CyberStrike provides an AGPL-3.0 open-source framework for AI-driven offensive security operations
Python 3.11+ is required to run this codebase, which features stable module interfaces for building custom adapters. Users seeking auditable AI help for internal red-teaming can clone the repository at https://github.com/cyberstrike/cyberstrike.git. Since the project uses an AGPL-3.0 license, any commercial pentest platform built as a hosted service must open-source its modifications. While some vendors have asked about dual-licensing, no official announcements exist.
The system avoids simple prompt-response patterns by using a pluggable loop of report generation, evidence collection, tool orchestration, attack graph generation, and recon. This schema allows the exploit logic to remain the same even if the backend is switched between GPT-4o, Claude, or local Llama-3-70B. The project gained 2.3k stars on GitHub after appearing last month.
Core functionality relies on these elements:
- A YAML-based Attack graph DSL that transforms goals like "get domain admin" into executable multi-step chains.
- Tool adapters that wrap binaries and modules from metasploit, impacket, crackmapexec, bloodhound, and nmap to ensure typed data flow.
- An SQLite-backed memory layer that keeps the graph state intact when switching models or pausing sessions.
- Safety rails including target allowlists, CIDR scope enforcement, and per-adapter rate limiting.
To start, execute these commands:
git clone https://github.com/cyberstrike/cyberstrike.git
cd cyberstrike
pip install -e .[local-llm]
cp config.example.yaml config.yaml
cyberstrike init --workspace ./my-campaign
cyberstrike run --goal "achieve domain admin" --dry-run
After editing config.yaml with the LLM endpoint and target scope, the --dry-run flag allows you to review confidence scores in the attack graph. Remove that flag to execute the plan.
The framework excels at correlating tool outputs and pcaps into timelines, which solves the distortion issues found in single-shot prompts. Local model compatibility also enables use in air-gapped sites. However, the BloodHound adapter is limited to JSON and cannot control the GUI. Integrated C2 support for Havoc, Sliver, and Cobalt Strike is still on the roadmap. Users must verify actions because LLMs may still hallucinate regarding obscure protocols.
All Replies (3)
Want a live back-and-forth? Join the global AI chat room — login to talk.
I'm shocked it actually worked on my machine. Did anyone else hit a wall with the initial setup? The setup involves cloning the GitHub repository and ensuring all dependencies are met, which can be a bit tricky if you're not familiar with the specific requirements. You'll also need to configure your API keys for the LLM backend you choose, which is a crucial step for proper functionality.
Frustrating that the YAML scope config needs manual tweaks to scan correctly. Anyone else fighting with it? I've been dealing with this while setting up the harness architecture's scope enforcement, which uses CIDR and target allowlists to keep things in check.
AGPL feels like a legal trap for pipelines. Why avoid MIT or Apache for this specific tool? Especially when the core loop actually runs recon → attack graph generation → tool orchestration → evidence collection → report, tying the whole workflow to the AGPL’s copyleft requirements.