Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
phantom-brain — Red portatil de reconocimiento inteligente con IA offline | Kitploit
Tools/GitHubGitHub/ottoyrocky/phantom-brain
Password CrackingReconnaissanceWi-Fi AuditingVulnerability AnalysisExploitationRFID/NFC ToolsInformation GatheringPenetration TestingHardware & IoT SecurityLearning & EducationRed TeamingAI Security
143213 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubottoyrocky/phantom-brain

phantom-brain

Red portatil de reconocimiento inteligente con IA offline

View Repository

PHANTOM BRAIN v0.9

Offline AI-powered pentesting analysis tool with real hardware integration

Local LLM analysis (via Ollama) for WiFi, Sub-GHz, NFC/RFID and WPA2 captures — no internet required, no cloud APIs, 100% offline. The main LLM runs on a Windows PC. The Raspberry Pi acts as a lightweight secondary node (live capture + phi3:mini only).

Hardware supported: Flipper Zero · WiFi Pineapple MK7 · Proxmark3 · Raspberry Pi 4 (Kali Linux) · Atheros AR9271

Models: mistral:7b-instruct · deepseek-r1:7b · phi3:mini

License: GPL-3.0 | Author: Otto | Community: AI Tinkerers

⚠️ Experimental project — not for production use. AI analysis assists human researchers; it does not replace manual auditing. Always verify findings independently.


What Phantom Brain IS and IS NOT

✅ What it IS❌ What it is NOT
Automatic analyzer that structures capture findingsA replacement for Wireshark, bettercap, or aircrack-ng
AI-powered report generator (offline, local LLM)An autonomous pentester
Orchestrator between hardware tools (Flipper, Pineapple, Proxmark)A production-ready security tool
Research and learning platformA substitute for manual auditing
100% offline — no data exfiltrationCloud-dependent or API-reliant

💡 Every AI-generated report should be treated as a starting point, not a final verdict. LLMs can hallucinate vulnerabilities. Structured parser output (without AI) is always more reliable.


System Architecture

FIELD (Mobile):
┌──────────────────┐
│  Flipper Zero    │ ──► Sub-GHz (.sub), NFC (.nfc), WiFi scanning
└──────────────────┘
┌──────────────────┐
│  WiFi Pineapple  │ ──► WPA2 Handshakes (.pcap), deauth, PMKID
└──────────────────┘
┌──────────────────┐
│  Proxmark3       │ ──► Advanced RFID/NFC (EM410x, MIFARE, EMV)
└──────────────────┘

BASE — PRIMARY NODE (required for full functionality):
┌──────────────────────────────────────────────────────┐
│  Windows PC (or Linux desktop)                       │
│  Python 3.11+ · Ollama · Flask API                  │
│  Runs: mistral:7b-instruct, deepseek-r1:7b           │
│  ► PHANTOM BRAIN CLI, full analysis, reports         │
└──────────────────────────────────────────────────────┘

BASE — SECONDARY NODE (optional, lightweight):
┌──────────────────────────────────────────────────────┐
│  Raspberry Pi 4 (Kali Linux)                         │
│  Ollama · Atheros AR9271                             │
│  Runs: phi3:mini only (mistral:7b too heavy for Pi)  │
│  ► Live WiFi capture · lightweight local inference   │
│  NOTE: connects to the PC's Ollama for heavy models  │
└──────────────────────────────────────────────────────┘

⚠️ Architecture note: The Raspberry Pi does not run the full Phantom Brain stack autonomously. For complete analysis with mistral:7b-instruct or deepseek-r1:7b, a PC with Ollama is required. The Pi serves as a capture node and can run phi3:mini for lightweight offline inference only.

Analysis Pipeline (v0.9)

``` input → classifier → tool.run() → ToolResult(risk, findings) → Ollama ```

Each capture type goes through its specific tool before reaching the LLM. The tool structures the output with a risk level and key findings, enriching the context sent to Ollama.


Features

WiFi / Marauder

  • Marauder log parser
  • Detection of vulnerable WPS networks
  • Identification of hidden networks
  • Security statistics

Sub-GHz / Flipper Zero

  • `.sub` file parser (`sub_ghz_parser.py`)
  • Extraction: protocol, frequency, keys, packets
  • Supports: Security+ 2.0, Rolling Code, Fixed Code
  • Pattern analyzer across captures (`sub_ghz_analyzer.py`)

NFC / Flipper Zero + Proxmark3

  • `.nfc` file parser (`nfc_parser.py`)
  • Supports: MIFARE Classic 1K/4K, MIFARE Plus, NTAG, FeliCa, EMV
  • Vulnerability analyzer (`nfc_analyzer.py`)
  • Detection: Darkside, Hardnested, Reader Auth Bypass
  • Special analysis for SUBE (public transport)
  • Proxmark3 output parser (`proxmark_parser.py`)

WPA2 / WiFi Pineapple

  • PCAP parser with Scapy (`pcap_parser_v2.py`)
  • Extraction: BSSID, SSID, EAPOL frames, PMKID
  • Validation of complete handshakes
  • Full pipeline: `hcxpcapngtool` → `hashcat -m 22000`

Tools System (v0.9)

  • `tools/base_tool.py` — unified `BaseTool` + `ToolResult` contract
  • `ToolResult` with `risk` (CRITICO/ALTO/MEDIO/BAJO) and structured `findings`
  • `tools/registry.py` — central registry, dispatches the correct tool by type
  • `tools/classifier.py` — auto-detection by extension and content
  • 14/14 tests passing with real fixtures (`pytest tests/test_tools.py`)

Database and Reports

  • SQLite for analysis history (`db_manager.py`)
  • Plain-text reports with timestamp
  • Search by UID/BSSID, filter by risk level
  • Analysis statistics

Flask API REST

  • `flask_api.py` running on port 5000
  • `GET /status` — checks Ollama and available models
  • `POST /upload` — receives `.pcap`, `.nfc`, `.sub` files
  • `POST /analyze` — analyzes with Ollama and saves to SQLite
  • `GET /analysis/` — queries saved analysis by ID

Supported AI Models

ModelMin RAMStorageSpeed (CPU)Best forNode
phi3:mini4 GB~2.3 GB~5 minQuick triage, lightweight inference, works on Pi — limited reasoning depthRaspberry Pi 4 / PC
mistral:7b-instruct8 GB~4.1 GB~30 s (PC)Recommended default. Full analysis, precise actionable commands, best accuracy/speed ratioPC only
deepseek-r1:7b8 GB~4.5 GB~45 s (PC)In-depth analysis, detailed mitigation steps, chain-of-thought reasoningPC only

Note: Speed benchmarks measured on a PC with 32 GB RAM (CPU-only, no GPU). GPU acceleration via CUDA/ROCm will significantly reduce inference time. The Pi can only run phi3:mini reliably — mistral:7b causes thermal throttling and OOM on Pi 4B 8GB.

All models run 100% offline via Ollama — no internet connection required.


File Structure

phantom-brain/
├── phantom_brain.py          # Main CLI - entry point
├── flask_api.py              # API REST Flask
├── db_manager.py             # SQLite - report history
├── pcap_parser_v2.py         # Parser WPA2/PCAP
├── proxmark_parser.py        # Parser output Proxmark3
├── nfc_parser.py             # Flipper .nfc file parser
├── nfc_analyzer.py           # NFC vulnerability analyzer
├── sub_ghz_parser.py         # Flipper .sub file parser
├── sub_ghz_analyzer.py       # Sub-GHz pattern analyzer
├── exploit_guide.py          # Exploitation guides without AI
├── proxmark_launch.bat       # Proxmark3 launcher script (Windows)
├── config.yaml.example       # Configuration template
├── requirements.txt          # Python dependencies
├── tools/                    # Modular tools system (v0.9)
│   ├── base_tool.py          # BaseTool + ToolResult with risk/findings
│   ├── classifier.py         # Capture type auto-detection
│   ├── registry.py           # Central tools registry
│   ├── proxmark_tool.py      # Tool Proxmark3
│   ├── nfc_tool.py           # Tool NFC
│   ├── wpa2_tool.py          # Tool WPA2/PCAP
│   └── subghz_tool.py        # Tool Sub-GHz
├── tests/                    # Automated tests (14/14 passing)
│   └── test_tools.py
├── prompts/                  # System prompts separated by type
│   └── system_prompts.py
├── benchmarks/               # Benchmark suite
│   ├── dataset/              # Captures with expected results
│   ├── results/              # JSON and markdown reports
│   ├── benchmark_runner.py
│   └── run_benchmark.py
├── reportes/                 # Generated reports (ignored in git)
├── pcap/                     # WPA2 captures (ignored in git)
└── archive/                  # Previous versions

Installation

Download Tool