1. Project Overview & Context
CyberDoom Pentest v2.1 translates current, real-world cybercrime techniques (like high-frequency card testing, mobile API exploitation, and sophisticated social engineering precursors) into controlled, non-destructive test cases. The objective is not just to find vulnerabilities, but to provide **quantitative metrics of resilience** and identify precise hardening requirements for security teams. This project addresses the gap between theoretical penetration testing and continuous, adversarial threat simulation.
Core Impact Metrics
-
95%Automation Rate
-
300+Active Test Cases
-
v2.1Current Version
2. Key Threat Simulation Modules
The platform is divided into two highly specialized simulation modules, each targeting distinct vectors of financial fraud. Use the tabs below to explore the detailed test cases.
MNO & Mobile Money Simulation
Focus: Testing APIs and User Authentication against social engineering and direct system intrusion (e.g., SIM-Swap precursors).
| Target Service | Simulation Feature | Validation Goal |
|---|---|---|
Safaricom (M-Pesa)
|
SMS Social Engineering (Smishing) | Test user training effectiveness and SMS Sender ID Spoofing prevention controls. |
Airtel (Airtel Kenya)
|
Unauthorized PIN Change & Remote Transaction | Validate security controls on key financial transaction APIs (SS7/Diameter layer and API access controls). |
| All MNOs | SIM Detail/IMSI Extraction | Assess resilience against SIM-Swap precursor attacks by checking for vulnerability in subscriber data lookup. |
3. Adversarial Simulation Methodology
The CyberDoom process strictly follows an intelligence-led, four-phase cycle to ensure comprehensive coverage and measurable results, moving beyond conventional compliance-based auditing.
Threat Intelligence Fusion
Collect real-time data on criminal forums, dark web activity, and fraud trends impacting FinTechs in the region. Prioritize test cases based on active TTPs (Tactics, Techniques, and Procedures).
API/Protocol Execution
Deploy automated, high-volume, non-destructive simulation attacks against authenticated APIs, payment gateways, and MNO signaling protocols (SS7/Diameter) in a controlled environment.
Resilience Scoring & Metrics
Generate a quantitative score indicating the **time-to-detect (TTD)** and **time-to-respond (TTR)**. Provide clear, evidence-based reports showing exactly where the platform failed to prevent or detect the simulation.
Defensive Implementation
Collaborate with development teams to implement targeted fixes (e.g., rate limit adjustments, stronger input validation, API hardening). Re-run the exact failing test cases to validate efficacy.
4. Core Technology Stack
The CyberDoom platform is built for speed, concurrency, and minimal latency, essential for effective financial fraud simulation across multiple technology layers.
Python (Scrapy/Requests)
The **core engine** for attack vector scripting, data serialization, and running complex, stateful multi-step simulations.
Golang (Microservices)
Used for **high-concurrency modules** (e.g., high-frequency card testing) where raw network performance is critical.
SS7/Diameter Protocol Stacks
Low-level networking components for simulating **MNO core attacks** (e.g., SIM detail extraction) to test telecom security controls.
Kafka (Event Streaming)
Handles the ingestion and correlation of massive volumes of simulation logs before processing by Elasticsearch.
Elasticsearch / Kibana
For **real-time log aggregation**, analysis of simulation results, and generating the resilience metrics dashboard.
Docker & Kubernetes
Ensures simulations are run in **isolated, repeatable, and scalable** containers without impacting production systems.
5. Governance & Ethical Framework
Due to the sensitive nature of FinTech threat simulation, CyberDoom operates under a strict legal and ethical framework to ensure all activities are authorized, controlled, and non-disruptive.
Strict Legal Authorization
All simulations require a signed Letter of Engagement and a formalized Scope of Work (SOW) from the client's Head of Security or C-level executive. The SOW defines the exact endpoints, rate limits, and allowed time windows.
Zero Production Impact
A **kill-switch mechanism** is integrated into every high-volume test. All activities are confined to designated Staging or Pre-Production environments, or strictly monitored production endpoints with pre-authorized, non-live accounts.