LeoAI  by cha0upup

AI-driven platform for automated post-penetration management and host collaboration

Created 1 month ago
258 stars

Top 97.9% on SourcePulse

GitHubView on GitHub
Project Summary

Summary

LeoAI is an AI-driven, post-exploitation management platform for authorized red teams and security researchers. It integrates LLM agents to automate complex tasks, providing a unified web workbench for host asset management, collaborative operations, and AI-assisted reconnaissance and exploitation, streamlining post-exploitation workflows.

How It Works

The architecture employs a Platform AI for analysis and task orchestration, delegating operations to Puppet AIs within target sessions. Puppet AIs use LangChain4j and over 100 tools for execution, progress reporting, and data accumulation. Supporting multiple LLMs (OpenAI, Tongyi Qianwen, DeepSeek, etc.) with dynamic context adaptation, it enables sophisticated AI agent interactions for automated post-exploitation.

Quick Start & Requirements

  • Requirements: Java 17+, Linux/macOS/Windows, 4GB+ RAM, 500MB disk, modern browser.
  • Installation:
    • JAR: Download LeoAi-<version>.jar. Run java -jar --add-opens java.base/java.lang=ALL-UNNAMED LeoAi-<version>.jar. Access http://localhost:8082.
    • Docker: Clone repo, run docker compose up -d --build from root.
  • Default Credentials: admin / 54ikun (change immediately).
  • Links: Releases, Repo.

Highlighted Details

  • AI Automation: Dual AI roles (Platform/Puppet), multi-LLM support, dynamic context (up to 1M tokens), 100+ AI tools, pre-built Skills for recon, credential hunting, privilege escalation, lateral movement.
  • Toolset: Virtual terminals, file managers, database consoles, network scanners, HTTP repeaters/fuzzers, proxy/tunneling, system management, credential extraction.
  • Shells & Obfuscation: Memory shells (18+ middleware, 41+ injection types), traffic obfuscation (TLS spoofing, custom encode/decode logic).
  • Collaboration: User/team management, host sharing, auditing logs, centralized AI/skill management.

Maintenance & Community

Hosted on GitHub with issues tracked via GitHub Issues. Contact: chaodovvn@gmail.com. No dedicated community channels or roadmap detailed.

Licensing & Compatibility

Licensed under GNU General Public License v3.0 (GPL v3). This strong copyleft license may restrict commercial use or integration with closed-source software.

Limitations & Caveats

AI functionality requires external LLM services (API keys, network access). HTTPS is recommended via a front-end reverse proxy. The project is strictly for legally authorized use, with developers disclaiming responsibility for misuse.

Health Check
Last Commit

3 days ago

Responsiveness

Inactive

Pull Requests (30d)
0
Issues (30d)
4
Star History
65 stars in the last 30 days

Explore Similar Projects

Feedback? Help us improve.