Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
T3MP3ST — autonomous red teaming platform; multi-agent offensive-security meta-harness | Kitploit
Tools/GitHubGitHub/elder-plinius/t3mp3st
Penetration Testing FrameworksReconnaissanceExploit FrameworksVulnerability AnalysisWeb Application ExploitationCTFCloud SecurityMobile SecurityBinary AnalysisLearning & EducationRed TeamingAI Security
5.5k1.1k4021 days agoReviewed by Kitploit
GitHubelder-plinius/t3mp3st

T3MP3ST

autonomous red teaming platform; multi-agent offensive-security meta-harness

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🌩️ T3MP3ST 🌩️

 ▄▄▄█████▓▓█████  ███▄ ▄███▓ ██▓███  ▓█████   ██████ ▄▄▄█████▓
 ▓  ██▒ ▓▒▓█   ▀ ▓██▒▀█▀ ██▒▓██░  ██▒▓█   ▀ ▒██    ▒ ▓  ██▒ ▓▒
 ▒ ▓██░ ▒░▒███   ▓██    ▓██░▓██░ ██▓▒▒███   ░ ▓██▄   ▒ ▓██░ ▒░
 ░ ▓██▓ ░ ▒▓█  ▄ ▒██    ▒██ ▒██▄█▓▒ ▒▒▓█  ▄   ▒   ██▒░ ▓██▓ ░
   ▒██▒ ░ ░▒████▒▒██▒   ░██▒▒██▒ ░  ░░▒████▒▒██████▒▒  ▒██▒ ░
   ▒ ░░   ░░ ▒░ ░░ ▒░   ░  ░▒▓▒░ ░  ░░░ ▒░ ░▒ ▒▓▒ ▒ ░  ▒ ░░
     ░     ░ ░  ░░  ░      ░░▒ ░      ░ ░  ░░ ░▒  ░ ░    ░
   ░         ░   ░      ░   ░░          ░   ░  ░  ░    ░
             ░  ░       ░               ░  ░      ░

A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.

scores: re-derivable   verify-claims 24/24   PRs welcome   License: AGPL-3.0

Your AI coding agent is already a hacker — T3MP3ST hands it an arsenal.

Point it at an authorized target and the kill chain runs itself: recon → exploit → report, from a browser War Room or the CLI, driven by the agent you're already signed into — Claude Code, Codex, Hermes — or a model you run fully offline (Ollama, LM Studio, vLLM). No new API keys, no cloud tenant, no second bill. Your agent is the brain; T3MP3ST is the war machine bolted around it. Self-hosted storm. Keyless warfare. ⚡

And it won't ask you to take its word for it. On XBOW's own 104-challenge suite it scores 90.1% pass@1 — above XBOW's self-reported 85% — alongside hint-free CTF solves and a cold hunt on real, post-cutoff CVEs the model had never seen. Every number in this README recomputes from committed data with one command (npm run verify-claims). Loud about the mission, honest about the build — the status table says exactly what's live, what's scaffolding, and what's still roadmap; full receipts in Benchmarks.

Three things set it apart:

  1. Reproducible. Every number in this README recomputes from committed data — npm run verify-claims re-derives all of them, 24/24 green. A claim that can't be reproduced doesn't ship. No trust-me numbers, ever.
  2. Keyless. The AI coding agent already on your machine is the backbone. No API keys, no second bill, no gatekeeper.
  3. Honest about scope. The status table marks exactly what's stable, experimental, or roadmap — because red-teaming shouldn't be a priesthood, and it damn sure shouldn't run on vibes.

Jump to → Quick start · What it hunts · What ships today · Benchmarks · Architecture · Docs

⚠️ Authorized use only

T3MP3ST is an offensive security tool, built for authorized testing, research, and education. Point it only at systems you own or have explicit, written permission to test. Unauthorized access to computers, networks, or data is illegal in most jurisdictions — you alone are responsible for how you use this software and for staying inside the law and your rules of engagement. Bring the storm to your targets, not someone else's.

T3MP3ST is provided as-is under the AGPL-3.0 license, with no warranty and no liability for any damage, loss, or misuse. The authors do not endorse, support, or condone unauthorized activity. Get permission. Stay in scope. Don't be a menace. 🫡

Why it exists

Offensive security sits behind years of practice and expensive tooling. The bet behind T3MP3ST is that a coordinated agent swarm puts real bug-hunting in reach of people who never got the invite, across web apps, CTFs, smart contracts, source code, and embedded/robotics OSS. That is an ambitious bet, and the sections below are careful to separate what already works from what is still a bet.

What it hunts

DomainWhat it doesStatus
🕸️ Web appsBlack-box, external-attacker recon → exploit (XBEN suite)✅ Stable
🚩 CTFHint-free, sandbox-jailed solves (Cybench)✅ Stable
🤖 Robotics / OT / embeddedCoordinated-disclosure pipeline for OSS vuln hunting (OSV + live-PoC + refuter)✅ Pipeline stable
📂 Source codeWhite-box repo analysis with blind master-builder decomposition⚠️ Python-only ingest
💰 Smart contractsDamn Vulnerable DeFi⚠️ reproduction, not novel discovery
☁️ Cloud (IaC)Misconfig-detection benchmark (cloud:bench) + opt-in cloud arsenal (aws/az/gcloud + scoutsuite/cloudfox/pmapper; pacu gated)🚧 IaC-misconfig scaffolding — live-cloud exploitation not yet benchmarked
📱 MobileBuilt-in static analyzer (manifest misconfig + secret/cleartext detection, mobile:bench) + opt-in arsenal (mobsfscan/objection/drozer; frida gated)🚧 static-detection scaffolding — dynamic exploitation not benchmarked
🔩 Binary / REDecompiled-output sink detector (unsafe-copy / format-string / cmd-injection / int-overflow, binary:bench) + opt-in arsenal (ghidra/radare2/objdump/checksec/strings; gdb gated)🚧 static sink-detection scaffolding — solving/pwn not benchmarked

Quick start

Fastest path to a running War Room (keyless, ~2 min to set up; mission time depends on the target):

npm install
npm run server        # War Room → http://127.0.0.1:3333/ui/

In the War Room, open Settings and connect a local agent (Claude Code / Codex / Hermes). Then describe a target to Op Admiral in plain English and launch. The agent you connected is the brain. No key required.

Prefer to bring a key? Set one and skip the connect step:

export OPENROUTER_API_KEY=...     # or VENICE_API_KEY / ANTHROPIC_API_KEY / OPENAI_API_KEY
export XAI_API_KEY=...            # Grok Build (grok-build-0.1) — xAI's coding model, native tool-calling

Slow local agents can be given more room with T3MP3ST_LOCAL_AGENT_TIMEOUT_MS for each CLI call, T3MP3ST_TASK_TIMEOUT_MS for mission tasks, and T3MP3ST_GENERAL_TIMEOUT_MS for planning requests. Values are milliseconds.

Or run it fully offline on your own model — no key, no cloud. Defaults to Ollama; point it at any OpenAI-compatible server (LM Studio, vLLM, llama.cpp):

ollama serve && ollama pull llama3                          # or an OpenAI-compatible server
export TEMPEST_LOCAL_BASE_URL=http://localhost:11434/api    # LM Studio: http://localhost:1234/v1
export TEMPEST_LOCAL_MODEL=llama3
npx tempest                                                 # → "Change default provider" → local

Tool-calling works on any local model (it's driven over text), so the Arsenal runs even on models without native function-calling.

Check the numbers for yourself:

npm run verify-claims             # re-derives every headline from committed JSON in bench/

Library/SDK usage, the full HTTP API, and MCP setup live in docs/.

What ships today

Download Tool