An AI-driven, sandbox-first penetration testing platform that discovers security gaps across the network, Linux/Windows hosts, and Active Directory — strictly read-only, fully audited, and safe for sensitive internal environments.
Every action descends through the same layered path. Nothing reaches a target without passing the guardrail.
--internal Docker net · argv-only exec · OS timeouts.Borrowed from Phantom's defense model, hardened by adversarial review.
Targets canonicalized (decimal/hex/octal) then subnet_of the allowed range. Default-deny on anything unparseable.
Closed allowlists. Per-tool dangerous-flag denial. Exploit tools armed-only.
Argv-only exec in an internet-isolated Docker network. No shell, no host route.
Wall-clock + token + dollar ceilings on a monotonic ledger. Kill on breach.
SHA-256 chained, tamper-evident log of every authorize/exec/deny.
Redacts secrets/PHI (passwords, SSN, MRN); tool output treated as untrusted.
Network outside-in, plus credentialed host and directory depth.
nmap · masscan · nuclei · sslscan · whatweb · enum4linux · smbmap · snmp · ldapsearch — 9 profiles.
SUID/GTFOBins · NOPASSWD sudo · weak sshd · world-writable · Lynis.
SMB signing · AlwaysInstallElevated · unquoted services · WDigest · UAC · LAPS.
Anonymous bind · RootDSE disclosure · user enumeration. PingCastle/BloodHound hooks.
One scan, three interchangeable engines — pick per run.
Beyond a linear checklist: Argus reasons over the evidence graph, chains findings into attack paths, and adapts what it runs next — every action still re-authorized by the 7-layer guardrail, so autonomy never escapes scope.
Curated read-only probe for .env, .git, actuator, Swagger/OpenAPI — maps the unauthenticated foothold surface.
Reframes recon as architecture: flags database/management/directory planes reachable from a user VLAN.
Finds ungoverned local LLMs/notebooks (Ollama, Jupyter, Gradio, vLLM, vector DBs).
Detects GPP cpassword, exposed .env/.git, history/registry secrets — reports the path, never the secret.
Deterministic decision-trees derive multi-step attack paths, each tagged proof: observed | theoretical.
observe → plan → authorize → collect → re-plan, bounded by budget/depth. Guardrail vets every step.
Armed and in AEGIS_LAB_NET and isolation-attested — connect/read-only probes, never against clinical scope.
Built for a internal enterprise network: read-only, isolated, least-privilege, auditable.
aegis audit verifies the chain end-to-end.