<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: William Jiang</title>
    <description>The latest articles on DEV Community by William Jiang (@0xwi11iam).</description>
    <link>https://dev.to/0xwi11iam</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3732189%2F39921a8d-296c-45a1-b9d9-40664740ff38.png</url>
      <title>DEV Community: William Jiang</title>
      <link>https://dev.to/0xwi11iam</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/0xwi11iam"/>
    <language>en</language>
    <item>
      <title>Announcing Suijin</title>
      <dc:creator>William Jiang</dc:creator>
      <pubDate>Fri, 21 Aug 2026 05:55:04 +0000</pubDate>
      <link>https://dev.to/0xwi11iam/announcing-suijin-4046</link>
      <guid>https://dev.to/0xwi11iam/announcing-suijin-4046</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fk3z0a5id87eb0whl7m0g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fk3z0a5id87eb0whl7m0g.png" alt="Logo" width="377" height="355"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h4&gt;&lt;a href="https://github.com/0xwi11iam/Suijin" rel="noopener noreferrer"&gt;Check out Suijin here&lt;/a&gt;&lt;/h4&gt;

&lt;p&gt;Security testing, defense and penetration testing today is completely broken. Manual pentesting is too slow to keep up with the rapidly evolving security landscape. Packaged, simple script based security tools can no longer keep up with the creative methods of the attackers of 2026. &lt;/p&gt;

&lt;p&gt;The developer community's answer was fully autonomous AI agents. These agents are smart and work in theory, but come with massive caveats and won't work and fall apart in the field.&lt;/p&gt;

&lt;p&gt;What if your red/blue team could run 24/7, adapt to what it finds, write dynamic exploits, write reports, and defend your site and find bug bounties all at the same time? What if you could snap the modules together like Lego to adapt to each and every scenario?&lt;/p&gt;

&lt;p&gt;Meet Suijin.&lt;/p&gt;

&lt;h2&gt;
  
  
  Introduction
&lt;/h2&gt;

&lt;p&gt;I'm William, the dev behind Suijin, a fully open-source, automatic dual mode offensive/defensive cybersecurity framework.&lt;/p&gt;

&lt;p&gt;The Red Team is an AI agent, powered by SOTA models that can autonomously do reconaissance, save leaked credentials, and write and chain exploits to legitimately think like a real redteamer and find vulnerabilities in your own software or find bug bounties in web apps and web services online.&lt;/p&gt;

&lt;p&gt;The Blue Team is a team of AI agents, like an SOC running in your terminal. The team of AI agents can intelligently discern between threats and normal requests and respond by deceiving the attacker, creating honeypots, and blocking the IP before they even have time to think.&lt;/p&gt;

&lt;p&gt;Both tools share one toolkit, one knowledge graph and one knowledge base. They can run independently or together, all at the same time.&lt;/p&gt;

&lt;h2&gt;
  
  
  What really sets us apart
&lt;/h2&gt;

&lt;p&gt;Most AI tools are paperweights when air-gapped or without an API key.  Suijin can use its heuristic bypass and built in knowledge base to defend or attack in an airgapped environment.&lt;/p&gt;

&lt;p&gt;We've all seen what an AI agent does with too much autonomy. Suijin has built in human-governance, strict scope enforcement, cost caps and zero-cost supervisors that can detect when something is going wrong, and a policy engine that can detect dangerous patterns before the agent hits enter.&lt;/p&gt;

&lt;p&gt;Red Team can attack and Blue Team can defend in Suijin Battle mode where you can watch the AI agents battle each other with live tarpitting, exploits and network blocks and scripts, closest thing to a real purple teaming exercise that you are ever going to see on your own laptop.&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Inspiration
&lt;/h2&gt;

&lt;p&gt;One day I was doing a classic penetration test on a web service when I realised I was doing the same command, similar exploits, over and over again on the same few endpoints. Why couldn't this be automatic?&lt;/p&gt;

&lt;p&gt;And I tried the other automatic, script based tools. But there was always an issue. The moment a single character was wrong, the whole pipeline failed. Why?&lt;/p&gt;

&lt;p&gt;And from that day onward, I began my work on Suijin.&lt;/p&gt;

&lt;p&gt;It took many days of planning, coding, iterating, debugging before I got to my v1 release, adding tools, commands, changing the skill build up until it was a MVP.&lt;/p&gt;
&lt;h2&gt;
  
  
  What Suijin brings
&lt;/h2&gt;

&lt;p&gt;Suijin brings:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;260+ agent tools — nmap, sqlmap, gobuster, Metasploit, custom KB tools, and more&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Offline knowledge base — HackTricks, GTFOBins, PayloadsAllTheThings, SecLists — all indexed with FTS5&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Built-in labs — 8 deliberately vulnerable apps (SQLi, XSS, Log4j, SSTI, command injection, and more)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Supervisor — zero-cost pattern detector that catches loops, stalls, and missed flags with no LLM cost&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Battle mode — red vs blue live, with scoring, tarpitting, network blocks, and battle reports&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Modular OS architecture — kernel + tiers + installable modules = extensible and maintainable&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;HITL + governance — human approvals, policy enforcement, scope controls, audit trails&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  Built in labs
&lt;/h2&gt;

&lt;p&gt;We didn't want you to learn on real targets. Suijin ships with 8 deliberately vulnerable Flask apps, including blue_target — a 25-endpoint app with SQLi, XSS, SSTI, command injection, IDOR, XXE, and more. Launch one, point Suijin at it, and watch the agent get to work.&lt;/p&gt;

&lt;p&gt;It's the safest way to learn red teaming and blue teaming at the same time.&lt;/p&gt;
&lt;h2&gt;
  
  
  Get Started
&lt;/h2&gt;

&lt;p&gt;Getting started takes one command:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-fsSL&lt;/span&gt; https://raw.githubusercontent.com/0xwi11iam/Suijin/main/install.sh | bash
suijin doctor &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; suijin selftest
suijin
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That's it.  A security OS on your machine.&lt;/p&gt;

&lt;p&gt;We built Suijin because we believe open-source security tools should be powerful, accessible, and safe. We've put hundreds of hours into making this work — and we're just getting started.&lt;/p&gt;

&lt;p&gt;Star the repo. File an issue. Contribute a module. Share this with your team.&lt;/p&gt;

&lt;p&gt;The future of security is autonomous. Let's build it together!&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>python</category>
      <category>modular</category>
    </item>
    <item>
      <title>My Mac Was a $2000 Brick. Here's How I Gained Root Access in 5 Minutes</title>
      <dc:creator>William Jiang</dc:creator>
      <pubDate>Wed, 29 Jul 2026 14:09:01 +0000</pubDate>
      <link>https://dev.to/0xwi11iam/my-mac-was-a-2000-brick-heres-how-i-gained-root-access-in-5-minutes-f3k</link>
      <guid>https://dev.to/0xwi11iam/my-mac-was-a-2000-brick-heres-how-i-gained-root-access-in-5-minutes-f3k</guid>
      <description>&lt;p&gt;I built &lt;a href="https://github.com/0xwi11iam/macos-evilmaid" rel="noopener noreferrer"&gt;https://github.com/0xwi11iam/macos-evilmaid&lt;/a&gt; to help those who are locked out of their Macs.&lt;/p&gt;

&lt;p&gt;With this tool, with just a USB drive and Recovery Mode you can regain root access to your Mac in under 5 minutes without deleting any files and not touching ANYTHING that might damage your system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I remember the exact moment I realized I was stuck.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I was sitting in front of my own Mac—a machine I paid for with my own money—and I couldn't do anything with it. I had standard user permissions. No sudo. No admin access. No way to install the tools I needed. No way to fix the problem.&lt;/p&gt;

&lt;p&gt;It wasn't malicious. It wasn't stolen. It was just... locked down. MDM. A provisioning profile from an organization that had long since forgotten I existed. And I was trapped in my own hardware.&lt;/p&gt;

&lt;p&gt;I spent days trawling through forums, GitHub issues, and ancient StackExchange threads. Everything I found was either: completely outdated (10.12 Sierra-era fixes that no longer work), dangerously destructive (suggestions to wipe the entire drive), or vague and unhelpful ("just use Recovery Mode" with no actual steps).&lt;/p&gt;

&lt;p&gt;I was stuck in a dead zone—a technical problem that was just obscure enough that nobody had written a clear, modern, working solution.&lt;/p&gt;

&lt;p&gt;So I built one.&lt;/p&gt;

&lt;p&gt;This is macos-evilmaid — a tool that lets you regain root access on an MDM-locked Mac in under 5 minutes, using nothing more than a USB drive and Recovery Mode.&lt;/p&gt;

&lt;p&gt;Here's what it does:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;You boot into Recovery Mode (⌘+R or power button on Apple Silicon).&lt;/li&gt;
&lt;li&gt;You run build.sh from a USB drive.&lt;/li&gt;
&lt;li&gt;The script drops a LaunchDaemon that runs as root on the next boot.&lt;/li&gt;
&lt;li&gt;You connect to the resulting reverse shell via nc.&lt;/li&gt;
&lt;li&gt;You enable the root user with dsenableroot.&lt;/li&gt;
&lt;li&gt;You're done. Full admin access. No files deleted. No data lost.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;It works on macOS Sequoia (untested on Tahoe, but likely compatible). It targets the data volume (/private/var/tmp/ and /Library/LaunchDaemons/), so it doesn't break the system volume seal.&lt;/p&gt;

&lt;p&gt;But I didn't just release a script. I documented everything:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The attack chain—so you understand what's happening under the hood.&lt;/li&gt;
&lt;li&gt;The mitigations—so you can harden your own systems against this.&lt;/li&gt;
&lt;li&gt;The detection methods—so blue teams know what to look for.&lt;/li&gt;
&lt;li&gt;The ethical boundaries—so there's no confusion about when this is legal and when it's not.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is the tool I wished existed a year ago. I built it so nobody else has to waste days searching for a fix that doesn't exist.&lt;/p&gt;

&lt;p&gt;Thanks!&lt;/p&gt;

</description>
      <category>security</category>
      <category>bash</category>
      <category>root</category>
    </item>
  </channel>
</rss>
