
Red portatil de reconocimiento inteligente con IA offline
Offline AI-powered pentesting analysis tool with real hardware integration
Local LLM analysis (via Ollama) for WiFi, Sub-GHz, NFC/RFID and WPA2 captures — no internet required, no cloud APIs, 100% offline. The main LLM runs on a Windows PC. The Raspberry Pi acts as a lightweight secondary node (live capture + phi3:mini only).
Hardware supported: Flipper Zero · WiFi Pineapple MK7 · Proxmark3 · Raspberry Pi 4 (Kali Linux) · Atheros AR9271
Models: mistral:7b-instruct · deepseek-r1:7b · phi3:mini
License: GPL-3.0 | Author: Otto | Community: AI Tinkerers
⚠️ Experimental project — not for production use. AI analysis assists human researchers; it does not replace manual auditing. Always verify findings independently.
| ✅ What it IS | ❌ What it is NOT |
|---|---|
| Automatic analyzer that structures capture findings | A replacement for Wireshark, bettercap, or aircrack-ng |
| AI-powered report generator (offline, local LLM) | An autonomous pentester |
| Orchestrator between hardware tools (Flipper, Pineapple, Proxmark) | A production-ready security tool |
| Research and learning platform | A substitute for manual auditing |
| 100% offline — no data exfiltration | Cloud-dependent or API-reliant |
💡 Every AI-generated report should be treated as a starting point, not a final verdict. LLMs can hallucinate vulnerabilities. Structured parser output (without AI) is always more reliable.
FIELD (Mobile):
┌──────────────────┐
│ Flipper Zero │ ──► Sub-GHz (.sub), NFC (.nfc), WiFi scanning
└──────────────────┘
┌──────────────────┐
│ WiFi Pineapple │ ──► WPA2 Handshakes (.pcap), deauth, PMKID
└──────────────────┘
┌──────────────────┐
│ Proxmark3 │ ──► Advanced RFID/NFC (EM410x, MIFARE, EMV)
└──────────────────┘
BASE — PRIMARY NODE (required for full functionality):
┌──────────────────────────────────────────────────────┐
│ Windows PC (or Linux desktop) │
│ Python 3.11+ · Ollama · Flask API │
│ Runs: mistral:7b-instruct, deepseek-r1:7b │
│ ► PHANTOM BRAIN CLI, full analysis, reports │
└──────────────────────────────────────────────────────┘
BASE — SECONDARY NODE (optional, lightweight):
┌──────────────────────────────────────────────────────┐
│ Raspberry Pi 4 (Kali Linux) │
│ Ollama · Atheros AR9271 │
│ Runs: phi3:mini only (mistral:7b too heavy for Pi) │
│ ► Live WiFi capture · lightweight local inference │
│ NOTE: connects to the PC's Ollama for heavy models │
└──────────────────────────────────────────────────────┘
⚠️ Architecture note: The Raspberry Pi does not run the full Phantom Brain stack autonomously. For complete analysis with
mistral:7b-instructordeepseek-r1:7b, a PC with Ollama is required. The Pi serves as a capture node and can runphi3:minifor lightweight offline inference only.
``` input → classifier → tool.run() → ToolResult(risk, findings) → Ollama ```
Each capture type goes through its specific tool before reaching the LLM. The tool structures the output with a risk level and key findings, enriching the context sent to Ollama.
| Model | Min RAM | Storage | Speed (CPU) | Best for | Node |
|---|---|---|---|---|---|
phi3:mini | 4 GB | ~2.3 GB | ~5 min | Quick triage, lightweight inference, works on Pi — limited reasoning depth | Raspberry Pi 4 / PC |
mistral:7b-instruct | 8 GB | ~4.1 GB | ~30 s (PC) | Recommended default. Full analysis, precise actionable commands, best accuracy/speed ratio | PC only |
deepseek-r1:7b | 8 GB | ~4.5 GB | ~45 s (PC) | In-depth analysis, detailed mitigation steps, chain-of-thought reasoning | PC only |
Note: Speed benchmarks measured on a PC with 32 GB RAM (CPU-only, no GPU). GPU acceleration via CUDA/ROCm will significantly reduce inference time. The Pi can only run
phi3:minireliably —mistral:7bcauses thermal throttling and OOM on Pi 4B 8GB.
All models run 100% offline via Ollama — no internet connection required.
phantom-brain/
├── phantom_brain.py # Main CLI - entry point
├── flask_api.py # API REST Flask
├── db_manager.py # SQLite - report history
├── pcap_parser_v2.py # Parser WPA2/PCAP
├── proxmark_parser.py # Parser output Proxmark3
├── nfc_parser.py # Flipper .nfc file parser
├── nfc_analyzer.py # NFC vulnerability analyzer
├── sub_ghz_parser.py # Flipper .sub file parser
├── sub_ghz_analyzer.py # Sub-GHz pattern analyzer
├── exploit_guide.py # Exploitation guides without AI
├── proxmark_launch.bat # Proxmark3 launcher script (Windows)
├── config.yaml.example # Configuration template
├── requirements.txt # Python dependencies
├── tools/ # Modular tools system (v0.9)
│ ├── base_tool.py # BaseTool + ToolResult with risk/findings
│ ├── classifier.py # Capture type auto-detection
│ ├── registry.py # Central tools registry
│ ├── proxmark_tool.py # Tool Proxmark3
│ ├── nfc_tool.py # Tool NFC
│ ├── wpa2_tool.py # Tool WPA2/PCAP
│ └── subghz_tool.py # Tool Sub-GHz
├── tests/ # Automated tests (14/14 passing)
│ └── test_tools.py
├── prompts/ # System prompts separated by type
│ └── system_prompts.py
├── benchmarks/ # Benchmark suite
│ ├── dataset/ # Captures with expected results
│ ├── results/ # JSON and markdown reports
│ ├── benchmark_runner.py
│ └── run_benchmark.py
├── reportes/ # Generated reports (ignored in git)
├── pcap/ # WPA2 captures (ignored in git)
└── archive/ # Previous versions