OpenAI 2026 hackathon

PathFinder & one-shot-enum

PathFinder turns scattered pentest recon into evidence-backed next steps, helping security testers quickly identify the most promising attack paths.

Solo project by tpazz Koorehpaz · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,848 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

PathFinder & one-shot-enum is a self-reported security automation tool designed to help penetration testers process scattered enumeration outputs from various pentesting tools into prioritized, evidence-backed next steps. It is described as a correlation engine that normalizes findings from traditional and AI attack surfaces, integrating with existing tools like Nmap or BloodHound rather than replacing them.

What changed

The project evolved from an enumeration parser into a more structured tool for connecting findings across multiple tools and environments. During the OpenAI 2026 hackathon, it reportedly used Codex/GPT-5.6 to expand parser coverage, improve correlation, and integrate one-shot-enum.

Single most important open question

Is there any evidence of real-world usage or adoption by security professionals beyond the author's own testing?

Back to contents

What The Product Actually Is

The description states that PathFinder is a tool that turns raw pentesting and AI system enumeration output into prioritized, evidence-backed next steps. It includes a companion tool called one-shot-enum which performs broad first-pass discovery across traditional infrastructure and AI attack surfaces.

PathFinder parses and normalizes the resulting evidence, correlating services, credentials, web content, Active Directory data, privilege escalation findings, and AI components. It does not replace tools like Nmap or BloodHound but connects their results.

The author describes building PathFinder iteratively, starting with common enumeration outputs and adding rules for correlating findings into actionable recommendations. The tool is said to support real-world lab testing and code reviews for improving parser reliability.

Evidence

  • PathFinder processes outputs from traditional network/web tools, Active Directory, credential discovery, privilege escalation checks, and AI systems.
  • It integrates with one-shot-enum for initial discovery and evidence collection.
  • It uses a normalized finding format to preserve context while enabling correlation.
  • The tool was extended using Codex/GPT-5.6 during Build Week.

Inference The tool appears to be a post-processing engine that enhances existing pentesting workflows by reducing manual analysis of scattered outputs.

Back to contents

Positioning & Claim Evolution

The author claims PathFinder helps security testers quickly identify the most promising attack paths by turning scattered recon data into actionable insights. It is positioned as a bridge between enumeration and decision-making, aiming to reduce time spent sorting through tool output.

It evolved from being just an enumeration parser into a practical correlation and prioritization engine during Build Week, where it was extended with Codex/GPT-5.6.

Evidence

  • The tagline: “PathFinder turns scattered pentest recon into evidence-backed next steps, helping security testers quickly identify the most promising attack paths.”
  • The author states that PathFinder grew beyond a collection of parsers into a practical engine.
  • It integrates with one-shot-enum for streamlined workflow from discovery to analysis.

Inference The positioning has shifted from a simple parser to a tool that supports human judgment in pentesting workflows, rather than automating full attacks.

Back to contents

Target Customer & ICP

The description states that PathFinder is aimed at security testers, particularly those preparing for or taking the OSCP exam. It helps them connect findings from various tools into actionable steps.

Evidence

  • The author mentions that after taking the OSCP exam, they felt overwhelmed by the amount of enumeration required.
  • PathFinder is described as helping testers spend less time sorting through output and more time investigating opportunities.
  • One-shot-enum is presented as a tool for initial discovery, suggesting it targets early-stage recon.

Inference The primary customer segment appears to be penetration testers or cybersecurity professionals in training, especially those using open-source tools like Nmap, BloodHound, etc.

Back to contents

Business Model & Pricing Evidence

No information about pricing, monetization strategy, or business model is provided in the description.

Evidence

  • No mention of revenue streams, subscriptions, licensing models, or commercial use cases.
  • The project was submitted to a hackathon and built during Build Week.

Inference It is unclear whether this is intended for commercial sale, open-source distribution, or personal use only.

Back to contents

Technical & Delivery Signals

The author reports that PathFinder was built iteratively using Python. It supports parsing outputs from various tools with different formats and schemas. The tool includes parsers, attack rules, regression tests, and real-world lab testing to improve reliability.

Codex/GPT-5.6 was used during Build Week to expand parser coverage, strengthen cross-tool correlation, and integrate one-shot-enum.

Evidence

  • Built with Python.
  • Supports normalization of inconsistent tool outputs.
  • Uses parsers, attack rules, regression tests, and lab testing for improvement.
  • Extended using Codex/GPT-5.6 during Build Week.
  • Integrates with one-shot-enum.

Inference The technical approach involves iterative development, normalization of data formats, and leveraging AI to scale parsing capabilities.

Back to contents

Traction & Maturity Signals

There is no evidence of traction or adoption beyond the author’s own testing and lab environments. No customers, users, or real-world deployments are mentioned.

Evidence

  • The project was submitted to a hackathon.
  • It was built during Build Week.
  • The author tested it against an isolated Metasploitable 2 lab.
  • No mention of external usage, feedback, or adoption.

Inference The tool is at an early stage of development and lacks any measurable traction or user base.

Back to contents

Competitive Context

No direct competitors are named in the description. However, the author notes that PathFinder does not replace tools like Nmap or BloodHound but connects their results.

Evidence

  • PathFinder is described as complementary to existing tools such as Nmap and BloodHound.
  • It supports AI system reconnaissance, which may place it near emerging AI security tooling.

Inference It operates in a niche between traditional pentesting automation and AI-focused recon tools. Its competitive positioning depends on how well it integrates with current toolchains.

Back to contents

Key Risks & Red Flags

  • Lack of traction or adoption: No evidence of real-world usage or customer feedback.
  • Unverified claims: All statements are self-reported without independent verification.
  • Limited scope: The tool is described as a personal project built during a hackathon, not a commercial product.
  • Dependency on external tools: Relies heavily on other tools (e.g., Nmap) for input, which may limit its utility if those tools change or become obsolete.
  • AI integration claims: Mentioned AI coverage but no details on how it works or whether it's validated.

Inference The tool is likely in a prototype or early-stage development phase and has not yet demonstrated commercial viability or market demand.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific pentesting tools does PathFinder currently support, and how often do those tools change their output formats?
  2. How many real-world labs have you tested PathFinder against beyond the Metasploitable 2 lab?
  3. Have you received any feedback from actual security professionals or testers using this tool?
  4. Is there a plan to monetize or commercialize PathFinder, and what would that model look like?
  5. What are the main challenges in maintaining parser accuracy as external tools evolve?

Back to contents

Investment/Partnership Verdict

Not evidenced.

Evidence

  • No financial data, funding rounds, headcount, or valuation.
  • No indication of a clear path to market or commercial traction.
  • The project is described as a personal tool built during a hackathon.

Inference At this stage, there is insufficient evidence to assess whether PathFinder has investment potential or strategic value for partnerships. It appears to be an early-stage idea with no demonstrated product-market fit or business model.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.