Open Issues Need Help
View All on GitHubAn AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: The issue proposes enhancing the agent's intelligence by integrating a local, vector-indexed pentesting knowledge base (KB). This KB, curated from sources like ExploitDB and NVD, would be queried before resorting to web search, aiming to significantly reduce latency, improve the reliability of retrieved information by providing verified content, and bridge knowledge gaps for recent CVEs beyond the LLM's training data cutoff.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: This GitHub issue proposes implementing a cross-session learning system for the agent, combining 'Reflexion' and 'Episodic Memory'. The agent will generate structured reflections after failures and store complete engagement episodes. In future sessions, relevant past experiences and reflections will be retrieved and injected into the agent's context, enabling it to learn from mistakes and build institutional knowledge, much like a human pentester.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: This issue proposes replacing the agent's current flat todo list with a two-level Planner-Executor hierarchy to improve strategic direction on long engagements. The Planner will define strategic milestones with budgets and contingency plans, while the existing ReAct loop (Executor) works within these scopes. This system aims to prevent agents from drifting by enforcing iteration budgets and enabling proactive contingency planning.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: The issue proposes implementing a new, dedicated attack path specifically for client-side browser exploitation, leveraging tools like `browser_autopwn2` and JavaScript payloads. This is deemed necessary because client-side attacks have a unique 'reversed connection model' where the victim connects to the attacker, and require dynamic browser fingerprinting for payload selection, which the current unclassified paths do not adequately support or guide.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: This GitHub issue proposes implementing a dedicated, classified attack path for local privilege escalation within an agent. The goal is to systematically enumerate OS-specific privesc vectors on both Linux and Windows, then apply targeted exploits to escalate privileges from a low-privilege shell to root/SYSTEM. The current unclassified fallback is deemed insufficient due to its lack of structured, methodical, and OS-dependent enumeration and exploitation capabilities.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: This GitHub issue proposes implementing a dedicated attack path for credential capture, combining fake services like Metasploit capture servers with network poisoning techniques such as LLMNR/NBNS/mDNS spoofing, followed by hash cracking. The core challenge lies in the temporal coordination and concurrent execution of multiple background services, which must run simultaneously and wait for victim authentication, a pattern distinct from other "fire-and-forget" attack paths.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: The issue proposes implementing a dedicated, classified attack path for web application vulnerabilities like SQL injection, LFI, XXE, and SSRF. Currently, these attacks are categorized as 'unclassified,' which is insufficient. A classified path would enable a proper discovery-confirm-exploit-escalate pipeline, allowing for parameter-aware targeting and specific tool selection based on the vulnerability type.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AI Summary: This issue requests the implementation of a dedicated, multi-step attack path for Active Directory environments, encompassing techniques like Kerberoasting, Pass-the-Hash, and DCSync. It highlights the necessity of managing complex attack chains where each step's output feeds the next, requiring precise knowledge of attack graphs, hash format routing, and coordination of tools like Metasploit to automate these advanced enterprise pentesting skills.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.