Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
AMBER-ICI — AMBER ICI v5: local-first Ollama investigative command center with case-scoped evidence, agent chains, hybrid retrieval, streaming analysis, graph and timeline views, OCR, controlled web research, and GPU telemetry. | Kitploit
Herramientas/GitHubGitHub/gs-ai/amber-ici
OSINT (Open Source Intelligence)Scripting & AutomationForensicsInformation GatheringDigital ForensicsPrivacyUtilities & FrameworksThreat IntelligenceMachine LearningLearning & EducationAI SecurityLabs & Practice
19830hace 1 mesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
GitHubgs-ai/amber-ici

AMBER-ICI

AMBER ICI v5: local-first Ollama investigative command center with case-scoped evidence, agent chains, hybrid retrieval, streaming analysis, graph and timeline views, OCR, controlled web research, and GPU telemetry.

Ver Repositorio
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

AMBER ICI interface banner

AMBER ICI v5

AMBER ICI (AMBER Investigative Command Interface) is a local-first browser interface for investigative and analytical workflows powered by a local Ollama server.

It includes:

  • A single-model Analyst Console and multi-model Parallel execution
  • A user-defined agent chain driven from the main terminal's SEND button
  • User control over which agents run, how many, how many loops, and which local model each uses
  • Local-model generation of agent configurations from a plain-language objective
  • A persistent semantic Archive backed by Ollama embeddings
  • Fibonacci fractal retrieval for active-file context
  • File uploads, read-only linked-directory access, text extraction, and OCR
  • Optional Playwright-backed web fetch and public-record search, behind a single master switch
  • Standalone entity graph, timeline, and vector-store views
  • Local token-rate, session, GPU/VRAM, and temperature telemetry where available

Ollama inference is restricted by the UI to loopback endpoints (127.0.0.1, localhost, or ::1). AMBER does not include cloud inference or application telemetry, and no feature requires a login, API key, or account. The WEB pill is the master switch for all internet access: with it OFF, AMBER makes no outbound request of any kind.

v5 Highlights

  • Local case workspaces with case-bounded evidence and Archive retrieval
  • Streaming SHA-256 artifact identity, ingestion provenance, duplicate detection, and source citations
  • Deterministic keyword retrieval fused with existing semantic Archive results
  • Explicit, bounded memory scoped to sessions, investigators, cases, agents, or reasoning tasks
  • Operator-selected investigation role templates using installed local Ollama models
  • Agent execution from the main terminal with per-agent models, limits, formats, handoffs, and loop controls
  • Playwright WEB preflight, visible execution diagnostics, direct-fetch fallback, and one-hour local caching
  • Cached hardware detection with Metal, CUDA, ROCm, unified-memory, utilization, and temperature reporting
  • Coalesced streaming updates for responsive long-form output
  • Bounded persisted metadata, escaped generated UI content, reproducible Node dependencies, and expanded sensitive-runtime exclusions

Current Feature Set

Analyst Console

  • Streams a conversation with one selected Ollama model
  • Supports a system prompt, JSON output mode, seed, temperature, and CTX size
  • Injects active-file, optional web, and retained conversation context
  • Stops active work with STOP or Esc

The console pill bar carries the execution controls:

PillValuesPurpose
TEMP / CTX / MEM / FMT / STREAM / SEED / SYS—Analyst-mode inference settings
WEBOFF (default) / ONMaster switch for all internet access
EXECANALYST (default) / AGENTSWhat SEND runs: the single active model, or the agent chain
AGN0 = allHow many agents the chain runs, taken in card order
LOOPS1+How many times the chain repeats; mirrored with the Agents panel LOOPS field

Parallel

  • Runs the same prompt against all checked models
  • Streams and tracks each response independently
  • Applies the same CTX and active-file controls used by the Analyst Console

Agents — the execution chain

Agents are user-defined and are the primary execution path. There is no built-in or fixed agent list; the Agents panel starts empty and you populate it two ways:

  • + CREATE AGENT — define one by hand
  • GENERATE FROM PROMPT — describe an objective and a selected local planner model writes the agent set for you

Each agent stores its own runtime configuration:

FieldDefaultNotes
Agent name—Required
Agent purpose—Injected as [AGENT PURPOSE]
Agent system prompt—The agent's role instruction
Preferred local model—Required; must be installed in Ollama
Temperature0.35Per agent, independent of the console TEMP pill
Max output tokens0 (auto)0 uses AMBER's length heuristic
Loops1Passes this agent makes per chain loop, each refining its own previous output
Output formatplain textJSON sets Ollama's JSON mode and skips length expansion
Handoff instructions—Passed to the next sequential agent as [HANDOFF FROM PREVIOUS AGENT]
Execution modesequentialsequential, parallel, or gated
Output target, memory scope, role, tool access, enabled, notes—Under ADVANCED

Running the chain. Set EXEC to AGENTS, type a prompt in the main terminal, and press SEND. AMBER reads the selected mode, the enabled agents, each agent's local model, the AGN count, and the LOOPS count, then executes: parallel agents concurrently, followed by sequential agents in card order, once per loop. Each sequential agent receives the previous agent's output as [UPSTREAM OUTPUT] plus that agent's handoff note. Progress and every agent's streamed output print into the main terminal, and the final answer is retained in conversation history. The Agents panel RUN button does the same thing using the panel's own LOOPS field.

In AGENTS mode SEND does not require an active model in the Models panel, because each agent carries its own. gated agents are excluded from the chain — run them individually with their card's RUN button.

Missing models are never substituted. Saving an agent or starting a chain with a model that Ollama does not have prints an actionable block in the terminal naming the requested model, the models actually installed, and the ollama pull <model> command needed, and the run does not start.

Saved agent sets can be stored and restored by name from the Agents panel.

The earlier PIPELINE / CHAIN step-sequence mode was retired from the interface. Its engine and state/pipeline_state.json remain in place for backward compatibility, but it is no longer a selectable mode; agents are the execution chain.

Archive and Memory

  • Chunks and embeds queued files with embeddinggemma:latest
  • Searches the local archive by cosine similarity
  • Imports and exports archive JSON
  • Adds the most recent assistant output directly to the archive
  • Builds an in-browser Fibonacci fractal index for file-source retrieval
  • Offers FAST, HYBRID, and DEEP retrieval profiles

Case Intelligence

The Archive now includes an optional case boundary without replacing its existing all-archive workflow:

  • NEW CASE creates local case metadata.
  • ADD ACTIVE TO CASE records selected files as evidence, retains the existing raw upload, computes a streaming SHA-256 identity, and records ingestion provenance.
  • Archive vectors indexed while a case is selected carry that case ID. Case searches fuse those semantic results with a deterministic keyword fallback when both are available.
  • REMEMBER LAST explicitly saves the latest assistant output as labeled case memory. Model output is never silently promoted to evidence or memory.
  • ADD INVESTIGATION ROLES adds optional Director, Researcher, Investigator, Analyst, Documenter, and Critic templates to the existing user-defined agent registry. They use the operator-selected local model and do not run automatically.

Case intelligence is stored atomically in one versioned standard-library JSON store and uses AMBER's existing Ollama client.

Standalone Views

The header opens these tools in separate tabs:

  • Entity Provenance Graph: http://127.0.0.1:8765/amber_graph.html
  • Timeline: http://127.0.0.1:8765/amber_timeline.html
  • Vector Store manager: http://127.0.0.1:8765/amber_vectorstore.html

Requirements

Core runtime:

Descargar herramienta