hexstrike-ai  by 0x4m4

AI agents for autonomous penetration testing and cybersecurity research

Created 1 month ago
1,792 stars

Top 24.0% on SourcePulse

GitHubView on GitHub
Project Summary

HexStrike AI MCP Agents is an advanced platform designed to empower AI agents with autonomous penetration testing and vulnerability discovery capabilities. It integrates over 150 cybersecurity tools, enabling AI models like Claude, GPT, and Copilot to perform automated security assessments, bug bounty hunting, and security research.

How It Works

HexStrike employs a multi-agent architecture driven by an "Intelligent Decision Engine." This engine analyzes targets, selects optimal tools, and orchestrates complex attack chains. Specialized AI agents, such as the BugBountyWorkflowManager and CVEIntelligenceManager, execute specific tasks autonomously. The platform leverages a "FastMCP" protocol for seamless AI integration and features a modern visual engine for real-time dashboards and progress visualization.

Quick Start & Requirements

  • Installation: Clone the repository, create a Python virtual environment, install dependencies (pip install -r requirements.txt), and install core security tools via apt or pip.
  • Prerequisites: Python 3.9+, recommended RAM 16GB+, 50GB+ storage, 4+ CPU cores. Optional GPU for AI features.
  • Running: Start the server with python3 hexstrike_server.py.
  • AI Integration: Configure AI agents (e.g., Claude Desktop, VS Code Copilot) by pointing them to the HexStrike server URL (http://localhost:8888).
  • Documentation: API Reference, Health Check.

Highlighted Details

  • Integrates 150+ security tools across network, web, cloud, binary analysis, forensics, and CTF domains.
  • Features 12+ specialized AI agents for autonomous tasks like vulnerability discovery, exploit generation, and CTF solving.
  • Includes an AI-powered "Intelligent Decision Engine" for tool selection, parameter optimization, and attack chain orchestration.
  • Offers a "Browser Agent" as a Burp Suite alternative for headless browser automation and web application security analysis.
  • Provides a modern visual engine with real-time dashboards, animated progress bars, and color-coded vulnerability cards.

Maintenance & Community

The project is actively maintained by "m0x4m4" and welcomes community contributions. Support and discussions are available via GitHub Issues and a Discord Server.

Licensing & Compatibility

Released under the MIT License, permitting commercial and non-commercial use with attribution.

Limitations & Caveats

The README emphasizes responsible disclosure and warns that AI agents have powerful system access, recommending isolated environments and oversight. Unauthorized testing is strictly prohibited.

Health Check
Last Commit

2 weeks ago

Responsiveness

Inactive

Pull Requests (30d)
6
Issues (30d)
38
Star History
1,804 stars in the last 30 days

Explore Similar Projects

Starred by Dan Guido Dan Guido(Cofounder of Trail of Bits), Chip Huyen Chip Huyen(Author of "AI Engineering", "Designing Machine Learning Systems"), and
1 more.

cai by aliasrobotics

5.7%
3k
Cybersecurity AI (CAI) is an open framework for building AI-driven cybersecurity tools
Created 5 months ago
Updated 2 days ago
Feedback? Help us improve.