Sandbox
@FunnyWolf/Viper

Red team platform with LLM agent and modules

VIPER is a red team platform for adversary simulation and post-exploitation across Windows, Linux, and macOS. It combines a visual interface, built-in modules, automation, and an LLM agent to support security assessment work.

5,299 stars704 forksUpdated 3mo ago
Who it's for

Builders who run adversary simulation and red team operations across multiple systems.

What it delivers

You can manage red team assessments in one platform instead of stitching together separate tools and workflows.

What it does

Multi-platform implants

Supports Windows, Linux, and macOS for cross-platform red team work.

Built-in post-exploitation modules

Includes more than 100 modules covering MITRE ATT&CK stages.

LLM agent

Adds a built-in language model agent for automated processing and decision support.

Automation and notifications

Supports orchestration and notification workflows for ongoing monitoring.

Custom Python modules

Lets you extend the platform with Python-based modules for special cases.

Evasion and pivoting features

Includes anti-tracing, handler firewall, defense evasion, and pivot graph functions.

README

cover-v5-optimized

Getting-Started · Documentation

Static Badge chat on Discord follow on X(Twitter) Commits last month Issues closed Docker Pulls Release

README in English 简体中文版自述文件

VIPER is a powerful and flexible red team platform. It integrates the core tools and functionalities required for adversary simulation and red team operations, assisting you in efficiently completing cybersecurity assessment tasks.

  • User-Friendly Interface
    Provides an intuitive interface that enables red team members to rapidly initiate security assessment tasks.

  • Multi-Platform Support
    Supports red team assessments across multiple operating systems, including Windows, Linux, and macOS, ensuring broad compatibility.

  • Out-of-the-Box Red Teaming Tools
    Designed to cover all phases of the MITRE ATT&CK framework, offering a comprehensive attack simulation solution.

  • Integrated LLM Agent
    Built-in Large Language Model (LLM) agent enhances automated processing capabilities and intelligent decision-making support.

  • Automated Workflows
    Supports orchestration and notification mechanisms for 24/7 monitoring of target environments.

  • Rich Built-in Modules Integrates over 100 post-exploitation modules covering all stages of the MITRE ATT&CK framework, meeting the needs of different scenarios.

  • Custom Extensibility
    Supports Python-based custom module development to meet specialized requirements or add extended functionalities.

  • More Advanced Features Includes built-in anti-tracing/handler firewall/defense evasion/pivot graph/automated notification functions.

img.webp img_1.webp img_2.webp img_3.webp img_4.webp img_5.webp

Product Comparison

VIPERCobalt StrikeNightHawkBruteRatel
ImplantsWindows
Linux
MacOS
WindowsWindowsWindows
Visual UI
Pivot Graph
Custom PluginPythonCNA
Built-in Evasion
Automation
Team Collaboration
LLM Agent
PriceFree$12,600 user/year$10,000 user/year$3,000 user/year

Website

www.viperrtp.com

Files in the repo

Repository payload8 top-level entries
  • .github
  • docs
  • .gitignore
  • package.json
  • README_ZH.md
  • README.md
  • tsconfig.json
  • vercel.json

Discussion (0)

Ask about usage, or say what you built with it

Sign in to join the discussion.

No comments yet. Be the first to say what this is good for.

More other

😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]

505k
archestra-ai/
archestra

Enterprise AI Platform with guardrails, MCP registry, gateway & orchestrator

4.3k

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

4.4k
Kymo-MCP/
mcpcan

MCPCAN is a centralized management platform for MCP services. It deploys each MCP service using a container deployment method. The platform supports container monitoring and MCP service token verification, solving security risks and enabling rapid deployment of MCP services. It uses SSE, STDIO, and STREAMABLEHTTP access protocols to deploy MCP。

727

Securely scale AI usage across your organization. A single stack to Connect, Secure, Observe and Distribute agents, MCPs, and Skills within your company.

266
stacklok/
toolhive-studio

ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents

163