Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/mister-iks/pcybox-attackgraph
Defensive ToolsNetwork SecurityCTFPenetration TestingLearning & EducationRed TeamingLearning Paths & CoursesLabs & Practice
GitHubmister-iks/pcybox-attackgraph

pcybox-attackgraph

Open source browser lab to build a simulated infrastructure, watch an attack move through it, and check whether your defense works.

View Repository
38524 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Website
Share

PCYBOX AttackGraph logo

PCYBOX AttackGraph

Build. Attack. Defend. Understand.

An open source lab that runs entirely in your browser: build a simulated infrastructure, watch an attack move through it, and check whether your defense really works. Every step comes with the reason it worked, and every control says exactly which precondition it breaks.

Live demo · Français · Specification · How the engine works · Lab format · Contributing

An attack from the Internet reaches the customer database in 3 steps

With network segmentation, the same attack is contained at the web server, and the Why? panel explains the block

Why this project

Attack surface, lateral movement, segmentation, blast radius, defense in depth: these ideas are hard to grasp from static diagrams. PCYBOX AttackGraph turns them into something you can see and manipulate:

  • Visible: the attack moves on the map, step by step, with replay controls.
  • Explainable: the Why? panel lists the preconditions that held, the control that stopped a step, and the controls that could have stopped it, with one click to try them.
  • Causal: the Before / after view compares your architecture with the same lab without any control.
  • Honest: controls have no magic effect. MFA does not protect a service account; patching stops the entry but not an attacker already inside; a WAF (coming soon) stops injection but not every vulnerable component.
  • Accessible everywhere: no account, no server, no tracking. Works on modest devices, in several languages, with a keyboard and a screen reader (the Text view is a full equivalent of the map).

Simulation only. The lab never scans, contacts or attacks a real system. Techniques are described at a conceptual level, mapped to MITRE ATT&CK, without any exploitation procedure.

Try it

Open the live demo: nothing to install, no account. Or run it locally:

git clone https://github.com/Mister-iks/pcybox-attackgraph.git
cd pcybox-attackgraph
pnpm install
pnpm dev

Then open the URL printed in the terminal, click Run attack, switch Network segmentation on, and run again.

Keyboard: Space plays or pauses, arrow keys step through the attack, Home goes back to the start.

Build your own lab

Switch to Edit, then drag elements from the palette onto the map, connect them by dragging from the dot on the side of an element, and fill in services, weaknesses, stored credentials, identities, assets, controls and scenarios in the side panel. The Problems tab points out what is probably wrong (a flow to a port without service, a control that applies to nothing...). Undo and redo with Ctrl+Z and Ctrl+Y. Your lab is saved in the browser and can be exported, imported and shared by link.

What is in the app

  • Three templates: Web Application (flat network, leftover secrets), Small Office (shared local admin password, remote desktop open to the Internet) and Active Directory (domain admins logging on to workstations, admin tiering).
  • A lab editor: palette, connections by drag and drop, forms for every part of a lab, live problem detection, undo and redo, autosave.
  • A deterministic engine with 8 techniques and 6 controls (segmentation, secrets vault, MFA, patching, least privilege, credential protection).
  • Animated map, timeline with x1/x2/x4 replay, Why? panel, Before / after comparison, Text view.
  • Sharing by link (the whole lab travels in the URL fragment, nothing is stored on a server), export and import of .attackgraph.json files.
  • English and French, light and dark themes, reduced motion support.

See the roadmap for what comes next.

How it works

lab (.attackgraph.json) ──▶ validation ──▶ engine (web worker) ──▶ story of events ──▶ map, timeline, Why?

The engine saturates the attacker's capabilities round by round (footholds, credentials, data access). Each technique has preconditions and effects; each control breaks a precise precondition. Because rounds are breadth first, the story replayed for a reached target is one of its shortest derivations. Details in docs/engine.md.

Repository layout

apps/web/           web application (React, React Flow, Vite)
packages/engine/    simulation engine: pure TypeScript, no DOM, fully tested
packages/schema/    JSON Schema of the .attackgraph.json lab format
packages/i18n/      messages (English, French) shared by the app and the CLI
packages/cli/       attackgraph command line tool
content/templates/  ready-to-use labs (CC BY 4.0)
docs/               specification, engine and format documentation

Development

Requirements: Node.js 20 or later and pnpm.

pnpm install
pnpm dev             # start the app
pnpm test            # engine, schema and app unit tests
pnpm e2e             # end-to-end tests (Playwright, desktop and mobile)
pnpm verify          # everything the CI checks: text, types, tests, build, bundle budget

Command line

pnpm attackgraph validate content/templates
pnpm attackgraph list content/templates/active-directory.attackgraph.json
pnpm attackgraph simulate content/templates/active-directory.attackgraph.json --scenario phishing --enable tiering
pnpm attackgraph compare content/templates/web-application.attackgraph.json --enable segmentation --lang fr
pnpm attackgraph simulate <lab> --format markdown   # or json, for other tools

Performance budget: at most 250 kB of initial JavaScript (gzip). The CI fails above it.

Roadmap

VersionFocus
v0.1One network, one attack, one defense: the Web Application template
v0.2 (in progress)Lab editor, 3 templates, command line tool
v0.3Attack paths, choke points, blast radius, embeddable view, offline PWA
v0.5Challenge mode, teacher mode, 10 missions aligned with NICE, ECSF and CyBOK
v1.0Stable format, 8 templates, 9 languages including Arabic and Chinese

The complete plan is in the specification (French).

Contributing

Contributions are welcome: code, labs, translations, and reviews by security practitioners of the technique catalog. Start with CONTRIBUTING.md. Please follow the code of conduct, and report vulnerabilities as described in SECURITY.md.

License

Download Tool