Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
violin — Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven reporting with guard gates. | Kitploit
Ferramentas/GitHubGitHub/strategic-automation/violin
Authentication & AuthorizationOSINT (Open Source Intelligence)Penetration Testing FrameworksPrivilege EscalationReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration TestingRed Teaming
1351835há 2 diasRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
GitHubstrategic-automation/violin

violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven reporting with guard gates.

Ver RepositórioSite
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Violin

Violin ☤ — Supervised Agentic Hermes Pentest Profile

Release Ready License: MIT Hermes >=0.18.0 Kali Linux Parrot OS Landing page GitHub stars

35 playbooks · 19 references · 14 templates · required execution guard · Hermes-native

Violin is a Hermes-native agentic pentest profile for supervised, authorised penetration tests — from reconnaissance through safe exploit validation to reporting. It uses Hermes' built-in toolsets, seven routed skills, and the required violin-guard plugin at the target-execution boundary. The standalone CLI supports release checks, diagnostics, and administrative recovery; target commands run through the plugin. Violin adds no profile-specific credentials and inherits the provider and tool backends already configured in Hermes.

Quick start · Workflow · Guard tools · Benchmarks · Landing page · Discussions · Development

Following Violin? Star the repository to keep it easy to find and help other security engineers discover supervised agentic pentesting.

Community discovery

Violin is listed in community-curated collections including awesome-ai-security, awesome-hermes-skills, awesome-hermes-agent, and awesome-infosec.

Third-party coverage: Starlog technical analysis and “Violin: Supervised Agentic Penetration Testing Profile for Hermes Agent”.

For independent evaluation, use the reviewer kit, which collects the benchmark path, known limits, review context, and a factual comparison with autonomous pentest-agent designs.


Guarded target executionScope, phase, PTT, skill, hypothesis, history, and synchronization checks run before a target command starts.
Persistent engagement statePTT tasks, hypotheses, command history, checkpoints, evidence, and reports survive context compression.
Evidence-backed findingsA typed submission binds each validated finding to authenticated execution receipts.
Routed methodologyA pentest orchestrator selects focused web, identity, API, business-logic, LLM-security, and misconfiguration playbooks.
Bounded executionSingle commands, command bursts, background processes, batch review, heartbeat checks, and cancellation share one state model.
Verifiable releasesPlugin registration, schemas, skill snapshots, documentation contracts, lint, formatting, and the full test suite are release-gated.

Quick start

Install the profile

hermes profile install https://github.com/Strategic-Automation/violin
hermes -p violin

Then start with an authorized target and let Violin collect the scope before any target interaction:

Run an authorized penetration test against example.com.

Requirements

  • Hermes Agent 0.18.0 or newer
  • Python 3.11 and uv for local development
  • Kali Linux or Parrot OS for the expected security-tool environment
  • Written authorization and an approved scope

Violin does not select a model or provider. Configure those in Hermes. For a capable default, use Qwen3.8 27B locally or DeepSeek V4 Flash through a hosted provider.

Engagement lifecycle

flowchart LR
    S[Scope] --> R[Recon]
    R --> V[Vulnerability research]
    V --> E[Exploit validation]
    E --> P[Reporting]
    P --> X[Retrospective]

    G[Violin Guard] -. validates .-> R
    G -. validates .-> V
    G -. validates .-> E
  1. Initialize the engagement and approve scope/scope.yaml.
  2. Select one active PTT task and its routed skill with violin_record_ptt.
  3. Run target commands with violin_exec or violin_exec_burst.
  4. Update hypotheses as evidence changes their status.
  5. Review each bounded command batch with violin_review_batch.
  6. Submit validated findings and generate the final report.
  7. Complete the retrospective.

The complete phase model is:

SCOPING → RECON → VULN_RESEARCH → EXPLOITATION
         → POST_EXPLOITATION / PRIVESC / FLAGS
         → REPORTING → RETROSPECTIVE

Starting work in a new phase requires a PTT task under that phase. Existing tasks are not moved between phase sections.

Guard tools

The plugin registers twelve Hermes tools from one typed registry:

ToolPurpose
violin_record_pttCreate, start, refresh, close, or cancel a PTT task
violin_record_hypothesisCreate or update a scoped hypothesis
violin_submit_findingSubmit a validated finding bound to its signed execution receipts
violin_execExecute one guarded command
violin_exec_burstExecute a bounded command file
violin_exec_statusRead background execution status
violin_exec_cancelCancel tracked background execution
violin_review_batchReview a completed batch and settle state
violin_rebind_pending_batchRebind a pending batch after confirmation
violin_heartbeat_doneClear a completed heartbeat review
violin_targetResolve the approved assessment target
violin_statusExplain current tasks, skills, and blockers

violin_exec is the generic target-command boundary. There are no tool-specific execution adapters or binary allowlists. Installed non-interactive tools may run only after the engagement gates pass.

The raw-terminal hook is a best-effort safety net, not network containment. Use terminal only for host-local preparation and administration.

Safety model

Baixar ferramenta