
PhantomRecon ist ein CLI-basiertes, modulares, agentengesteuertes Red-Team-Automatisierungstool, das dazu entwickelt wurde, autonome offensive Sicherheitsworkflows zu demonstrieren, die von KI (Google Gemini über das Agent Development Kit – ADK) unterstützt werden.
PhantomRecon ist ein CLI-basiertes, modulares, agentengesteuertes Red-Team-Automatisierungstool, das dazu dient, autonome offensive Sicherheits-Workflows zu demonstrieren, die von KI unterstützt werden (Googles Gemini über das Agent Development Kit - ADK).
python -m phantomrecon
python -m phantomrecon --target example.com --auto \
--nmap-timeout 30 --nmap-top-ports 100 --nmap-args "-sV -Pn"
--target <domain|ip>: Ziel, das bewertet werden soll--auto: Recon → Plan → Route → Report ausführen--nmap-timeout <seconds>: Überschreibt NMAP_TIMEOUT--nmap-top-ports <N>: Überschreibt NMAP_TOP_PORTS--nmap-args "...": Hängt an Nmap-Argumente an (NMAP_ARGS)--nmap-disable: Nmap deaktivieren (setzt NMAP_DISABLE=1)Umgebungsvariablen werden ebenfalls direkt unterstützt: NMAP_TIMEOUT, NMAP_TOP_PORTS, NMAP_ARGS, NMAP_DISABLE.
.gitignore schließt reports/* aus, außer reports/sample_report.md.reports/.Als Proof-of-Concept konzipiert, simuliert es die Identifizierung eines Ziels, die Durchführung breiter Aufklärung (Nmap, DNS, Websuche), die Planung einer Angriffsstrategie mithilfe eines LLM, die bedingte Ausführung simulierter Exploits und die Erstellung eines Berichts.
phantomrecon/
├── phantomrecon/ # Main package (exported orchestrator agent)
│ ├── __init__.py
│ ├── __main__.py # CLI entrypoint (interactive and non-interactive)
│ └── agent/ # Agent graph and tools
├── agents/ # Python modules containing agent/tool logic
│ ├── recon_logic.py # Nmap, DNS (dig), seeded web analysis; ADK search enabled
│ ├── routing_logic.py # Logic for the Exploit Router agent
│ ├── exploit_web_logic.py # Functions for web exploits (currently simulated)
│ ├── exploit_sql_logic.py # Functions for SQL exploits (currently simulated)
│ └── report_logic.py # Functions for report generation using session state
├── configs/
│ └── targets.json # (Optional) Target configuration
├── data/
│ └── dummy_scan_output.json # Example Nmap data if no target specified
├── demos/
│ └── walkthrough.md # Demo steps
├── prompts/ # Prompt templates for LLM agents
├── reports/
│ └── sample_report.md # Example output report
├── requirements.txt # Python dependencies (includes google-adk)
├── .gitignore # Files excluded from version control
└── LICENSE # MIT License
recon_workflow - Parallel-Agent):
nmap_tool)dns_tool)web_search_tool)aggregation_tool):
aggregated_recon_data in den Sitzungszustand.planning_agent - LlmAgent):
attack_planner_prompt.txt, um einen JSON-Angriffsplan zu generieren.attack_plan in den Sitzungszustand.exploit_router - RouterAgent):
attack_plan aus dem Zustand.web_exploit_tool, sql_exploit_tool).exploit_results im Sitzungszustand hinzu.report_tool):
python3, pip, nmap, dig, whois, sqlmap, wapiti, wpscan, searchsploit.python3 -m venv venv
source venv/bin/activate # On Windows use `venv\Scripts\activate`
pip install -r requirements.txt
.env.example in .env (falls ein Beispiel existiert) oder bearbeiten Sie .env.GOOGLE_API_KEY hinzu.GOOGLE_GENAI_USE_VERTEXAI auf True oder False und konfigurieren Sie zugehörige Variablen (GOOGLE_CLOUD_PROJECT, GOOGLE_CLOUD_LOCATION), falls Sie Vertex AI verwenden.python -m phantomreconpython -m phantomrecon --target <target> --autoadk run phantomreconDieses Tool ist ausschließlich für autorisierte Sicherheitstests und Bildungszwecke bestimmt. Verwenden Sie es nicht gegen Systeme ohne ausdrückliche Genehmigung.
Dieses Projekt ist unter der MIT-Lizenz lizenziert - siehe die Datei LICENSE für Details.
sudo apt install nmap oder brew install nmap)sudo apt install dnsutils oder brew install bind)sudo apt install whois oder brew install whois)sudo apt install sqlmap oder brew install sqlmap)sudo apt install wapiti oder brew install wapiti)sudo apt install ruby-full und dann gem install wpscan oder brew install wpscan)sudo apt install exploitdb oder brew install exploitdb)requirements.txt aufgeführt sind (Installation über pip install -r requirements.txt)