m524security/AIPT
GitHub: m524security/AIPT
一个基于AI的渗透测试与红队框架,整合MITRE ATT&CK、OWASP等方法论,通过LLM系统提示词驱动全链路攻击分析与漏洞验证。
Stars: 0 | Forks: 0
# 🔴 AI-Powered Penetration Testing & Red Team Framework
## 📋 Table of Contents
1. [Overview](#overview)
2. [Legal & Ethical Framework](#legal--ethical-framework)
3. [System Architecture](#system-architecture)
4. [AI System Prompt](#ai-system-prompt)
5. [Methodology Frameworks](#methodology-frameworks)
6. [Kali Linux Cheat Sheet](#kali-linux-cheat-sheet)
- Phase 0: Environment Setup
- Phase 1: Reconnaissance & OSINT
- Phase 2: Web Application Testing
- Phase 3: API Security Testing
- Phase 4: Network Exploitation
- Phase 5: Post-Exploitation & Privilege Escalation
- Phase 6: AI/LLM Security Testing
- Phase 7: Reporting & Documentation
7. [Vulnerability Chaining](#vulnerability-chaining)
8. [False Positive Reduction](#false-positive-reduction)
9. [Tool Integration Matrix](#tool-integration-matrix)
10. [MITRE ATT&CK v19 Mapping](#mitre-attck-v19-mapping)
11. [Quick Reference](#quick-reference)
12. [Contributing](#contributing)
13. [License](#license)
## 🎯 Overview
This framework provides a **comprehensive, rigorous, and aggressive** approach to authorized penetration testing, red team operations, and offensive cybersecurity research. Designed specifically for:
- ✅ **Authorized lab environments** (Oracle VM + Kali Linux)
- ✅ **Bug bounty programs** with explicit scope definitions
- ✅ **Security certification preparation** (OSCP, CEH, GPEN, GWAPT)
- ✅ **AI/LLM security research** and adversarial testing
- ✅ **Defensive skill development** through offensive understanding
### Key Features
| Feature | Description |
|---------|-------------|
| **AI-Native** | LLM-powered analysis with structured reasoning chains |
| **Framework-Agnostic** | Integrates MITRE ATT&CK, OWASP, PTES, NIST AI RMF |
| **False-Positive Aware** | Multi-layer validation before reporting findings |
| **Chain-Oriented** | Maps vulnerability chains for maximum impact assessment |
| **Cloud-Ready** | Covers AWS, Azure, GCP, Kubernetes, Serverless |
| **AI-Security** | Includes OWASP LLM Top 10:2025 & Agentic Top 10:2026 |
## ⚖️ Legal & Ethical Framework
### 🔴 CRITICAL: Authorization Requirements
+-----------------------------------------------------------------------------+
| BEFORE ANY TESTING, YOU MUST HAVE: |
| |
| ✓ WRITTEN authorization from the system owner |
| ✓ DEFINED scope (in-scope and out-of-scope boundaries) |
| ✓ EMERGENCY contacts for immediate escalation |
| ✓ RULES of engagement (RoE) document signed by all parties |
| ✓ LIABILITY waiver and insurance coverage (for professional engagements) |
| ✓ DATA handling agreement (GDPR, CCPA compliance where applicable) |
+-----------------------------------------------------------------------------+
### Prohibited Activities
- ❌ Testing systems without explicit written authorization
- ❌ Exploiting vulnerabilities in production without approval
- ❌ Causing denial of service without explicit permission
- ❌ Exfiltrating sensitive data beyond scope
- ❌ Sharing findings with unauthorized third parties
- ❌ Using exploits for 0-day vulnerabilities without responsible disclosure
- ❌ Social engineering against real individuals without consent
### Responsible Disclosure
If you discover a vulnerability:
1. **STOP** immediately and document your findings
2. **NOTIFY** the system owner through proper channels
3. **WAIT** for acknowledgment before further testing
4. **PROVIDE** a reasonable remediation timeline (90 days standard)
5. **COORDINATE** public disclosure with the vendor
## 🏗️ System Architecture
+-----------------------------------------------------------------------------+
| AI PENETRATION TESTING FRAMEWORK |
+-----------------------------------------------------------------------------+
| LAYER 1: AI ORCHESTRATION |
| +- System Prompt (Role Definition, Behavioral Directives) |
| +- Context Management (Target, Scope, RoE) |
| +- Chain-of-Thought Reasoning (Attack Path Analysis) |
| +- Output Validation (False Positive Reduction) |
+-----------------------------------------------------------------------------+
| LAYER 2: METHODOLOGY ENGINE |
| +- MITRE ATT&CK v19 (15 Tactics, 222 Techniques) |
| +- OWASP Top 10:2025 (Web Applications) |
| +- OWASP API Security Top 10:2023 |
| +- OWASP LLM Top 10:2025 & Agentic Top 10:2026 |
| +- PTES (Penetration Testing Execution Standard) |
| +- NIST AI RMF + Generative AI Profile |
+-----------------------------------------------------------------------------+
| LAYER 3: TOOL INTEGRATION |
| +- Kali Linux Default Toolset |
| +- Custom Scripts & Automation |
| +- MCP Server Integration (Burp Suite, Metasploit, etc.) |
| +- Cloud CLI Tools (AWS CLI, Azure CLI, gcloud) |
+-----------------------------------------------------------------------------+
| LAYER 4: REPORTING & DOCUMENTATION |
| +- CVSS v3.1 Scoring |
| +- CWE Mapping |
| +- Attack Chain Visualization |
| +- Remediation Roadmap |
| +- Executive Summary Generation |
+-----------------------------------------------------------------------------+
## 🤖 AI System Prompt
标签:AI, DLL 劫持, Modbus, Web报告查看器, 大语言模型, 实时处理, 密码管理, 自动化代码审查