berylliumsec/nebula

AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

What it solves

Nebula is a unified desktop surface for security engagements, consolidating tools like terminals, browsers, code editors, and reporting tools into one place. It solves the problem of context loss and fragmentation during penetration testing by allowing operators to move seamlessly between research, execution, and documentation.

How it works

The platform integrates an AI assistant that can investigate, organize, and write, while keeping the human operator in control. It uses a isolated OCI execution environment (via Docker or Podman) to run tools safely. The workflow follows a strict sequence: intent, assistance, approval, execution, and evidence. It supports various model runtimes, including hosted, local, and OpenAI-compatible models, though the core terminal and reporting features remain available without an AI provider.

Who it’s for

Security professionals and penetration testers who need a structured, AI-assisted environment for conducting authorized security tests.

Highlights

  • Unified Workspace: Combines terminal, browser, notes, findings, and reports in a single interface.
  • Operator-Centric Control: Features explicit authority controls, including scope enforcement, approval pauses, and hard budgets.
  • Durable Evidence Trail: Uses content-addressed artifacts and append-only events to maintain a verifiable record of how conclusions were reached.
  • Flexible AI Integration: Compatible with local and hosted LLMs, but functional as a standalone security workbench.