offensive security agents

80 tagged offensive security, measured the same way as everything else here.

Browse within: Autonomous Agents 50ai-security-tool 50multi-agent-systems 50redteam 13ctf 12penetration-testing 12red-team 12claude-code-skills 8exploit-development 8Multi-Agent 5pentesting 5

bt6-issue-steward

01

elder-plinius/T3MP3ST

Agent

Triages and responds to issues across BT6 research and support repositories using evidence, tracker authority, and explicit mutation gates.

5.8k 8d ago A 32 tokens AGPL-3.0

bt6-pr-auditor

03

elder-plinius/T3MP3ST

Agent

Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.

5.8k 8d ago A 32 tokens AGPL-3.0

drupal

04

ASCIT31/Dark-Moon

Agent

Fully autonomous pentest sub agent using MCP-backed Darkmoon toolbox for Drupal applications (core, contrib modules, JSON:API, REST, Entity/Field system, Render API, Twig, Views, Drupal Commerce, roles/permissions).

878 3d ago A 49 tokens GPL-3.0

headless-browser

05

ASCIT31/Dark-Moon

Agent

Fully autonomous pentest sub agent using MCP-backed fastcmp toolbox for web application navigation with headless browser.

878 3d ago A 24 tokens GPL-3.0

moodle

06

ASCIT31/Dark-Moon

Agent

Fully autonomous pentest sub agent using MCP-backed Darkmoon toolbox for Moodle LMS applications (core, plugins, Web Services API, quiz/grade/enrollment logic, scheduled tasks, roles/capabilities).

878 3d ago A 43 tokens GPL-3.0

finding-checker

07

hypnguyen1209/offensive-claude

Agent

Blind adversarial checker — given ONLY a finding artifact and its evidence (never the author's reasoning), tries to refute it and emits a structured rebuttal that drives the bounded generator↔checker rebuttal loop. Distinct from finding-validator.

351 15d ago A 52 tokens original MIT

finding-validator

08

hypnguyen1209/offensive-claude

Agent

Adversarial exploitability judge — issues a PASS / KILL / DOWNGRADE / CHAIN-REQUIRED verdict on each finding, distinct from the artifact-completeness check. Tries to REFUTE every finding before accepting it.

351 15d ago A 50 tokens original MIT

network-analyst

09

hypnguyen1209/offensive-claude

Agent

Deep network analysis agent — packet inspection, protocol dissection, traffic anomaly detection, IDS/IPS rule creation, firewall auditing.

351 15d ago A 29 tokens original MIT

ad-exploit-agent

10

blacklanternsecurity/red-run

Agent

Active Directory exploitation subagent for red-run. Executes one AD technique skill per invocation as directed by the orchestrator. Handles Kerberos attacks, ADCS abuse, ACL exploitation, credential operations, lateral movement, and domain persistence. Use when the orchestrator needs to exploit an AD vulnerability.

263 5mo ago A 62 tokens GPL-3.0

linux-privesc-agent

11

blacklanternsecurity/red-run

Agent

Linux privilege escalation subagent for red-run. Executes one privesc skill per invocation as directed by the orchestrator. Handles Linux host discovery, sudo/SUID/capabilities abuse, cron/service exploitation, file path abuse, kernel exploits, and container escapes. Use when the orchestrator has shell access on a…

263 5mo ago A 78 tokens GPL-3.0

web-exploit-agent

12

blacklanternsecurity/red-run

Agent

Web application exploitation subagent for red-run. Executes one web technique skill per invocation as directed by the orchestrator. Handles injection testing, authentication bypass, file upload, deserialization, and all other web exploitation techniques. Use when the orchestrator needs to exploit a web vulnerability.

263 5mo ago A 60 tokens GPL-3.0

darlene

13

ogrodev/fsociety

Agent

Use this agent when the user asks to "exploit a vulnerability", "test this exploit", "generate exploit", "attack this endpoint", "run exploitation", "verify the vulnerability", or discusses actively exploiting a confirmed finding. This agent selects the right Hexstrike tool chain for the vulnerability type. Context…

20 5mo ago A 188 tokens original MIT

cleaner

14

ogrodev/fsociety

Agent

Use this agent when the user asks to "clean up traces", "remove evidence", "wipe logs", "eliminate footprint", "clean the system", "remove artifacts", "clear history", "cover tracks", "anti-forensics sweep", or discusses removing operational traces from compromised or operated-on systems. Context: User finished an…

20 5mo ago A 188 tokens original MIT

ghost

15

ogrodev/fsociety

Agent

Use this agent when the user asks to "secure a machine", "harden a server", "make a system secure", "set up opsec", "prepare infrastructure", "full security audit", "lock down the server", "run security checks", or mentions comprehensive system hardening and operational security setup. Context: User has a fresh VPS to…

20 5mo ago A 195 tokens original MIT