Automating security engagements through AI-driven orchestration.
Project details
Vigil integrates offensive security and incident response efforts in a single CLI. Leveraging a full Kali runtime, it utilizes AI to orchestrate workflows and deploy specialized agents for both red and blue team engagements. Vigil offers a structured approach to managing security tasks while ensuring accountability in operations.
Vigil is an advanced AI-driven platform designed for security engagements, integrating specialist agents, a complete Kali runtime, and a reliable orchestrator within a single command-line interface (CLI). It streamlines offensive security testing and incident response through a structured workflow, enabling operators to efficiently manage engagements.
Key Features:
Comprehensive Security Engagements: Vigil facilitates end-to-end security engagements by allowing an intelligent language model (LLM) operator to read a phased workflow prompt, dispatch specialist agents, and execute real tools within a shared Kali container. Detailed records are maintained for every interaction, including targets, services, requests, probes, findings, and attack chains, all stored in a durable orchestrator database.
Multiple Engagement Modes: The system supports five operational modes across a single backend, including web red-teaming, white-box code analysis, combined web and code analysis, Android application testing, and blue incident response.
Verified Findings and Audits: Each finding is independently validated by agents other than the original author, ensuring accuracy and integrity. Commands executed during the assessment are recorded, maintaining a thorough audit trail.
Integrated Tools and Resources: Vigil operates within a long-lived Kali container equipped with essential tools for reconnaissance, web scanning, fuzzing, and exploitation, along with an audited browser for secure operations.
Durability and Scalability: Engagements manage state effectively, retaining critical data in an SQLite database with rotations and backups, making it easier to handle recurring tasks without losing context or progress.
Enhanced Collaboration: The platform includes several client integrations—Claude Code, Codex, Kimi, Goose, OpenCode, and Pi—allowing diverse applications in security testing and incident response.
How It Works:
Operators can initiate engagements quickly through commands that establish the environment and assign specific tasks:
vigil engagement create https://target.example --hosts target.example
vigil engagement start <engagement-key> --client codex
The framework emphasizes authorized use only, designed to operate strictly within the confines of ethical guidelines and legal approvals. Successful interactions and configurations demand explicit authorization and adherence to engagement scopes.
Documentation and Support: Vigil comes with extensive documentation covering installation, engagement creation, assessment commands, and operational guidelines, which can be consulted for in-depth understanding and operations management. For more details on setting up and using Vigil, refer to the comprehensive resources available in the repository.
Comments
0Start the conversation
Share the first comment.