Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
nightcrawler — Local AI powered red teamer on a phone | Kitploit
Tools/GitHubGitHub/garagehq/nightcrawler
Password CrackingReconnaissanceWi-Fi AuditingVulnerability AnalysisExploitationIDS/IPS EvasionPenetration TestingCommand and ControlRed TeamingAI Security
GitHubgaragehq/nightcrawler
67956592 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

nightcrawler

Local AI powered red teamer on a phone

View Repository

Nightcrawler

An autonomous penetration testing agent that runs entirely on a smartphone. Drop the phone on a network, walk away, and it discovers hosts, maps services, finds vulnerabilities, and generates a pentest report — all without cloud connectivity.

 ░█▄░█ █ █▀▀ █░█ ▀█▀ █▀▀ █▀█ ▄▀█ █░█░█ █░░ █▀▀ █▀█
 ░█░▀█ █ █▄█ █▀█ ░█░ █▄▄ █▀▄ █▀█ ▀▄▀▄▀ █▄▄ ██▄ █▀▄  v0.1.0

 AUTONOMOUS MOBILE PENTEST AGENT
 OnePlus 8 · NetHunter · LFM2.5-1.2B · OpenCL GPU

What is this?

Penetration testing (pentesting) is the practice of testing a computer network's security by simulating an attack — with the network owner's explicit permission. Professional pentesters are hired to find vulnerabilities before real attackers do.

Nightcrawler automates this process on a phone. It uses a small AI model (LFM2.5-1.2B-Instruct-Heretic, 1.2 billion parameters) running locally on the phone's GPU to decide what to do next — which host to probe, which tool to use, what to look for. No internet connection or cloud API required.

Demo

▶️ Watch Nightcrawler in action on Instagram

How it works

  1. WiFi Breach (optional) — If dropped without WiFi, it can autonomously crack WPA2 networks using an external USB WiFi adapter
  2. Reconnaissance — Discovers devices on the network using stealthy scans
  3. Enumeration — Probes discovered services (web servers, file shares, SSH, DNS, etc.)
  4. Exploitation — Tests for known vulnerabilities and default credentials
  5. Reporting — Generates a structured pentest report with findings and remediation advice

The agent operates like a patient human pentester — it rotates across hosts, does one small action per turn, and builds knowledge gradually over hours. This makes it much harder to detect than traditional vulnerability scanners that blast every host at once.

Key concepts

TermWhat it means
Drop boxA device left on a target network to perform testing autonomously
ScopeThe set of networks/hosts you're authorized to test
Rules of Engagement (ROE)A legal document specifying what you're allowed to do
StealthTechniques to avoid detection by network monitoring (IDS/IPS)
MCPModel Context Protocol — a standard interface for AI tool use
C2Command and Control — the web dashboard for monitoring and steering the agent

Architecture

┌──────────────────────────────────────────────────────────┐
│                   PHONE (OnePlus 8)                       │
│                                                           │
│  ┌─────────────┐     ┌──────────────────┐                │
│  │  LFM2.5     │     │  Agent Loop      │                │
│  │  1.2B model │◄───►│  (main.py)       │                │
│  │  on GPU     │     │  Decides what     │                │
│  │  (:8080)    │     │  to do next       │                │
│  └─────────────┘     └────────┬─────────┘                │
│                               │                           │
│                      ┌────────▼─────────┐                │
│                      │  Scope Proxy     │  ← Safety layer │
│                      │  Validates every │    Blocks out-  │
│                      │  command before  │    of-scope     │
│                      │  execution       │    actions      │
│                      └────────┬─────────┘                │
│                               │                           │
│                      ┌────────▼─────────┐                │
│                      │  Kali MCP Server │  ← Runs the    │
│                      │  nmap, curl,     │    actual       │
│                      │  smbclient, ...  │    commands     │
│                      └──────────────────┘                │
│                                                           │
│  ┌──────────────────┐  ┌──────────────────┐              │
│  │  Web Dashboard   │  │  SQLite DB       │              │
│  │  (:8888)         │  │  Hosts, vulns,   │              │
│  │  Monitor & steer │  │  creds, commands │              │
│  └──────────────────┘  └──────────────────┘              │
└──────────────────────────────────────────────────────────┘

For the full system design, see docs/ARCHITECTURE.md.

Features

  • Fully autonomous — no human in the loop during operation
  • 100% local inference — AI runs on the phone's GPU, no cloud needed
  • Scope-enforced — two-layer defense prevents out-of-scope actions
  • Stealth-first — slow scan rates, host rotation, cover traffic, nmap -T2 only
  • 27 exploit playbooks — multi-step attack chains that execute automatically
  • 24,956-entry CVE database — version-aware vulnerability matching
  • Web dashboard — real-time monitoring, host management, C2 controls
  • WiFi breach mode — autonomous WPA2 cracking with USB adapter (Pwnagotchi-inspired)
  • Passive discovery — background capture of mDNS/NBNS/DHCP/ARP broadcasts
  • Multi-network — data isolated per network, survives DHCP changes via MAC-keyed hosts
  • Self-healing — garbage detection, context reset, watchdogs, stuck detection
  • Training capture — logs successful interactions for future model fine-tuning
  • Report generation — downloadable pentest report with vulns, exploit chains, remediation

See docs/FEATURES.md for the complete feature reference.

Hardware

Required

  • Android phone with Kali NetHunter (tested on OnePlus 8, Snapdragon 865)
  • Root access via Magisk
  • 12GB+ RAM (model uses ~1.3GB, Android uses ~4GB, rest for tools)

Optional

  • USB WiFi adapter for offline WiFi breach mode (Ralink RT3572 recommended)
  • Custom kernel with MAC80211 for monitor mode (build guide)
  • NVIDIA AGX for offloading to a larger model over Tailscale

GPU Performance

All inference via OpenCL on Adreno 650 GPU:

ModelQuantizationPrompt SpeedGeneration Speed
LFM2.5-1.2B-Instruct-Heretic (production)Q8_0115 tok/s13 tok/s
Qwen3.5-0.8BQ8_030.5 tok/s6.3 tok/s
Qwen3.5-4BQ4_010.1 tok/s2.0 tok/s

Note: Android throttles the GPU on battery power (6x slowdown). Nightcrawler includes a GPU governor daemon that forces max performance and auto-throttles at ≤15% battery.

Quick Start

# 1. Install (inside Kali NetHunter chroot)
bash INSTALL.sh

# 2. Wait for llama-server to start (~5 min after boot)
curl -s http://127.0.0.1:8080/health  # Should return {"status":"ok"}

# 3. Start all services
bash scripts/run-36h.sh

# 4. Open the web dashboard (from any device on your Tailscale network)
# https://<your-tailscale-hostname>:8888

Dry Run (no real commands executed)

NC_DRY_RUN=1 python3 main.py

This uses a mock Kali server so you can test the agent loop without executing real network commands.

Manual Start (if not using tmux launcher)

kali-server-mcp --port 5000 &
python3 scope_proxy.py --config config.yaml --port 8800 --upstream http://127.0.0.1:5000 &
bash scripts/webui-daemon.sh start
python3 main.py &

Configuration

Edit config.yaml before deployment:

mission:
  id: "CLIENT-YYYY-XXX"           # Your engagement ID
  scope:
    networks: ["auto"]             # "auto" = detect from wlan0 at startup
    excluded_hosts: ["auto"]       # "auto" = gateway + self IP
    excluded_ports: [502, 503]     # SCADA/ICS ports to never touch
  authorization: "ROE-YYYY-XXX.pdf"
  max_runtime_hours: 0             # 0 = no limit

model:
  local:
    ctx_size: 8192
    port: 8080
Download Tool