  • Conducted API and network testing
  • Applied privilege escalation techniques
  • Established persistence
  • Proposed remediation strategies
  • Validated fixes using OpenVAS

⚠️ Sensitive Content Notice

Due to the nature of exploitation techniques and security vulnerabilities, certain screenshots and proof-of-concept details have been intentionally excluded to prevent misuse.

All activities were conducted in a controlled lab environment for educational purposes only.


📄 Documentation

Detailed report, notes, and supporting materials are available in the Week 4 folder.


⚠️ Disclaimer

This project is intended for educational purposes only. All testing was performed in a controlled environment. Unauthorized use of these techniques is strictly prohibited.


👨‍💻 Author

Aditya Mehta
Cybersecurity Enthusiast


About

Advanced VAPT & Exploitation Framework covering exploit chaining, API security, privilege escalation, network attacks, mobile testing, and a full PTES-based capstone engagement.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors