人工智能驱动的渗透测试 MCP 服务器
"在日本神话中,天狗是一种凶猛的山灵——战略大师、武士和武士的导师。在网络安全中,它引导你度过狩猎的每个阶段。"
从侦察到报告——人工智能辅助渗透测试,只需一条命令。
Tengu 是一个 MCP 服务器,将 Claude 转变为渗透测试副驾驶员。它协调 80 种安全工具——从 Nmap 到 Metasploit——并内置安全控制、审计日志和专业报告生成。
将 Claude 用作交互式渗透测试副驾驶——你来指导行动,Claude 自动选择正确的工具并串联它们。
git clone https://github.com/rfunix/tengu.git && cd tengu make docker-build make docker-up
将Claude Code连接到运行中的服务器:```bash
claude mcp add --transport sse tengu http://localhost:8000/sse
然后询问 Claude:Do a full pentest on http://192.168.1.100
Claude 自动链式使用工具:validate_target → whatweb → nmap → nikto →
nuclei → sqlmap → correlate_findings → generate_report
| 命令 | 启动内容 |
|---|---|
make docker-up | Tengu MCP 服务器 (:8000) |
make docker-lab | + Juice Shop、DVWA(安全练习目标) |
make docker-pentest | + Metasploit、OWASP ZAP(真实世界目标) |
make docker-full | + Metasploit、ZAP 和实验目标 |
无需编辑文件即可扫描自定义目标:```bash TENGU_ALLOWED_HOSTS="192.168.1.0/24,10.0.0.0/8" make docker-up
### 镜像层级
为您的使用场景选择合适的大小:
| 层级 | 大小 | MCP工具 | 使用场景 |
|------|------|-----------|----------|
| `最小` | ~480MB | 17 | 轻量级分析、CVE研究、报告撰写 |
| `核心` | ~7GB | 47 | 完整渗透测试工具包(默认) |
| `完整` | ~8GB | 80 | 全部 + 活动目录、无线、隐蔽/OPSEC |```bash
TENGU_TIER=minimal make docker-build # lightweight
TENGU_TIER=core make docker-build # default
TENGU_TIER=full make docker-build # everything
所有层级均包含全部35个提示和20个资源 — 仅有二进制工具不同。
前提条件: Python 3.12+, uv, Kali Linux(推荐)```bash
git clone https://github.com/rfunix/tengu.git && cd tengu
uv sync
make install-tools
uv run tengu
连接 Claude Code:```bash
claude mcp add --scope user tengu -- uv run --directory /path/to/tengu tengu
在 tengu.toml 中配置允许的目标:```toml
[targets]
allowed_hosts = ["192.168.1.0/24", "example.com"]
关于 Claude Desktop、VM/SSE 远程设置及高级配置,请参阅 [docs/deployment-guide.md](https://github.com/rfunix/tengu/blob/main/docs/deployment-guide.md)。
</details>
### 配置参考```toml
[targets]
# REQUIRED: Only these hosts will be scanned
allowed_hosts = ["192.168.1.0/24", "example.com"]
blocked_hosts = [] # Always blocked, even if in allowed_hosts
[stealth]
enabled = false # Route traffic through Tor/proxy
[stealth.proxy]
enabled = false
type = "socks5h"
host = "127.0.0.1"
port = 9050
[osint]
shodan_api_key = "" # Required for shodan_lookup
[tools.defaults]
scan_timeout = 300 # seconds
有关完整参考,请参见 docs/configuration-reference.md。
运行完全自主的渗透测试,无需手动调用工具。该代理使用 Claude 作为其战略大脑,Tengu 作为其执行工具集,遵循 PTES 方法论,从侦察到报告全程自动化。
cp .env.example .env
**实验目标 (Juice Shop, DVWA):**```bash
make docker-lab
make docker-agent # default model (sonnet)
make docker-agent-haiku # cheaper — claude-haiku-4-5, max_tokens=1024
make docker-agent-sonnet # balanced — claude-sonnet-4-6, max_tokens=4096
真实世界的渗透测试(Tengu + MSF + ZAP,无实验室容器):```bash make docker-pentest make docker-agent
**在浏览器中查看报告:**```bash
make docker-report-view # http://localhost:8888 — styled HTML, all reports
make docker-report-browse # same, auto-opens browser
REPORT_PORT=9999 make docker-report-view # custom port
不使用 Docker:```bash uv sync --extra agent python autonomous_tengu.py 192.168.1.100 --scope 192.168.1.0/24 --type blackbox
python autonomous_tengu.py 192.168.1.100 --model claude-haiku-4-5 --max-tokens 1024 --timeout 30
**成本控制** — 三个环境变量/CLI 标志:
| 标志 | 环境变量 | 默认值 |
|---|---|---|
| `--model` | `TENGU_AGENT_MODEL` | `claude-sonnet-4-6` |
| `--max-tokens` | `TENGU_AGENT_MAX_TOKENS` | `2048` |
| `--timeout` | `TENGU_AGENT_TIMEOUT` | `60` (分钟, `0`=无限制) |
### 工作原理```
START → initializer → strategist ─┬─→ executor → analyst ─┬─→ strategist (loop)
│ └─→ reporter → END
├─→ human_gate → executor
└─→ reporter → END
关键行为:
msf_run_module、hydra_attack、impacket_kerberoast、sqlmap_scan 且 level≥3)执行前中断--max-iterationscorrelate_findings + score_risk + generate_report| 阶段 | 名称 | Tengu 所做工作 | 关键工具 |
|---|---|---|---|
| 1 | 前期参与 | validate_target 确认范围,check_tools 验证就绪状态 | validate_target, check_tools |
| 2 | 情报收集 | OSINT、DNS 侦察、子域名枚举、技术指纹识别 | nmap, subfinder, amass, shodan, whatweb |
| 3 | 威胁建模 | Claude 分析已收集情报,对攻击面进行优先级排序,构建威胁场景 | (AI 驱动 — 无外部工具) |
| 4 | 漏洞分析 | 模板扫描、Web 应用测试、SSL/TLS 分析、参数模糊测试 | nuclei, nikto, ffuf, sqlmap, testssl |
| 5 | 利用 | 对人机协作确认的漏洞进行受控利用 | msf_run_module, sqlmap, hydra, searchsploit |
| 6 | 后利用 | 凭证收集、横向移动评估、权限提升 | impacket_kerberoast, nxc_enum, enum4linux |
| 7 | 报告 | 关联所有发现、计算风险评分、生成专业报告 | correlate_findings, score_risk, generate_report |
minimal(17 个工具,约 480MB)·core(47 个工具,约 7GB,默认)·full(80 个工具,约 8GB) 使用TENGU_TIER=<tier> make docker-build构建。所有层级均包含全部 35 个提示词和 20 个资源。