The Academy is free // the war room is optional
DAEMONCORE // ACADEMY
TRADECRAFT // PENTEST DELIVERABLE & CVSS v4.0 SUITE

Pentest Finding & Deliverable Generator

Full offline CVSS v4.0 & v3.1 scoring calculator with verified vulnerability presets, technical root cause analysis, PoC terminal evidence, and 1-click export to Executive-ready Markdown, DefectDojo JSON, and Jira.

FIRST.org CVSS v4.0

Exact MacroVector scoring with new Attack Requirements (AT) and Subsequent Impact metrics.

Verified Presets

Pre-configured findings for AS-REP Roasting, LLMNR, SMB Signing, Weak Ciphers, and Shadow Credentials.

1-Click Exports

Direct output to Executive Markdown deliverables, DefectDojo API JSON, and Jira tickets.

Executive Ready

Structured C-suite risk summaries alongside detailed tactical remediation scripts and GPO settings.

PRESET VULNERABILITY TEMPLATES // CONSULTANT REPOSITORY

Dossier:2 Findings Staged
CALCULATED METRIC SEVERITY
CVSS v4.0 (FIRST.org)OFFICIAL
6.8/ 10.0MEDIUM
Severity Scale
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
EQ1 (Exploit)
L1
EQ2 (Complex)
L0
EQ3 (Vuln Sys)
L1
EQ4 (Sub Sys)
L0
EQ5 (Joint)
L1
CVSS v4.0 replaces "Scope" with distinct Vulnerable System vs Subsequent System impacts, and introduces the Attack Requirements (AT) metric.

1. EXPLOITABILITY METRIC GROUP (ATTACK CONDITIONS)

N

Remotely exploitable across the internet or boundary network without physical or subnet proximity.

L

Specialized access conditions or extenuating circumstances do not exist. Repeatable exploitation.

v4.0 NEW
N

The attack does not depend on deployment-specific configurations or non-default prerequisites.

L

Requires standard user privileges (e.g. standard domain account, guest role, or basic subscriber).

N/P/A
N

Vulnerability can be exploited without any interaction from another human user.

2. VULNERABLE SYSTEM IMPACT (DIRECT TARGET COMPONENT)

H

Total loss of confidentiality; all data exposed.

N

No loss of integrity within the vulnerable system.

N

No impact to availability of the vulnerable system.

3. SUBSEQUENT SYSTEM IMPACT (DOWNSTREAM / LATERAL SYSTEMS)

Replaces legacy CVSS v3.1 Scope (S:U / S:C) with explicit downstream impact modeling
H

Total loss of confidentiality on connected/downstream databases or secondary systems.

H

Complete lateral compromise of downstream systems (e.g. domain takeover, cloud pivot).

N

No availability impact to subsequent systems.