sl4de/basilisk-webpentest
Basilisk WebPentest Dataset Instruction‑tuning data for web penetration testing, used to train sl4de/Basilisk-7B. Direct, uncensored expert answers (payloads, PoCs, tool commands, reports) for authorized security testing and education. Files File Records Domains basilisk_v0.jsonl 2,999 SQLi, XSS, Recon basilisk_v1.jsonl 8,054 19 (v0 + SSRF, XXE, deserialization, auth/JWT, access control, API, SSTI, LFI, CSRF, CORS, request smuggling, prototype… See the full description on the dataset page: https://huggingface.co/datasets/sl4de/basilisk-webpentest.
Basilisk WebPentest Dataset
Instruction‑tuning data for web penetration testing, used to train sl4de/Basilisk-7B. Direct, uncensored expert answers (payloads, PoCs, tool commands, reports) for authorized security testing and education.
Files
Format
JSON Lines; one example per line, in chat‑message form:
{"messages":[
{"role":"system","content":"You are a senior web penetration testing expert ..."},
{"role":"user","content":"MySQL login form, the username field is injectable. Give me an auth bypass payload."},
{"role":"assistant","content":"Closing the string and commenting out the rest drops the password check. Payload: admin'-- -"}
],"meta":{"domain":"sqli","type":"payload","difficulty":"easy"}}meta.domain / type (payload | explain | tool | report | multiturn) / difficulty (easy | med | hard) is for curation only; it is not fed to the model. Example secrets/keys are placeholders (EXAMPLE), not real credentials.
Notes
Synthesized with a strong teacher model and validated (JSON schema, deduplication, refusal and language checks). Content is in English.
Disclaimer
For authorized penetration testing, CTF practice, security research, and education only. You are responsible for complying with all applicable laws.
License
MIT © sl4de
