Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ARES — Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault, and multi-format reporting. | Kitploit
Tools/GitHubGitHub/mafifrizi/ares
Defensive ToolsPenetration Testing FrameworksExploit FrameworksVulnerability AnalysisPost-ExploitationCloud SecurityCommand and ControlRed Teaming
GitHubmafifrizi/ares

ARES

Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault, and multi-format reporting.

View Repository
281161 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
ARES Logo

ARES™

Autonomous Red Team Engagement & Continuous Security Validation Platform

The open-core platform empowering enterprise red teams, MSSPs, and security operations centers to execute targeted offensive engagements, discover deterministic attack paths, and continuously validate defensive posture with zero collateral risk.


Version Python FastAPI React MITRE Security License Unit Suite


Platform Showcase • Why ARES? • Competitive Matrix • Architecture • MITRE Matrix • Quickstart • Zero-Trust Security • Documentation


⚡ Executive Summary

Traditional penetration testing is fundamentally flawed: it is expensive, episodic, point-in-time, and leaves organizations blind to newly introduced misconfigurations and emerging adversary tradecraft. Meanwhile, automated vulnerability scanners overwhelm SOC teams with thousands of hypothetical CVEs without demonstrating exploitability or multi-stage lateral attack paths.

ARES bridges this gap. Built from the ground up for modern enterprise infrastructure, ARES delivers an autonomous, goal-directed red team engagement platform that models real-world threat actors. By combining hard kernel-level scope firewalls, adaptive OPSEC noise profiling, an interactive directed acyclic graph (DAG) attack solver, and 60+ weaponized techniques mapped to MITRE ATT&CK, ARES allows security teams to prove vulnerability exploitability, locate shortest compromise paths to Active Directory Crown Jewels, and generate executive-ready deliverables with zero operational downtime.


🎯 Why Enterprises Choose ARES

root@kitploit:~
                                    THE ARES ADVANTAGE
 ┌─────────────────────────┐   ┌─────────────────────────┐   ┌─────────────────────────┐
 │   STRICT SCOPE ENCLAVE  │   │   AUTONOMOUS DAG ENGINE │   │ ZERO-TRUST ARCHITECTURE │
 │ Hard kernel CIDR egress │   │ Computes shortest paths │   │ Memory-only JWT tokens, │
 │ whitelisting prevents   │───│ to Domain Admins & Crown│───│ AES-256 encrypted vault,│
 │ any collateral impact.  │   │ Jewels deterministically│   │ strict HMAC-CSRF checks.│
 └─────────────────────────┘   └─────────────────────────┘   └─────────────────────────┘
                                            │
                                            ▼
                               ┌─────────────────────────┐
                               │ INSTANT EXECUTIVE SUITE │
                               │ Branded PDF, HTML, JSON │
                               │ deliverables with zero  │
                               │ native GTK dependencies │
                               └─────────────────────────┘

Core Value Pillars

  1. 🛡️ Zero-Collateral Scope Governance: Every campaign runs inside an isolated cryptographic boundary. Hard target IP and CIDR validations at the network socket layer guarantee that no packet ever touches out-of-scope infrastructure.
  2. 🧠 Autonomous Goal-Directed Planning: Operators set high-level objectives (e.g. domain_admin, full_compromise, cloud_audit), and the ARES decision engine autonomously synthesizes multi-stage execution paths using graph heuristics and optional LLM agents (Claude / OpenAI / local Ollama).
  3. 🕸️ Multi-Vector Attack Graph (DAG): Ingest BloodHound collections or map active domain sessions in real time. The built-in graph engine calculates shortest attack paths, highlights chokepoints, and simulates lateral pivot feasibility.
  4. 🔐 Defense-in-Depth Security Model: Engineered for zero-trust environments. Database-authoritative sessions, memory-only short-lived JWT access tokens, HttpOnly rotating refresh credentials, and AES-256-GCM encrypted local vaults protect harvested hashes and sensitive client evidence.
  5. 📑 Automated Deliverables Pipeline: One-click generation of branded, audit-ready compliance deliverables in PDF, HTML, Markdown, and JSON formats. Features automated headless browser PDF rendering on Windows/Linux without external GTK dependencies.

📊 Market Comparison Matrix


🖥️ Platform Showcase & Control Surfaces

The ARES Platform features a high-performance, responsive operator dashboard engineered with dark-tech aesthetics, low cognitive load, and audited operational control.

root@kitploit:~
# Launch local development environment
.\.venv\Scripts\ares.exe dashboard dev --no-reload

1. 🛡️ Operator Enclave & Zero-Trust Gateway

Autonomous entry barrier designed specifically for authorized offensive operators and security personnel.

ARES Operator Enclave & Zero-Trust Authentication Gateway

ARES Operator Enclave — Sign In button erupts with crimson plasma fire on hover, click, and Enter key. Dynamic Architectural Grid canvas, system environment specifications, and ARES Cyber Dragon mascot on the right panel.

  • The Problem Solved: Eliminates unauthorized operator access, token replay attacks, and token leakage to local browser storage.
  • Key Capabilities:
    • Crimson Fire Signature Interaction: Real-time HTML5 Canvas particle fire system envelops the Sign In button on hover (continuous), click (burst), and Enter key (burst without pointer) — physics-based particles with buoyancy, turbulence, and radial glow using requestAnimationFrame.
    • ARES Cyber Dragon Ambient Mascot: Integrated brand mascot watermark on the telemetry pane with calibrated opacity and crimson back-glow, harmonized with frosted glass environment specs.
    • Live Dynamic Architectural Grid Canvas: Low-overhead hardware-accelerated 60 FPS HTML5 canvas with real-time traveling data pulses and cursor proximity illumination.
    • Memory-Only Token Isolation: Short-lived JWTs reside strictly in memory; refresh credentials use host-only, HttpOnly cookies with one-time rotation.
    • Enterprise Multi-Tenant SSO (SAML 2.0 & OIDC): SP-initiated federated authentication with Okta, Azure AD, and Google Workspace. Features App-level Fernet credential encryption, one-time replay protection (InResponseTo/nonce), JIT role mapping, and strict local password lockout for federated identities. (See SSO Setup Guide).
    • HMAC Double-Submit CSRF Protection: Constant-time verification on all state-mutating requests (X-ARES-CSRF).
    • Cryptographic Brute-Force Shield: Enforces exponential backoff and IP-based rate limiting on authentication attempts.

2. 📊 Executive Command Center & Telemetry

Real-time operational command console providing instant posture visibility across active campaigns.

ARES Executive Command Center & Telemetry

Executive Command Center displaying real-time telemetry, confirmed findings by severity, and operational health.


ARES Executive Overview Standby & Fresh-Install Hero

Tactical Zero-State Overview — Clean onboarding hero with instant readiness strip and initialization actions when running zero active campaigns.

  • The Problem Solved: Aggregates scattered offensive metrics into a single real-time operational pane without requiring manual status queries.
  • Key Capabilities:
    • Operational Design System: Engineered with high-density visual hierarchy (inspired by Grafana, Linear, and Sentry) — featuring subtle left-accented contextual panels (panel-subtle), dynamic reactive topbar health indicators, and distinct dashed progress tracks for uninitialized metric baselines.
    • Actionable Engagement Insights: Replaces redundant raw counts with contextual security posture insights:
      • Engagement Posture: Clear state delineation (Staged, Executing, or Standby) distinguishing scoped targets from executing campaigns.
      • Execution Health: Real-time monitor of pipeline anomalies, module execution failures, and enclave stability.
      • Attack Surface: Live tracking of discovered hosts, credential pivots, and network penetration depth.
    • Telemetry & Pipeline Ingestion: Real-time worker pool throughput, P95 task duration, and live event ingestion indicators.
    • Tactical Fresh-Install Hero: Automatic empty-state fallback with a centered initialization CTA and minimal readiness strip when starting with zero campaigns.

3. 🎯 Scoped Campaign & Target Boundary Management

Zero-collateral target governance enforcing hard CIDR whitelist boundaries and encrypted evidence isolation.

ARES Scoped Campaign & Target Boundary Management

Campaign Management interface showing target scopes, CIDR boundaries, noise controls, and encrypted credential vault.

  • The Problem Solved: Prevents catastrophic out-of-scope scanning and eliminates unencrypted credential files on operator laptops.
  • Key Capabilities:
    • Persistent Operator Guidance: Persistent <label> definitions across all campaign pickers and parameter inputs, preventing operator ambiguity during rapid engagements.
    • Hard CIDR Whitelists: Network-level boundary enforcement. The engine intercepts and drops any request targeting unapproved IP addresses or subnets.
    • Noise Profiles & Jitter: Configure engagement throttle levels (Stealth, Normal, Aggressive) with randomized delay distributions.
    • AES-256 Encrypted Enclave Vault: Harvested NTLM hashes, Kerberos tickets, and service credentials are encrypted at rest with AES-256-GCM.
    • Clean Teardown Workflows: Single-click campaign deletion that securely cleans up all associated database rows, graph vertices, and temporary artifacts.

4. ⚡ Modular Adversary Orchestration (60+ Modules)

Extensive catalog of weaponized adversary techniques aligned with the MITRE ATT&CK enterprise matrix.

ARES Modular Adversary Orchestration

Module Catalog with MITRE ATT&CK categorization, dynamic parameter generation, and dry-run safety modes.

  • The Problem Solved: Replaces unvalidated, unreliable GitHub scripts with typed, reproducible, and auditable adversary modules.
  • Key Capabilities:
    • Comprehensive Vector Coverage: 60+ modular techniques covering Active Directory (ad.kerberoast, ad.adcs, ad.enum_users), Windows (windows.uac_bypass), Linux, Cloud (AWS, Azure, GCP), and Network infrastructure.
    • Streamlined Execution Panel: Clean execution view with persistent field labels, demoted low-weight dependency hints, and focused on-submit validation replacing intrusive default warning cards.
    • Dynamic Typed Schemas: UI forms are generated dynamically from Python Pydantic models with strict validation.
    • Dry-Run Safety Engine: Validate target responsiveness, parameters, and expected outcome before transmitting offensive traffic.
    • Role-Gated Execution: Operator and Team Lead permissions required for execution; sensitive high-noise modules require explicit confirmation.

5. 🕸️ Multi-Vector Attack Graph & Objective Replay

Interactive directed acyclic graph (DAG) solver visualizing enterprise attack paths and privilege escalation chains.

ARES Multi-Vector Attack Graph & Objective Replay

Multi-Vector Attack Graph with automated luminous white patch cables, left-to-right hierarchy (Domain Controller → Findings → Hosts), and real-time safe metadata inspection.

  • The Problem Solved: Translates raw vulnerability data into actionable, visual compromise paths that executives and engineers can understand immediately.
  • Key Capabilities:
    • Automated Cyber Patch Cable Routing: Real-time rendering of automated luminous white cables (#ffffff) connecting Domain Controllers, security findings, and discovered hosts without manual dragging.
    • Deterministic Left-to-Right Hierarchy: Clean, collision-free column layout originating from the Domain Controller (DC01) on the left, through active security findings, to target member hosts.
    • Shortest Path Algorithms: Deterministically calculates the fewest hops required to compromise Domain Controllers or cloud root credentials.
    • Native BloodHound / SharpHound Ingest: Directly import BloodHound JSON archives into the ARES graph engine for unified analysis.
    • Interactive Entity Inspection: Explore relationships between users, groups, computers, ACLs, and active Kerberos sessions with fluid navigation and real-time safe detail inspector.
    • Objective Replay: Re-simulate historical attack chains to verify defensive patch efficacy.

6. 📑 Automated Report Engine & Evidence Library

Instant deliverable generation producing branded, audit-ready compliance reports across multiple enterprise formats (Executive PDF, Technical Markdown, Defect CSV).

ARES Automated Report Engine & Evidence Library

Report Engine and Artifact Library supporting multi-format exports with synchronized real-time lifecycle management.

  • The Problem Solved: Eliminates the 40+ hours typically spent manually writing, formatting, and redacting pentest reports.
  • Key Capabilities:
    • Structured Generation Grid: Aligned multi-column layout with persistent <label> elements (Target Campaign, Export Format) and clean inline validation error feedback.
    • Multi-Format Export: One-click generation of PDF, HTML, Markdown, and JSON deliverables.
    • Automated Headless PDF Engine: Integrated fallback using Microsoft Edge / Chromium headless mode for clean PDF export without complex GTK dependencies on Windows.
    • Automated Evidence Redaction: Automatically redacts sensitive raw passwords and private keys in customer deliverables while retaining audit proofs.
    • Synchronized Report Library: Authenticated artifact repository with instant downloads, per-report deletion, and real-time UI state synchronization.

7. 🧠 Autonomous Strategy & AI Planner

Goal-directed autonomous engine that plans, prioritizes, and executes complex attack chains while respecting OPSEC limits.

ARES Autonomous Strategy & AI Planner

Autonomous Strategy Console for goal-based campaign planning and adaptive containment governance.

  • The Problem Solved: Coordinates multi-module attack chains autonomously without requiring constant manual operator intervention.
  • Key Capabilities:
    • Dynamic Engine Verification: Real-time asynchronous healthchecks against local Ollama daemons (GET /api/tags) with sub-second timeouts and TTL caching, paired with dynamic server-side cloud key verification (Claude, OpenAI).
    • Clean Operator-Centric Design: Persistent field labels (Target Campaign, Strategic Objective, AI Planning Engine, Explicit Authorizations), human-readable goal descriptions, and complete elimination of server environment variable leakage in UI labels.
    • Focused On-Submit Validation: Warning boxes removed from default page render; validation errors display inline beneath target fields only upon execution attempt.
    • Adaptive Containment Governor: Continuously evaluates defensive telemetry and noise thresholds, automatically slowing down or aborting aggressive actions when detection risk peaks.

8. 🔍 Attack Graph Entity Deep-Dive & Node Inspector

In-depth Active Directory entity telemetry, relationship inspection, and real-time safe detail auditing directly inside the canvas.

ARES Attack Graph Entity Deep-Dive & Node Inspector

Interactive Safe Detail Drawer displaying Domain Controller (DC01 10.10.10.2) telemetry, active compromise levels, open attack surface ports (53, 88, 135, 139, 389, 445, 636, 3268, 3389), and asset ownership states.

  • The Problem Solved: Eliminates context-switching between graph visualizers and CLI reconnaissance tools by providing live node telemetry in an interactive sidebar.
  • Key Capabilities:
    • Entity Attribute Inspection: Instantly examine IP address, hostname, OS telemetry, compromise levels, and domain controller flags (is_dc) upon selecting any graph node.
    • Attack Surface Port Mapping: Real-time visibility into open infrastructure ports (DNS 53, Kerberos 88, RPC 135, NetBIOS 139, LDAP 389, SMB 445, LDAPS 636, Global Catalog 3268, RDP 3389).
    • Safe Detail Auditing: Audited slide-out drawer providing granular telemetry without cluttering the main DAG canvas, complete with quick dismissal.

9. 🔗 Multi-Stage Adversary Execution Chains

Deterministic, multi-step kill chains orchestrating reconnaissance, credential harvesting, and lateral movement in sequence.

ARES Multi-Stage Adversary Execution Chains

Automated execution chains including AD Kerberos Exposure Chain and AD Domain Enumeration Chain.

  • The Problem Solved: Replaces manual step-by-step tool invocation with pre-verified, coordinated attack chains that pass outputs automatically to downstream modules.
  • Key Capabilities:
    • Pre-Built Attack Sequences: Out-of-the-box chains for Kerberos exposure (asreproast -> kerberoast -> hashcat), domain enumeration, and cloud privilege escalation.
    • Dynamic Context Passing: Credentials and hashes harvested in step 1 are automatically populated into target arguments for subsequent steps.
    • Integrated OPSEC Budgeting: Tracks cumulative noise and detection likelihood across the entire chain before initiating execution.

10. 🛡️ EDR / OPSEC Evasion & Bypass Knowledge Base

Empirical tracking of evasion efficacy across enterprise endpoint detection and response (EDR) platforms.

ARES EDR and OPSEC Evasion Matrix

Bypass Knowledge Base tracking technique success rates across CrowdStrike Falcon, SentinelOne, and Microsoft Defender.

  • The Problem Solved: Prevents offensive operators from blindly deploying burned or detected payloads against monitored customer infrastructure.
  • Key Capabilities:
    • Empirical Success Rates: Historical success rates categorized by specific evasion techniques (AMSI patching, syscall unhooking, process hollowing) and EDR vendor.
    • Cross-Session Evasion Memory: Engagement outcomes update a unified knowledge base, warning operators before they execute techniques with low success probabilities.
    • Defensive Jitter Controls: Granular delay distributions and packet spacing to evade behavioral heuristics and SIEM correlation rules.

11. 🔐 Zero-Trust Security Governance & Audit Trail

Audited multi-role access control, cryptographic API key lifecycle, and continuous platform integrity verification.

ARES Zero-Trust Security Governance

Operator profile management, scoped API key provisioning, and automated system security audits.

  • The Problem Solved: Guarantees non-repudiation, role-based boundary separation, and compliance assurance for offensive security operations.
  • Key Capabilities:
    • Role-Based Access Control (RBAC): Strictly enforced permission tiers (Team Lead, Operator, Recon, Reporter) governing module execution and evidence viewing.
    • Scoped API Keys: Cryptographically generated bearer tokens with configurable expiration and fine-grained permissions for CI/CD integration.
    • Live Audit Trail: Continuous append-only logging of every operator action, target scan, and credential retrieval for post-engagement review.

12. 📡 Live Operations & Real-Time Event Stream

High-frequency WebSocket event bus streaming operational telemetry, module output, and pipeline status.

ARES Live Operations Stream

Live operational event console with buffered telemetry and high-throughput WebSocket streaming.

  • The Problem Solved: Gives engagement commanders instant, unified situational awareness of all distributed agents and background tasks.
  • Key Capabilities:
    • Sub-Second Event Delivery: Asynchronous WebSocket bus streaming live stdout/stderr, module completion events, and defensive alerts.
    • Buffered Log Telemetry: Reconnection-resilient event buffering ensuring zero lost log lines during network fluctuations.
    • Multi-Operator Collaboration: Simultaneous operators see shared campaign execution events in real time.

13. 📋 Enterprise Playbooks & Campaign Templates

Standardized engagement architectures for recurring red team exercises, compliance audits, and purple team drills.

ARES Enterprise Campaign Templates

Built-in engagement templates including Internal Pentest, AD Full Compromise, Cloud Assessment, and Assumed Breach.

  • The Problem Solved: Eliminates manual scope configuration for standardized assessments and ensures consistent testing methodology across enterprise engagements.
  • Key Capabilities:
    • Turnkey Playbooks: Ready-to-deploy campaign templates with pre-configured target profiles, module sets, and report requirements.
    • Custom Template Authoring: Export successful custom engagements as reusable templates for internal teams and MSSP clients.
    • Safety Pre-Flights: Automated scope and permission validation before any template-based campaign goes live.

14. 🔌 Interactive OpenAPI 3.1 & Developer Integration

Fully documented, interactive REST API surface for custom tooling, SOC orchestration, and CI/CD pipeline integration.

ARES Interactive OpenAPI Documentation

Interactive Swagger UI documentation exposing 70+ operational endpoints for enterprise automation.

  • The Problem Solved: Enables seamless programmatic integration with existing enterprise SOAR platforms, custom reporting pipelines, and CI/CD security gates.
  • Key Capabilities:
    • 70+ Documented Endpoints: Complete REST coverage across authentication, campaigns, module execution, attack graphs, and deliverables.
    • OpenAPI 3.1 Conformance: Strictly validated request/response schemas generated directly from Python Pydantic models.
    • Interactive Sandbox: In-browser API testing with Bearer token authentication and CSRF token support.

🎛️ Control Surfaces Breakdown


🏗️ System Architecture & Data Pipeline

ARES follows a strict defense-in-depth architecture separating presentation, execution orchestration, security governance, and persistent cryptographic storage:

root@kitploit:~
flowchart TB
    subgraph Client["Presentation Layer (Operator Enclave)"]
        UI["React 19 Dashboard<br>(Vite + TypeScript)"]
        Mesh["Dynamic Architectural Grid<br>(Canvas 2D Engine)"]
        WSClient["WebSocket Client<br>(Real-Time Telemetry Stream)"]
    end

    subgraph Gateway["Zero-Trust Security Gateway"]
        FastAPI["FastAPI Async Engine<br>(Uvicorn Backend)"]
        AuthGuard["Auth & Session Guard<br>(Memory-Only JWT + HttpOnly Refresh)"]
        CSRF["HMAC Double-Submit CSRF<br>(X-ARES-CSRF Validation)"]
        RateLimit["Rate Limiting & Brute-Force Shield"]
    end

    subgraph Core["ARES Core Engine & Governance"]
        ScopeFirewall["Scope Egress Firewall<br>(Strict CIDR & IP Whitelist)"]
        Governor["OPSEC Noise Governor<br>(Adaptive Jitter & Throttling)"]
        Orchestrator["Module Execution Orchestrator<br>(Worker Thread Pool)"]
        AutoPlanner["Autonomous Strategy Engine<br>(DAG Heuristics / AI Planner)"]
    end

    subgraph Storage["Cryptographic Persistence Layer"]
        DB[(SQLite / PostgreSQL<br>Alembic Versioned)]
        Vault[(AES-256-GCM Vault<br>Encrypted Credentials & Hashes)]
        GraphEngine["Attack Graph DAG Engine<br>(BloodHound Ingest & Shortest Path)"]
    end

    subgraph Deliverables["Reporting Pipeline"]
        PDFGen["Headless Chromium / Edge Engine<br>(Automated PDF Generation)"]
        Artifacts["Evidence Library<br>(HTML, Markdown, JSON)"]
    end

    UI -->|HTTPS / REST| AuthGuard
    WSClient -->|WSS / Ticket Barrier| AuthGuard
    AuthGuard --> CSRF --> RateLimit --> FastAPI
    FastAPI --> ScopeFirewall
    ScopeFirewall --> Orchestrator
    Orchestrator --> Governor
    Orchestrator --> AutoPlanner
    Orchestrator --> Storage
    Storage --> GraphEngine
    FastAPI --> Deliverables

⚔️ Adversary Techniques & MITRE ATT&CK Matrix

ARES implements 60+ modular adversary techniques natively mapped to the MITRE ATT&CK Enterprise Framework:

root@kitploit:~
┌──────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│                                         MITRE ATT&CK MATRIX COVERAGE                                             │
├─────────────────────┬─────────────────────┬─────────────────────┬─────────────────────┬──────────────────────────┤
│ DISCOVERY           │ CREDENTIAL ACCESS   │ LATERAL MOVEMENT    │ PRIVILEGE ESCALATION│ DEFENSE EVASION / CLOUD  │
├─────────────────────┼─────────────────────┼─────────────────────┼─────────────────────┼──────────────────────────┤
│ • T1087 User Enum   │ • T1558.003 Kerberoast│ • T1021.002 SMB/RPC │ • T1548.002 UAC Byps│ • T1070 Indicator Removal│
│ • T1069 Group Enum  │ • T1558.004 AS-REP  │ • T1021.006 WinRM   │ • T1068 Token Privs │ • T1562 Impair Defenses  │
│ • T1046 Port/Net    │ • T1003 LSASS Dump  │ • T1550 Use Ticket  │ • T1053 Scheduled   │ • T1078 Cloud IAM Enum   │
│ • T1018 Host Disc   │ • T1649 ADCS ESC1-8 │ • T1071 App Layer   │ • T1055 Injection   │ • T1580 Cloud Discovery  │
│ • T1082 System Info │ • T1110 Pass Spray  │ • T1021.001 RDP     │ • T1134 Access Token│ • T1526 Cloud Hierarchy  │
└─────────────────────┴─────────────────────┴─────────────────────┴─────────────────────┴──────────────────────────┘
  • Active Directory Lab Suites: Full SPN discovery, Kerberoasting (ad.kerberoast), AS-REP Roasting, ADCS Certificate Template abuse (ESC1 through ESC8), DCSync account replication, and BloodHound data generation.
  • Endpoint Posture Checkers: Windows UAC Bypass methods, registry key persistence inspection, Linux container breakouts, and Sudo privilege enumeration.
  • Cloud Control Plane: Multi-cloud identity auditing across AWS IAM, Azure Active Directory / Entra ID role assignments, and GCP IAM bindings.

🚀 Quickstart: Up and Running in 60 Seconds

Prerequisites

  • Python: 3.11 or 3.12 (Python 3.12 recommended for Windows).
  • Node.js: v18+ (tested on Node v20 LTS).
  • OS: Windows 11/10 (PowerShell), Linux (Ubuntu/Debian/Kali), or macOS.

Fast Path (PowerShell on Windows)

root@kitploit:~
# 1. Clone the repository
git clone https://github.com/Mafifrizi/ARES.git
Set-Location .\ARES

# 2. Setup isolated Python virtual environment
py -3.12 -m venv .venv
.\.venv\Scripts\python.exe -m pip install -U pip
.\.venv\Scripts\python.exe -m pip install -e ".[dev,pdf]"

# 3. Install frontend dependencies
Set-Location frontend
& "C:\Program Files\nodejs\npm.cmd" ci
Set-Location ..

# 4. Configure local Edge PDF rendering engine & verify doctor status
$env:ARES_PDF_BROWSER = "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"
.\.venv\Scripts\ares.exe doctor --pdf-smoke

# 5. Launch development server (Frontend + Backend proxy)
.\.venv\Scripts\ares.exe dashboard dev --no-reload

Open your browser to http://127.0.0.1:5173/dashboard/.

  • Initial Operator: admin
  • Initial Password: Configured via ARES_DEFAULT_ADMIN_PASSWORD in .env (default: Admin123456!)

🔐 Enterprise Security Model & Compliance

ARES was designed for environments with the most stringent compliance and confidentiality requirements:

Defense-in-Depth Authentication

  • Memory-Only Access Tokens: Short-lived JWTs (15-minute lifespan) exist purely within in-memory React state and are never written to localStorage or sessionStorage.
  • Rotating Refresh Family: Long-lived refresh credentials are bound to strict, host-only, HttpOnly cookies (ares_refresh) with one-time rotation and automatic reuse revocation.
  • HMAC CSRF Barrier: State-changing endpoints mandate valid X-ARES-CSRF headers matched against cryptographically secure cookie tokens.

Role-Based Access Control (RBAC)

ARES enforces strict RBAC permissions across all API endpoints, background jobs, and UI surfaces:

Role Provisioning & Anti-Privilege Escalation Guarantees

  • Authoritative Database Identity: Unlike systems that blindly trust client-side JWT role claims, ARES resolves user identity and role directly from the live database on every request (row = await db.resolve_access_token_principal(...)). Tampered JWT claims are mathematically discarded.
  • Strict Role Gating at Account Creation: New user roles are assigned exclusively by a team_lead via POST /auth/register (guarded by require_team_lead()) or automatically mapped from enterprise Identity Providers during SP-initiated SAML/OIDC SSO.
  • Role Immutability: Role assignments are immutable post-creation. No public endpoint exists to alter user roles (PUT /users/{id} does not exist), eliminating horizontal and vertical privilege escalation vectors (e.g., recon escalating to team_lead or reporter running offensive modules).
  • Audited User Inventory: The dashboard Security console provides a transparent inventory of all registered identities and active sessions for engagement accountability.

🔌 ARES MCP Gateway & Product-Grade CLI

ARES provides a production-grade Model Context Protocol (MCP) Gateway that enables modern AI coding assistants (Cursor IDE, Claude Desktop, Windsurf, VS Code Cline, Zed, Open-WebUI, LibreChat) to interact with the ARES purple-team offensive platform safely and under strict governance.

ARES MCP Two-Pane Terminal Monitor

ARES MCP Two-Pane Split Terminal Monitor (OpenClaw style) with real-time tool telemetry, live scope inspection, and 1-key token authorization.

Unlike basic MCP servers that expose raw endpoints to LLMs without guardrails, ARES enforces strict Pre-Flight Scope Invariance (ScopeGuard), Anti-Prompt-Injection Taint Isolation, and Single-Use 60-second HMAC Confirmation Tokens before any live offensive action can execute.

🚀 Where Do I Start First? (Step-by-Step Onboarding)

For operators or developers connecting Cursor, Claude Desktop, or Windsurf to ARES:

  1. Verify Subsystem Readiness (doctor): Ensure all core subsystems (Protocol Engine, 9 Tools, 3 Resources, 3 Prompts, 62 Modules, Security Gates) report PASS:

    root@kitploit:~
    .\mcp.bat doctor
    
  2. 1-Click AI Client Setup (No Manual JSON Editing): Automatically configure your preferred IDE with a single command:

    root@kitploit:~
    # For Cursor IDE:
    .\mcp.bat setup --client cursor
    
    # For Claude Desktop:
    .\mcp.bat setup --client claude
    
    # For Windsurf:
    .\mcp.bat setup --client windsurf
    
    # For VS Code (Cline):
    .\mcp.bat setup --client cline
    

    This writes your active Python virtual environment path directly into the client config file (e.g. .cursor/mcp.json).

  3. Reload Window in Cursor IDE:

    • In Cursor, press Ctrl + Shift + P.
    • Select Developer: Reload Window.
    • Open Settings (Ctrl + ,) → Features → MCP Servers. The ares server will show a green dot ().

For in-depth architecture, the 7 security invariants, CLI scriptability (--json), POSIX exit codes, and operational tool schemas, see ARES MCP Gateway & Product-Grade CLI Specification.


🛠️ Extensible Developer SDK (Next-Gen Autonomous Architecture)

ARES provides a first-class, type-safe Python SDK (ares.sdk) to build custom adversary modules, simulate techniques in isolated test harnesses, and automate engagements programmatically:

1. Type-Safe Module Authoring (Generic BaseModule[P, R] & @ares_module)

Declare validated parameter schemas with Pydantic v2 and write modules with full IDE autocomplete:

root@kitploit:~
from ares.sdk import (
    BaseModule, ExecutionContext, ModuleResult,
    ModuleParams, param, SecretParam,
    OpsecLevel, Severity, ares_module,
)

class KerberoastParams(ModuleParams):
    dc: str = param("Target Domain Controller IP or FQDN", min_length=3)
    domain: str = param("AD DNS domain name, e.g. CORP.LOCAL", min_length=3)
    password: SecretParam = param("Domain user password", secret=True, required=False)

class CustomKerberoastModule(BaseModule[KerberoastParams, ModuleResult]):
    MODULE_ID = "custom.ad.kerberoast"
    MODULE_NAME = "Custom Kerberoasting"
    MODULE_CATEGORY = "ad"
    OPSEC_LEVEL = OpsecLevel.LOW
    MITRE_TECHNIQUES = ["T1558.003"]
    PARAMS_MODEL = KerberoastParams

    async def execute(self, ctx: ExecutionContext[KerberoastParams]) -> ModuleResult:
        # ctx.params provides full static typing and runtime validation
        await self.before_request(ctx.params.dc)

        # Emit findings using fluent context helpers
        finding = ctx.emit_finding(
            title=f"Kerberoastable SPN Captured on {ctx.params.dc}",
            severity=Severity.HIGH,
            mitre_technique="T1558.003",
        )
        return ModuleResult(status="success", findings=[finding], module_id=self.MODULE_ID)

2. Isolated Testing & Simulation (ModuleTestHarness)

Unit test custom techniques locally with mock scope guards, synthetic credential vaults, and fluent assertion matchers:

root@kitploit:~
from ares.sdk import ModuleTestHarness, Severity

async def test_module():
    harness = ModuleTestHarness(CustomKerberoastModule)
    result = await harness.simulate(params={"dc": "10.0.0.10", "domain": "LAB.LOCAL"})
    result.assert_success()
    result.assert_finding(severity=Severity.HIGH, mitre="T1558.003")

3. Programmatic Automation (AresClient)

Automate engagements, dispatch modules, and stream real-time WebSocket telemetry via Python scripts or CI/CD pipelines:

root@kitploit:~
from ares.sdk import AresClient

async with AresClient(base_url="http://127.0.0.1:8000", api_key="ares_key_...") as ares:
    campaign = await ares.campaigns.create(name="Op-Titan", scope=["10.0.0.0/24"])
    job = await ares.modules.run("ad.kerberoast", target="dc01.corp.local", campaign_id=campaign["id"])
    findings = await ares.campaigns.findings(campaign["id"])

See docs/module_sdk.md and docs/module-development.md for full developer documentation, architecture specifications, and examples.


📚 Documentation Sitemap

Comprehensive documentation is available in the docs/ directory:

  • Documentation Portal & Subsystem Index
  • Quickstart Engagement Guide
  • Next-Gen Module SDK Specification (v2)
  • ARES MCP Server & Product-Grade CLI Specification
  • Step-by-Step Module Development Guide
  • Dashboard Surface-by-Surface Manual
  • Adversary Module Catalog & Schemas
  • API Endpoint Reference & Payloads
  • Enterprise SSO Integration Guide (SAML 2.0 / OIDC)
  • Enterprise Security & Threat Model
  • Validation Lab & Test Harness

⚖️ Responsible Use & Legal Disclaimer

[!IMPORTANT] ARES is a dual-use software framework designed exclusively for authorized cybersecurity research, internal enterprise resilience validation, and professional red-team engagements with explicit written permission.

  • Do NOT execute ARES against any network, host, or cloud infrastructure without prior written authorization from the system owners.
  • Unauthorized system access or testing violates national and international cybercrime legislation (e.g. Computer Fraud and Abuse Act 18 U.S.C. § 1030).
  • The creators and maintainers of ARES assume no liability for misuse, damages, or regulatory violations caused by this software.

To report security vulnerabilities in ARES, please follow our Security Policy.


📄 License

ARES is distributed under the open-source MIT License.


ARES — Enterprise-Grade Autonomous Red Team Engagement System.
Continuous Security Validation. Zero Collateral Risk.

Download Tool
Operational CapabilityTraditional Manual PentestLegacy Vulnerability ScannersARES Autonomous Platform
Testing FrequencyAnnual / Semi-AnnualScheduled Daily / WeeklyContinuous / On-Demand
Exploitability ValidationManual & Labor Intensive❌ Theoretical CVE MatchingDeterministic Multi-Stage Proof
Multi-Hop Attack PathsManual Drawing❌ NoneReal-Time Interactive DAG
Scope Enclave & Egress FirewallOperator Discipline OnlyNetwork Firewalls OnlyHard Socket-Level CIDR Enforcement
Active Directory Lateral PathsSlow Script Execution❌ No Active PathsNative BloodHound & Kerberos Suite
Credential Security & StorageLoose Flat Files / CleartextVulnerability LogsAES-256-GCM Encrypted Vault
OPSEC & Telemetry ThrottlingManual Jitter ScriptsHigh Network NoiseAdaptive Noise Profiles & Governor
Delivery Time for Reports1–2 Weeks Post-EngagementRaw Data DumpsInstant Multi-Format Artifacts
Deployment FootprintExternal ConsultantsBulky Cloud AgentsAir-Gapped Local / Self-Hosted
SurfaceCore ResponsibilityAvailable Sub-TabsPrimary Operators
OverviewExecutive health, telemetry counters, finding severity metrics.Single PaneAll Stakeholders
CampaignsScope whitelisting, noise profiles, encrypted credential vault.List, Scope, FindingsTeam Lead, Operator
Modules60+ module catalog, parameter input forms, execution console.Catalog, Run Panel, ResultsOperator
ReportsDeliverable builder, evidence packages, Report Library lifecycle.Generate, LibraryOperator, Reporter
GraphDAG entity exploration, shortest attack paths, BloodHound ingest.Entities, Attack Paths, IngestOperator, Recon
TemplatesRepeatable engagement playbooks and multi-stage workflow plans.Templates, Plan BuilderTeam Lead, Operator
StrategyGoal-directed autonomous engine, AI planner integration.Objective, Active, ResultTeam Lead, Operator
SecurityOperator credentials, API key lifecycle, dependency audit checks.Account, API Keys, AuditTeam Lead
EDR/OPSECDefensive telemetry, bypass tracking, detection evasion rules.Knowledge Base, Report OutcomeOperator
LiveReal-time WebSocket event streams and buffered telemetry logs.Stream, BufferOperator
RoleAPI ValueOperational ScopeAdministrative Authority
Team Leadteam_leadComplete platform authority: campaign creation/deletion, user provisioning, security audits, high-noise module overrides.Full System Admin
OperatoroperatorDay-to-day operations: execute authorized modules, review findings, explore attack graph, generate reports. Cannot register users.Operational Tier
ReconreconRead-heavy reconnaissance: execute safe discovery and network fingerprinting modules. Execution of disruptive modules is blocked.Read-Heavy
ReporterreporterStakeholder review: read-only access to campaign analytics, findings, attack graphs, and generated deliverables. No execution rights.Read-Only Audit
Connected
  • Launch the Live Two-Pane Monitor (Optional Companion Window): In a dedicated terminal window, run the OpenClaw-style two-pane monitor to watch real-time AI tool invocations, scope checks, and approve tokens:

    root@kitploit:~
    .\mcp.bat monitor
    
    • Left Pane: Live stream of tool calls executed by the AI agent (ares_scope_check, ares_dry_run_module, ares_run_tool).
    • Right Pane: ScopeGuard CIDR boundaries, staged action diffs, and the Authorization Gateway.
    • Controls: Press A to approve a pending execution token, R to reject, C to clear stream, Q to quit.
  • Issue Your First Command to the AI Agent: Open Cursor Composer / Chat (Ctrl + I or Ctrl + L), and try this prompt:

    "Check active campaign status, verify scope for target 10.0.1.50, and stage a dry-run of module ad_kerberoast."