← all repositories
Ed1s0nZ/CyberStrikeAI

AI security testing platform that brings its own C2

It gives security teams an AI-native command center that orchestrates 100+ real testing tools and includes a built-in C2 framework for authorized engagements.

5.2k stars Go Domain AppsAgentsOther AI
CyberStrikeAI
Velocity · 7d
+16
★ / day
Trend
steady
star history

What it does CyberStrikeAI is a Go-based security testing platform that wraps over a hundred open-source tools—from nmap and sqlmap to nuclei and bloodhound—behind a web dashboard and AI agents. Users chat with OpenAI-compatible models to run scans, manage vulnerabilities, track attack chains, and even operate a lightweight built-in C2 framework for authorized engagements. It handles the full lifecycle: conversation, tool execution, result visualization, and audit logging, with SQLite persistence and role-based access.

The interesting bit The project leans heavily on CloudWeGo Eino to run multi-agent orchestration—modes like deep, plan_execute, and supervisor—where sub-agents can progressively disclose skills for specific domains like SQLi or API security. It also speaks native MCP (Model Context Protocol) over HTTP, stdio, and SSE, effectively turning the entire tool suite into an interoperable AI function catalog that can federate with external systems.

Key highlights

  • 100+ curated tool recipes covering the full kill chain, from reconnaissance and exploitation to forensics and post-exploitation, with YAML-based extensions
  • Multi-agent orchestration via Eino with single-agent ReAct and three multi-agent modes, plus 20+ sample skill packs for specialized testing
  • Built-in C2 framework with encrypted beacon channels, listeners, session/task queues, and MCP tools for AI-driven command-and-control
  • Human-in-the-loop approval gates with tool allowlists, plus chatbot integrations for DingTalk and Lark so you can approve a shell from your phone
  • Knowledge base with RAG and embedding-based retrieval, plus project “shared facts” that persist cross-session context like targets and credentials

Caveats

  • The built-in C2, WebShell manager, and exploitation features are repeatedly marked for authorized testing only, so operational security and legal clearance are entirely on you
  • Most of the 100+ tools are external binaries that must be present on the host; the AI falls back to alternatives when something is missing, but the platform is fundamentally an orchestration layer around existing scanners

Verdict Red teams and security engineers who want an auditable, collaborative AI copilot for real tooling will find this useful. If you are looking for a fully self-contained scanner that runs without dependencies, this is not it.

Frequently asked

What is Ed1s0nZ/CyberStrikeAI?
It gives security teams an AI-native command center that orchestrates 100+ real testing tools and includes a built-in C2 framework for authorized engagements.
Is CyberStrikeAI open source?
Yes — Ed1s0nZ/CyberStrikeAI is open source, released under the Apache-2.0 license.
What language is CyberStrikeAI written in?
Ed1s0nZ/CyberStrikeAI is primarily written in Go.
How popular is CyberStrikeAI?
Ed1s0nZ/CyberStrikeAI has 5.2k stars on GitHub and is currently holding steady.
Where can I find CyberStrikeAI?
Ed1s0nZ/CyberStrikeAI is on GitHub at https://github.com/Ed1s0nZ/CyberStrikeAI.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.