Pentest AI Agents
50 Claude Code subagents for authorized penetration testing, organized across recon, web, Active Directory, cloud, mobile, wireless, C2 operations, payload crafting, reverse engineering, forensics, and reporting. Tier 1 agents are advisory (you run the tools); Tier 2 agents can execute tools directly against declared in-scope targets. For authorized security testing only.
View on GitHubWhat it does
- engagement-planner
Generate phased pentest plans with MITRE ATT&CK mappings, time estimates, and rules-of-engagement templates.
- recon-advisor (Tier 2)
Parse Nmap/Nessus/BloodHound output, prioritize targets, and execute recon tools directly against declared in-scope hosts.
- ad-attacker (Tier 2)
Drive BloodHound, Impacket, CrackMapExec, and Certipy for Kerberos, delegation, ACL, and certificate-abuse attacks.
- detection-engineer
Generate Sigma, Splunk SPL, Elastic KQL, and Sentinel KQL detection rules with false-positive tuning.
- /recommend "task description"
Slash command that routes to the right agent and returns concrete next commands for any pentest task.
- db/doctor.sh
Audit which underlying CLI tools (nmap, nuclei, BloodHound, Impacket, etc.) are installed on your machine, grouped by agent.