Skip to main content

Quality gate OpenSSF Scorecard

🎤 Accepted to Black Hat USA Arsenal 2026, SecTor Arsenal 2026, and SecTor 2026 Briefings. Live Arsenal demos at both conferences, plus the SecTor Briefing talk APTL for Agentic Purple Teaming.

APTL—Advanced Purple Team Lab

Purple-team lab where AI agents drive the red and blue sides against an enterprise target stack.

One aptl lab start brings up: a fictional company's infrastructure (AD, web, DB, file share, and DNS), a Kali red-team box, a SOC stack (Wazuh + Suricata + MISP + TheHive + Cortex + Shuffle), and MCP servers giving AI agents programmatic control over it. Scenarios are Reproducible Agentic Environments SDL documents, selectable at startup; the Compose topology is realized from the nodes the scenario declares rather than a fixed preset, and each run captures a telemetry archive. Mail and reverse-engineering services are optional profiles and are not part of the default techvault-operational scenario.

Use cases: autonomous cyber-operations research, purple-team training, AI threat-actor assessment.

Status

🚧 Active development. Not for production. Not hardened. This lab gives AI agents access to real penetration-testing tools and runs intentionally vulnerable services. Container escapes and other security issues are possible—keep it on a host you can rebuild and a network you control. Always monitor red-team agents during scenarios.

Quick Start

Install the released CLI and materialize a lab, no clone required:

pipx install aptl-labs          # the released CLI, isolated in its own environment
aptl lab init my-lab            # materialize the lab assets into ./my-lab
cd my-lab
aptl lab start

aptl lab init <dir> copies the bundled lab assets (the Compose topology, scenarios, config templates, and container build contexts) out of the installed package into <dir>, which becomes your lab project directory. The published wheel ships those assets, so a PyPI install alone can run a lab. pipx installs the CLI into its own virtualenv, so the system-pip block on modern Debian/Ubuntu/WSL2 hosts (PEP 668) never applies. Install pipx with sudo apt install pipx if you do not have it.

To run from source instead (for development), clone the repo and use a virtualenv editable install (the python3 -m venv step needs python3-venv on Debian/Ubuntu). The checkout is itself the project directory, so no lab init is needed:

git clone https://github.com/Brad-Edwards/aptl.git
cd aptl
python3 -m venv .venv && source .venv/bin/activate
pip install -e .
aptl lab start

aptl lab start creates .env automatically when it is missing and replaces template placeholder values with lab credentials that match the running containers. The startup output points to .env for passwords and tokens. Run aptl lab info later to reprint the same access summary.

By default it boots the full techvault-operational scenario. List the catalog and start a smaller curated topology with:

aptl lab scenarios                                   # list startup scenarios
aptl lab start --scenario techvault-attacker-target  # or --scenario-path <file>

See Scenarios for the catalog.

Once it's up:

Surface URL / command
Wazuh Dashboard https://localhost:443 (admin / your INDEXER_PASSWORD from .env)
Victim shell aptl container shell aptl-victim
Kali shell aptl container shell aptl-kali

Lifecycle:

aptl lab status   # running containers
aptl lab info     # URLs, usernames, and .env credential references
aptl lab stop     # graceful stop
aptl lab stop -v  # ⚠ destroys all lab data (Wazuh indexes, MISP, TheHive, configs)
aptl kill         # emergency: kill MCP server processes
aptl kill -c      # emergency: kill MCP processes AND all lab containers

Requirements

  • Docker + Docker Compose + Docker Buildx
  • Python 3.11+
  • OpenSSH client (ssh-keygen on PATH): generates the lab SSH keys at standup. Preinstalled on Linux and macOS; on Windows install the built-in "OpenSSH Client" optional feature (or Git for Windows / WSL2).
  • RAM: 8 GB runs the smaller curated scenarios; the full techvault-operational stack needs more than 20 GB
  • 20 GB+ disk
  • Linux, macOS, or Windows with Docker Desktop/WSL2
  • Open ports: 443, 8443, 9000, 9001, 9200, 55000 (and the rest of the published ports in docker-compose.yml)

Architecture

flowchart TD
    AI([AI Agents])

    subgraph MCP[MCP Server Layer]
        direction LR
        m1[mcp-red] ~~~ m2[mcp-wazuh] ~~~ m3[mcp-indexer] ~~~ m4[mcp-network]
        m5[mcp-casemgmt] ~~~ m6[mcp-soar] ~~~ m7[mcp-threatintel] ~~~ m8[mcp-reverse]
    end

    Kali[Kali Red Team]
    Reverse[Optional Malware Analysis<br/>not in the default scenario]

    subgraph Scenario[Scenario Environment]
        Targets[Scenario-defined target topology<br/>AD · web · DB · file share · DNS · mail · victim hosts · etc.]
    end

    subgraph SOC[SOC Stack]
        direction LR
        S1[Wazuh SIEM] ~~~ S2[Suricata IDS] ~~~ S3[MISP TI]
        S4[TheHive + Cortex] ~~~ S5[Shuffle SOAR]
    end

    AI <--> MCP
    MCP --> Kali
    MCP --> SOC
    MCP --> Reverse

    Kali -->|attack| Scenario
    Scenario -.->|logs / telemetry| SOC

The scenario environment is whatever the SDL scenario defines. The default techvault-operational topology (AD, web, DB, file share, DNS, mail, victims) is one shape, and other scenarios compose different ones. Component-by-component breakdown: docs/architecture/index.md.

Scenarios

Scenarios are Reproducible Agentic Environments SDL documents under scenarios/. aptl lab scenarios lists the catalog; aptl lab start --scenario <id> (or --scenario-path <file>) selects one. The Compose profiles that come up are realized from the nodes the SDL declares—the topology follows the scenario's content, including dependency closure, rather than a preset keyed off its name.

The SDL language and the reusable environment-pack format live in the RAES companion repositories—OpenRAE/rae (SDL and semantics) and OpenRAE/env-packs (pack definitions, templates, schemas, and authoring support). APTL consumes those definitions and realizes them as a running Docker lab; the lab lifecycle and runtime stay APTL-owned.

The catalog ships the operational default plus four curated slices:

Scenario id Boots Omits
techvault-operational TechVault enterprise, Kali, SOC, and observability (default) Mail and reverse engineering
techvault-attacker-target Kali + one monitored victim + Wazuh core + observability Enterprise web tier, wider SOC stack
techvault-enterprise-web Vulnerable webapp + DB + AD + Wazuh core + observability Red-team apparatus, wider SOC stack
techvault-defensive-min Wazuh manager / indexer / dashboard + observability Attacker and enterprise components, wider SOC stack
techvault-observability-core OTEL collector + Tempo + Grafana Everything else—the smallest bounded surface

Authoring and selection details: SDL Reference · Curated TechVault Variants.

AI Agents (MCP)

aptl lab start builds the seven MCP servers for the default scenario and creates a private .mcp.json client configuration with the generated lab credentials. Start your AI client from the project directory so its relative entry points resolve correctly.

To rebuild the MCP artifacts without restarting the lab:

./mcp/build-all-mcps.sh

The repository still builds the optional reverse MCP artifact, but the generated default client config omits it because the default SDL has no reverse node. Full setup: MCP Integration.

Smoke-test the wiring once the lab is up:

  • Red side: ask the agent "Use kali_info to show me the lab network"
  • Blue side: ask the agent "Use wazuh_query_alerts to show me recent alerts"

Optional: Web UI

Localhost-only web UI for lab control and scenario runs.

pip install -e ".[web]"        # in the same .venv from Quick Start
aptl web serve                 # API server
cd web && npm install && npm run dev   # frontend (separate terminal)

Access at http://localhost:5173 (dev) or http://localhost:3000 (prod). The API container needs the host Docker socket; do not expose to untrusted networks.

Documentation

Getting started: Installation · Prerequisites · Quick Start Guide

Architecture: Overview · Networking · Enterprise Infrastructure

Components: Wazuh SIEM · Kali Red Team · Victim Containers · Reverse Engineering · MCP Integration · Default Defensive Posture

Scenarios & SDL: SDL Reference · Curated TechVault Variants · Pack authoring (OpenRAE/env-packs) · SOC Architecture Spec

Reference: TechVault Scenario Overview · TechVault Company Profile · TechVault OSINT Readiness · Container Template Guide

Ops: Troubleshooting · Smoke Test Plan

Ethics & Disclaimers

APTL uses commodity services and basic integrations. AI agents get Kali access—no enhancements to their latent capabilities beyond that. No red-team enhancements will be added to this public repository. An autonomous cyber-operations range is under development as a separate project.

You are responsible for following all applicable laws. The author takes no responsibility for your use of this lab. The repository contains intentional test credentials (covered by .gitguardian.yaml) for lab functionality—dummy values for educational use, not production secrets.

License

MIT


10-23 AI hacker shenanigans 🚓

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aptl_labs-5.2.0.tar.gz (9.8 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aptl_labs-5.2.0-py3-none-any.whl (3.0 MB view details)

Uploaded Python 3

File details

Details for the file aptl_labs-5.2.0.tar.gz.

File metadata

  • Download URL: aptl_labs-5.2.0.tar.gz
  • Upload date:
  • Size: 9.8 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aptl_labs-5.2.0.tar.gz
Algorithm Hash digest
SHA256 9b68fc9fbcff23f66f145d798e9db8c47b8b0c9b61ac62d3366b38959961a124
MD5 6e6ec5936cb84c431af693d5397650f0
BLAKE2b-256 c81a9c515715435d85fbca820f25eb0e86b90b8631369099b6ffe9b2a3df68e5

See more details on using hashes here.

Provenance

The following attestation bundles were made for aptl_labs-5.2.0.tar.gz:

Publisher: release-please.yml on Brad-Edwards/aptl

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file aptl_labs-5.2.0-py3-none-any.whl.

File metadata

  • Download URL: aptl_labs-5.2.0-py3-none-any.whl
  • Upload date:
  • Size: 3.0 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aptl_labs-5.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 2a6a20df0dd67a9848e020ee1f63b75fe161a71a3068a9085c10975f7876ee4e
MD5 d2e22c7d4b31dd3df850ebbc07482ccd
BLAKE2b-256 3cfe799eddbc3b7fccd0420c2129491c2af4fea50dade5fe6e40bd3c91fa3e5e

See more details on using hashes here.

Provenance

The following attestation bundles were made for aptl_labs-5.2.0-py3-none-any.whl:

Publisher: release-please.yml on Brad-Edwards/aptl

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

5.3.0

2 files

This release

5.2.0 This release

2 files

5.1.1

2 files

5.1.0

2 files

5.0.0

2 files

4.2.2

2 files

4.2.1

2 files

4.2.0

2 files

4.1.2

2 files

4.1.1

2 files

4.1.0

2 files

4.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page