MCP服务器使AI代理能够自主执行150+种网络安全工具,用于自动化渗透测试、漏洞发现、漏洞赏金自动化以及跨网络、Web应用程序和云基础设施的安全研究。
先进的人工智能驱动渗透测试 MCP 框架,集成 150+ 安全工具和 12+ 自主 AI 代理
HexStrike AI MCP v6.0 采用多代理架构,具备自主 AI 代理、智能决策和漏洞情报能力。```mermaid %%{init: {"themeVariables": { "primaryColor": "#b71c1c", "secondaryColor": "#ff5252", "tertiaryColor": "#ff8a80", "background": "#2d0000", "edgeLabelBackground":"#b71c1c", "fontFamily": "monospace", "fontSize": "16px", "fontColor": "#fffde7", "nodeTextColor": "#fffde7" }}}%% graph TD A[AI Agent - Claude/GPT/Copilot] -->|MCP Protocol| B[HexStrike MCP Server v6.0]
B --> C[Intelligent Decision Engine]
B --> D[12+ Autonomous AI Agents]
B --> E[Modern Visual Engine]
C --> F[Tool Selection AI]
C --> G[Parameter Optimization]
C --> H[Attack Chain Discovery]
D --> I[BugBounty Agent]
D --> J[CTF Solver Agent]
D --> K[CVE Intelligence Agent]
D --> L[Exploit Generator Agent]
E --> M[Real-time Dashboards]
E --> N[Progress Visualization]
E --> O[Vulnerability Cards]
B --> P[150+ Security Tools]
P --> Q[Network Tools - 25+]
P --> R[Web App Tools - 40+]
P --> S[Cloud Tools - 20+]
P --> T[Binary Tools - 25+]
P --> U[CTF Tools - 20+]
P --> V[OSINT Tools - 20+]
B --> W[Advanced Process Management]
W --> X[Smart Caching]
W --> Y[Resource Optimization]
W --> Z[Error Recovery]
style A fill:#b71c1c,stroke:#ff5252,stroke-width:3px,color:#fffde7
style B fill:#ff5252,stroke:#b71c1c,stroke-width:4px,color:#fffde7
style C fill:#ff8a80,stroke:#b71c1c,stroke-width:2px,color:#fffde7
style D fill:#ff8a80,stroke:#b71c1c,stroke-width:2px,color:#fffde7
style E fill:#ff8a80,stroke:#b71c1c,stroke-width:2px,color:#fffde7
### 工作原理
1. **AI 代理连接** - Claude、GPT 或其他兼容 MCP 的代理通过 FastMCP 协议连接
2. **智能分析** - 决策引擎分析目标并选择最优测试策略
3. **自主执行** - AI 代理执行全面的安全评估
4. **实时自适应** - 系统根据结果和发现的漏洞进行调整
5. **高级报告** - 带有漏洞卡片和风险分析的可视化输出
---
## 安装
### 快速设置以运行 hexstrike MCPs 服务器```bash
# 1. Clone the repository
git clone https://github.com/0x4m4/hexstrike-ai.git
cd hexstrike-ai
# 2. Create virtual environment
python3 -m venv hexstrike-env
source hexstrike-env/bin/activate # Linux/Mac
# hexstrike-env\Scripts\activate # Windows
# 3. Install Python dependencies
pip3 install -r requirements.txt
在此观看完整的安装与设置演示:YouTube - HexStrike AI 安装与演示
您可以在多种 AI 客户端上安装并运行 HexStrike AI MCP,包括:
请参考上方视频,获取针对这些平台的逐步说明与集成示例。
核心工具(必需):```bash
nmap masscan rustscan amass subfinder nuclei fierce dnsenum autorecon theharvester responder netexec enum4linux-ng
gobuster feroxbuster dirsearch ffuf dirb httpx katana nikto sqlmap wpscan arjun paramspider dalfox wafw00f
hydra john hashcat medusa patator crackmapexec evil-winrm hash-identifier ophcrack
gdb radare2 binwalk ghidra checksec strings objdump volatility3 foremost steghide exiftool
**云安全工具:**```bash
prowler scout-suite trivy
kube-hunter kube-bench docker-bench-security
浏览器代理要求:```bash
sudo apt install chromium-browser chromium-chromedriver
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add - echo "deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main" | sudo tee /etc/apt/sources.list.d/google-chrome.list sudo apt update && sudo apt install google-chrome-stable
### 启动服务器```bash
# Start the MCP server
python3 hexstrike_server.py
# Optional: Start with debug mode
python3 hexstrike_server.py --debug
# Optional: Custom port configuration
python3 hexstrike_server.py --port 8888
curl http://localhost:8888/health
curl -X POST http://localhost:8888/api/intelligence/analyze-target
-H "Content-Type: application/json"
-d '{"target": "example.com", "analysis_type": "comprehensive"}'
---
## AI客户端集成设置
### Claude Desktop 集成或 Cursor
编辑 `~/.config/Claude/claude_desktop_config.json`:```json
{
"mcpServers": {
"hexstrike-ai": {
"command": "python3",
"args": [
"/path/to/hexstrike-ai/hexstrike_mcp.py",
"--server",
"http://localhost:8888"
],
"description": "HexStrike AI v6.0 - Advanced Cybersecurity Automation Platform",
"timeout": 300,
"disabled": false
}
}
}
在 .vscode/settings.json 中配置 VS Code 设置:```json
{
"servers": {
"hexstrike": {
"type": "stdio",
"command": "python3",
"args": [
"/path/to/hexstrike-ai/hexstrike_mcp.py",
"--server",
"http://localhost:8888"
]
}
},
"inputs": []
}
---
## 功能特性
### 安全工具库
**150+ 专业安全工具:**
<details>
<summary><b>🔍 网络侦察与扫描(25+ 工具)</b></summary>
- **Nmap** - 高级端口扫描,支持自定义 NSE 脚本和服务检测
- **Rustscan** - 超快速端口扫描,带智能速率限制
- **Masscan** - 高速互联网规模端口扫描,支持横幅抓取
- **AutoRecon** - 全面自动化侦察,支持 35+ 参数
- **Amass** - 高级子域名枚举和 OSINT 收集
- **Subfinder** - 快速被动子域名发现,支持多数据源
- **Fierce** - DNS 侦察和区域传输测试
- **DNSEnum** - DNS 信息收集和子域名暴力破解
- **TheHarvester** - 从多个数据源收集电子邮件和子域名
- **ARP-Scan** - 使用 ARP 请求进行网络发现
- **NBTScan** - NetBIOS 名称扫描和枚举
- **RPCClient** - RPC 枚举和空会话测试
- **Enum4linux** - SMB 枚举,包含用户、组和共享发现
- **Enum4linux-ng** - 高级 SMB 枚举,增强日志记录
- **SMBMap** - SMB 共享枚举和利用
- **Responder** - LLMNR、NBT-NS 和 MDNS 投毒工具,用于凭证收集
- **NetExec** - 网络服务利用框架(原名 CrackMapExec)
</details>
<details>
<summary><b>🌐 Web 应用安全测试(40+ 工具)</b></summary>