Archive position — measured, not model output
0 likes on Devpost
2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,848 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
PathFinder & one-shot-enum is a self-reported security automation tool designed to help penetration testers process scattered enumeration outputs from various pentesting tools into prioritized, evidence-backed next steps. It is described as a correlation engine that normalizes findings from traditional and AI attack surfaces, integrating with existing tools like Nmap or BloodHound rather than replacing them.
What changed
The project evolved from an enumeration parser into a more structured tool for connecting findings across multiple tools and environments. During the OpenAI 2026 hackathon, it reportedly used Codex/GPT-5.6 to expand parser coverage, improve correlation, and integrate one-shot-enum.
Single most important open question
Is there any evidence of real-world usage or adoption by security professionals beyond the author's own testing?
What The Product Actually Is
The description states that PathFinder is a tool that turns raw pentesting and AI system enumeration output into prioritized, evidence-backed next steps. It includes a companion tool called one-shot-enum which performs broad first-pass discovery across traditional infrastructure and AI attack surfaces.
PathFinder parses and normalizes the resulting evidence, correlating services, credentials, web content, Active Directory data, privilege escalation findings, and AI components. It does not replace tools like Nmap or BloodHound but connects their results.
The author describes building PathFinder iteratively, starting with common enumeration outputs and adding rules for correlating findings into actionable recommendations. The tool is said to support real-world lab testing and code reviews for improving parser reliability.
Evidence
- PathFinder processes outputs from traditional network/web tools, Active Directory, credential discovery, privilege escalation checks, and AI systems.
- It integrates with one-shot-enum for initial discovery and evidence collection.
- It uses a normalized finding format to preserve context while enabling correlation.
- The tool was extended using Codex/GPT-5.6 during Build Week.
Inference The tool appears to be a post-processing engine that enhances existing pentesting workflows by reducing manual analysis of scattered outputs.
Positioning & Claim Evolution
The author claims PathFinder helps security testers quickly identify the most promising attack paths by turning scattered recon data into actionable insights. It is positioned as a bridge between enumeration and decision-making, aiming to reduce time spent sorting through tool output.
It evolved from being just an enumeration parser into a practical correlation and prioritization engine during Build Week, where it was extended with Codex/GPT-5.6.
Evidence
- The tagline: “PathFinder turns scattered pentest recon into evidence-backed next steps, helping security testers quickly identify the most promising attack paths.”
- The author states that PathFinder grew beyond a collection of parsers into a practical engine.
- It integrates with one-shot-enum for streamlined workflow from discovery to analysis.
Inference The positioning has shifted from a simple parser to a tool that supports human judgment in pentesting workflows, rather than automating full attacks.
Target Customer & ICP
The description states that PathFinder is aimed at security testers, particularly those preparing for or taking the OSCP exam. It helps them connect findings from various tools into actionable steps.
Evidence
- The author mentions that after taking the OSCP exam, they felt overwhelmed by the amount of enumeration required.
- PathFinder is described as helping testers spend less time sorting through output and more time investigating opportunities.
- One-shot-enum is presented as a tool for initial discovery, suggesting it targets early-stage recon.
Inference The primary customer segment appears to be penetration testers or cybersecurity professionals in training, especially those using open-source tools like Nmap, BloodHound, etc.
Business Model & Pricing Evidence
No information about pricing, monetization strategy, or business model is provided in the description.
Evidence
- No mention of revenue streams, subscriptions, licensing models, or commercial use cases.
- The project was submitted to a hackathon and built during Build Week.
Inference It is unclear whether this is intended for commercial sale, open-source distribution, or personal use only.
Technical & Delivery Signals
The author reports that PathFinder was built iteratively using Python. It supports parsing outputs from various tools with different formats and schemas. The tool includes parsers, attack rules, regression tests, and real-world lab testing to improve reliability.
Codex/GPT-5.6 was used during Build Week to expand parser coverage, strengthen cross-tool correlation, and integrate one-shot-enum.
Evidence
- Built with Python.
- Supports normalization of inconsistent tool outputs.
- Uses parsers, attack rules, regression tests, and lab testing for improvement.
- Extended using Codex/GPT-5.6 during Build Week.
- Integrates with one-shot-enum.
Inference The technical approach involves iterative development, normalization of data formats, and leveraging AI to scale parsing capabilities.
Traction & Maturity Signals
There is no evidence of traction or adoption beyond the author’s own testing and lab environments. No customers, users, or real-world deployments are mentioned.
Evidence
- The project was submitted to a hackathon.
- It was built during Build Week.
- The author tested it against an isolated Metasploitable 2 lab.
- No mention of external usage, feedback, or adoption.
Inference The tool is at an early stage of development and lacks any measurable traction or user base.
Competitive Context
No direct competitors are named in the description. However, the author notes that PathFinder does not replace tools like Nmap or BloodHound but connects their results.
Evidence
- PathFinder is described as complementary to existing tools such as Nmap and BloodHound.
- It supports AI system reconnaissance, which may place it near emerging AI security tooling.
Inference It operates in a niche between traditional pentesting automation and AI-focused recon tools. Its competitive positioning depends on how well it integrates with current toolchains.
Key Risks & Red Flags
- Lack of traction or adoption: No evidence of real-world usage or customer feedback.
- Unverified claims: All statements are self-reported without independent verification.
- Limited scope: The tool is described as a personal project built during a hackathon, not a commercial product.
- Dependency on external tools: Relies heavily on other tools (e.g., Nmap) for input, which may limit its utility if those tools change or become obsolete.
- AI integration claims: Mentioned AI coverage but no details on how it works or whether it's validated.
Inference The tool is likely in a prototype or early-stage development phase and has not yet demonstrated commercial viability or market demand.
Diligence Questions To Ask The Founders
- What specific pentesting tools does PathFinder currently support, and how often do those tools change their output formats?
- How many real-world labs have you tested PathFinder against beyond the Metasploitable 2 lab?
- Have you received any feedback from actual security professionals or testers using this tool?
- Is there a plan to monetize or commercialize PathFinder, and what would that model look like?
- What are the main challenges in maintaining parser accuracy as external tools evolve?
Investment/Partnership Verdict
Not evidenced.
Evidence
- No financial data, funding rounds, headcount, or valuation.
- No indication of a clear path to market or commercial traction.
- The project is described as a personal tool built during a hackathon.
Inference At this stage, there is insufficient evidence to assess whether PathFinder has investment potential or strategic value for partnerships. It appears to be an early-stage idea with no demonstrated product-market fit or business model.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
