WEBVTT

00:00.760 --> 00:02.400
Hello everyone and welcome.

00:02.600 --> 00:08.680
In this video we will continue from our previous video where we created a pen test planner agent and

00:08.680 --> 00:11.240
a cybersecurity research task.

00:11.640 --> 00:19.280
We also created a crew class where we would run this entire identity experience using the crew AI framework.

00:19.440 --> 00:21.960
So now I will go ahead and execute this.

00:22.880 --> 00:29.560
While this runs, I need to bring this up that I change the cybersecurity scanning from hackthissite

00:30.680 --> 00:32.320
to google.com.

00:32.800 --> 00:38.320
The reason to do that is there were a lot of vulnerabilities on the Hackthissite org.

00:38.840 --> 00:44.120
And it's a it's a lot of data to go through when I had google.com.

00:44.320 --> 00:50.800
It's relatively simple for beginners and intermediate learners, so that you can understand how you

00:50.800 --> 00:56.200
can do a web security vulnerability scan and create a post out of it.

00:56.560 --> 00:58.120
So just a heads up on that.

00:58.120 --> 01:04.870
I changed the URL to Google, and we will go over the vulnerabilities that the Zap proxy tool would

01:04.870 --> 01:06.590
find for google.com.

01:07.390 --> 01:09.710
It's it takes a while for it to run.

01:09.710 --> 01:11.510
So I'm going to pause the video.

01:11.750 --> 01:14.390
I will come back to this when it's done executing.

01:14.630 --> 01:15.310
Thank you.

01:15.470 --> 01:19.870
It took a while for it to run, but finally it was it was done executing.

01:20.870 --> 01:27.350
So let's go over the results that we got and do a quick analysis before I go dive deeper into analysis.

01:27.470 --> 01:33.190
I would like to just go over the the agent experience for the web security vulnerability.

01:33.590 --> 01:38.830
So the agent is supposed to provide comprehensive penetration testing on web applications.

01:39.430 --> 01:46.110
As a web application penetration tester, you pinpoint weakness in web applications with extensive knowledge

01:46.110 --> 01:48.670
of web application and security practices.

01:48.990 --> 01:56.230
You have set current numerous applications from potential threats, and then the task is to produce

01:56.230 --> 02:03.830
a detailed report that includes both original and cybersecurity scan results and find from your researches.

02:04.390 --> 02:10.590
The documents are structured provide clarity on both technical and non-technical stakeholders and these

02:10.590 --> 02:12.670
links should be cited if need be.

02:13.150 --> 02:16.070
So here's the links that you find from the research done.

02:16.070 --> 02:20.470
So let me copy this over and open it in a in an IDE.

02:21.230 --> 02:23.870
So I copied over the entire stack trace.

02:23.870 --> 02:26.270
And here is the visit print.

02:26.750 --> 02:33.470
The agent is web application penetration tester and the task is results of the scan and conduct thorough

02:33.470 --> 02:40.070
internet research to fact check and identify the potential solutions for the issues and vulnerabilities

02:40.070 --> 02:41.630
highlighted in the scan.

02:41.830 --> 02:44.350
So we have the results from the scan.

02:44.550 --> 02:48.270
So in this case here is the tool that invoked the scan.

02:48.270 --> 02:50.270
And this is the entire result.

02:50.630 --> 02:53.230
The file on the following sites were included.

02:53.510 --> 03:00.860
And then the alert description is the content security policy first to define the directives that has

03:00.860 --> 03:04.060
to fall back and content security policy.

03:04.900 --> 03:08.580
And there were some security findings that were found.

03:08.860 --> 03:17.380
So now what we are going to do is the agent will do analysis of vulnerabilities found on google.com.

03:17.700 --> 03:19.740
So here is the report it provided.

03:20.100 --> 03:24.260
So it says this is the report of analysis of vulnerabilities.

03:24.660 --> 03:31.620
These will have detected vulnerabilities and it provides a very thorough description potential impact

03:31.860 --> 03:34.060
and the mitigation strategy.

03:34.620 --> 03:35.740
This was the output.

03:35.740 --> 03:38.340
And if you notice here there was a conclusion.

03:38.340 --> 03:44.500
And these sites that were referenced for coming up with appropriate findings that were listed here.

03:44.820 --> 03:46.140
Thank you so much.

03:46.540 --> 03:49.180
This is just the repeat of the same thing.

03:49.180 --> 03:51.820
It's just in different color coded descriptions.

03:52.380 --> 03:53.580
Thank you so much.

03:53.740 --> 03:55.460
I'll see you in the next video.
