automajicly commited on
Commit
304fb53
Β·
verified Β·
1 Parent(s): 659ab0a

Update README.md

Browse files
Files changed (1) hide show
  1. README.md +90 -0
README.md CHANGED
@@ -1,3 +1,93 @@
1
  ---
2
  license: mit
 
 
 
 
 
 
 
 
 
 
 
 
 
3
  ---
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
  ---
2
  license: mit
3
+ tags:
4
+ - security
5
+ - pentesting
6
+ - autonomous-agent
7
+ - cybersecurity
8
+ - tool-use
9
+ - qwen2.5
10
+ language:
11
+ - en
12
+ base_model:
13
+ - bartowski/Qwen2.5-14B_Uncensored_Instruct-GGUF
14
+ pipeline_tag: text-generation
15
+ library_name: transformers
16
  ---
17
+
18
+ πŸ” Local Security Model β€” Autonomous Pentesting Agent
19
+
20
+ Developed by: automajicly
21
+ Built on: Qwen2.5-14b-Instruct-Uncensored-GGUF by Bartowski
22
+
23
+ OVERVIEW
24
+
25
+ Local_Security_Model is an autonomous penetration testing agent designed for professional security assessments. Built on top of Qwen 2.5, it operates through a custom MCP (Model Context Protocol) architecture that enables real-time tool orchestration, vulnerability discovery, and exploit chaining β€” all running locally with no cloud dependency.
26
+ This agent was developed as the core engine behind PenMaster Security, targeting small business security audits, WordPress hardening, and ecommerce vulnerability assessments.
27
+
28
+ Key Capabilities
29
+ β€’ Autonomous reconnaissance β€” masscan + nmap port/service enumeration with zero manual input
30
+ β€’ Vulnerability assessment β€” searchsploit integration for CVE matching against discovered services
31
+ β€’ Web application testing β€” nikto and sqlmap for injection and misconfiguration detection
32
+ β€’ Credential auditing β€” hydra and ncrack for multi-protocol brute force testing
33
+ β€’ Payload delivery β€” curl/wget for staged payload retrieval and HTTP interaction
34
+ β€’ Structured reporting β€” auto-generated HTML pentest reports with severity ratings and remediation guidance
35
+
36
+ Architecture
37
+
38
+ agent_loop.py ← LLM reasoning + tool chain generation (Qwen 2.5 via LM Studio)
39
+ mcp_server.py ← Flask-based tool execution server (port 8000, systemd managed)
40
+ report_generator.py ← HTML report engine with PenMaster branding
41
+ logs/ ← Structured JSON session logs
42
+ reports/ ← Auto-generated client-facing pentest reports
43
+
44
+
45
+ Model backend:
46
+ Qwen 2.5-14B served locally via LM StudioExecution layer: Flask MCP server with systemd auto-restartInterface: Terminal-native, SSH-accessible from remote IDEs (Cursor)
47
+
48
+ Tool Stack:
49
+
50
+ TOOL PURPOSE
51
+
52
+ masscan High speed port scanning
53
+
54
+ nmap Service/version enumeration
55
+
56
+ nitko Web server vulnerability scanning
57
+
58
+ sqlmap SQL injection detection
59
+
60
+ hydra Multi-protocol credential brute forcing
61
+
62
+ ncrack Network authentication cracking
63
+
64
+ searchsploit CVE/exploit database lookup
65
+
66
+ curl/wget HTTP interaction and payload staging
67
+
68
+
69
+
70
+ Intended Use
71
+
72
+ This model and agent stack is designed for:
73
+ β€’ Professional penetration testing against authorized targets
74
+ β€’ Security audits for small businesses, WordPress sites, and ecommerce platforms
75
+ β€’ Vulnerability research in isolated lab environments
76
+ β€’ Security education and CTF preparation
77
+ ⚠️ Authorized use only. This tool is intended exclusively for use against systems you own or have explicit written permission to test. Unauthorized use is illegal and unethical.
78
+
79
+
80
+ Target Environments
81
+ β€’ Kali Linux (primary deployment platform)
82
+ β€’ Isolated VM lab networks
83
+ β€’ Small business web infrastructure (with client authorization)
84
+
85
+
86
+ Business Context
87
+ Local_Security_Model is the core engine behind PenMaster Security β€” an independent penetration testing project offering:
88
+ β€’ Initial security audit and vulnerability report
89
+ β€’ Ongoing security hardening retainer
90
+ β€’ WordPress and ecommerce-focused assessments
91
+ πŸ“¬ Contact: GitHub.com/XenoCoreGiger31
92
+
93
+