SHAdd0WTAka/Zen-Ai-Pentest

🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️

What it solves

Zen-AI-Pentest is an autonomous penetration testing framework designed to automate security assessments. It reduces the manual effort required for reconnaissance, vulnerability scanning, and exploitation by using AI to orchestrate a vast array of professional security tools.

How it works

The system uses a ReAct (Reason $\rightarrow$ Act $\rightarrow$ Observe $\rightarrow$ Reflect) pattern and a state machine to manage the lifecycle of a security audit. An AI Orchestrator manages a pool of specialized agents (e.g., Recon, Exploit, Report) that can execute over 72 integrated security tools (like nmap, Metasploit, and sqlmap) within Docker-isolated sandboxes. It includes a risk engine to reduce false positives via multi-model voting and provides visual attack path analysis using Cytoscape.js.

Who it’s for

It is built for security professionals, bug bounty hunters, and enterprise red teams who need to automate complex security testing workflows.

Highlights

  • Autonomous AI Agents: 11 specialized personas covering domains from Cloud and ICS to Mobile and Crypto.
  • Extensive Tooling: Integration with 72+ industry-standard tools across network scanning, web security, and OSINT.
  • Risk & Validation: Bayesian-based false positive reduction and a 4-level safety system for exploit validation.
  • Comprehensive Reporting: Automated generation of PDF, HTML, and DOCX reports with compliance mapping (ISO 27001, PCI DSS, NIST).
  • Diverse Interfaces: Accessible via a React dashboard, Python CLI, REST API, and even a WhatsApp bot.

Related

  • Project
  • Project
  • Project
  • Project
  • Project