An open-source, agentic network red teaming tool.
Agents that plan, act, observe and report inside a scope you define. Every action is checked by a scope engine outside the model, gated by the autonomy level you set, and written to an audit log. One static binary, your model, your machine.
Authorized testing only. A scope file is required and approval gates are on by default. Read the rules
- ws-0031
- hop 1
- svc-backup
- hop 2
- files01
- hop 3
- dc01
- hop 4, out of scope
- dc02
One of three candidate paths in the sample run. The last hop is refused by the scope engine.
- runs on
- Linux amd64/arm64macOSWindowsDocker
- fits into
- GitHub ActionsGitLab CISARIF viewersNeo4j export(example list)
- your model
- local runtimes (Ollama, llama.cpp)OpenAI-compatible endpointsnone, deterministic planner(example list)
One binary, one graph, one agent on a leash.
pwner discovers hosts and identities on a network you are cleared to test and builds a single graph from them. An agent, running on your own model or a deterministic fallback, proposes what to check next.
A scope engine outside the model decides what is allowed. You decide who approves. Every step lands in an audit log. It ships no exploits and no implants, and validation is read-only.
Authorized testing only. If you do not have written permission to test a network, do not point pwner at it.
scope file requiredNothing runs without one. Targets that are not allowed are denied by default.approval gatesApprove-each-step is the default. The agent cannot edit its own gates.append-only audit logEach action records the rule that permitted it.Try it on a lab network before anything else.
Install, write a scope file, check it, then run a playbook against a lab range. The full walkthrough is in the docs.
curl -fsSL https://pwner.example/install | sh
Examples, not live. The install URL and registry paths are placeholders.
pwner init acme-demo # writes scope.yaml to edit pwner scope check # fails closed on a bad file pwner agent run playbook.yaml # lab range 10.0.0.0/24