Autonomous penetration testing agent with LLM-guided reasoning, modular scanning, and professional reporting.
- Port Scanning: Multi-threaded TCP port scanner with service detection and banner grabbing
- Web Reconnaissance: HTTP analysis, security header checks, technology detection, path discovery, SSL/TLS analysis
- Vulnerability Scanning: CVE matching against known vulnerable service versions, nuclei integration, exposed service detection
- Exploitation Framework: SSH analysis (version checks, weak algorithms), SMB version detection, web vulnerability correlation
- LLM Planning: Optional AI-guided attack chain generation (falls back to heuristic planner)
- Report Generation: HTML and Markdown reports with CVSS scoring
- Web Dashboard: Real-time campaign monitoring
- REST API: Programmatic access to all features
# Install
pip install -r requirements.txt
# Scan a target
pentest-agent scan 127.0.0.1
# Web reconnaissance
pentest-agent webscan example.com --deep
# Vulnerability scan
pentest-agent vulnscan 127.0.0.1
# Full campaign
pentest-agent attack 127.0.0.1 --output report.json
# Start API server
pentest-api
# Then open http://localhost:9090 in browser
# Generate config template
pentest-agent init┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ Recon │────▶│ Planner │────▶│ Executor │
│ Module │ │ (LLM/H) │ │ (Tools) │
└──────────────┘ └──────────────┘ └──────┬───────┘
│
┌──────────────┐ ┌──────────────┐ ┌──────▼───────┐
│ Reporter │◀────│ Vuln Scan │◀────│ Exploit │
│ (HTML/MD) │ │ (CVE/Nuc) │ │ Framework │
└──────────────┘ └──────────────┘ └──────────────┘
| Module | File | Description |
|---|---|---|
| Port Scanner | modules/scanner.py |
Multi-threaded TCP scanner |
| Web Recon | modules/web_recon.py |
HTTP analysis, headers, paths |
| Vuln Scanner | modules/vuln_scanner.py |
CVE matching, nuclei wrapper |
| Exploits | modules/exploits.py |
SSH, SMB, web exploit modules |
| Report Gen | modules/report_gen.py |
HTML/Markdown reports |
| Red Team | agents/red_team.py |
Campaign orchestrator |
| Planner | core/planner.py |
LLM + heuristic planning |
| Safety | core/safety.py |
Scope validation, blocked targets |
| Config | core/config.py |
YAML config, env vars |
- Scope validation against allowed target lists
- Blocked IP ranges (loopback, link-local, multicast)
- Blocked domains (.gov, .mil, major cloud providers)
- Destructive action approval gates
- Custom script dangerous pattern detection
- Python 3.10+
- Optional: nmap, nuclei, sqlmap (for enhanced scanning)
- Optional: OpenAI API key (for LLM-guided planning)
Apache-2.0