<ul data-eligibleForWebStory="true">Dissecting mainframe penetration testing techniques on z/OS, particularly focused on RACF security package.Deep dive into RACF database structure, internal architecture, and its decision-making logic.Developed utility racfudit, facilitates offline analysis of RACF database, provides insights for security analysis.Exploring RACF profile relationships, user authorization flows within z/OS, and password hashing algorithms.Detailed overview of DES and KDFAES encryption algorithms for RACF password and phrase hashes.