Skip to main content

Universal offensive-security engine, generic engine with knowledge as data

Project description

 ██████╗ ██████╗ ███████╗ ██████╗ ██████╗
██╔═══██╗██╔══██╗██╔════╝██╔═══██╗██╔══██╗
██║   ██║██████╔╝█████╗  ██║   ██║██████╔╝
██║   ██║██╔═══╝ ██╔══╝  ██║   ██║██╔══██╗
╚██████╔╝██║     ██║     ╚██████╔╝██║  ██║
 ╚═════╝ ╚═╝     ╚═╝      ╚═════╝ ╚═╝  ╚═╝

A universal offensive-security engine. One generic engine drives every scenario, web, internal network, AI agents, phishing. You change scenario by swapping data, plugins, and knowledge, never by editing the engine.

opfor mirrors codejury's "generic engine, knowledge as data" decoupling. The difference is that codejury reads code and judges, while opfor acts on live targets: it grows a live situation graph, gates every action by authorized scope, survives async waits, and keeps an audit ledger.

Layers

Layer What it owns Form
Capabilities How to reach a target and report the raw facts Capability, one tool per verb
Planner What to try next, gated on facts RuleSet under a scenario
Knowledge What a finding is and how severe Markdown the triage reads
Triage The verdict, the only place findings are minted Rule-based or model-backed
Kernel The blackboard, phase spine, scope, ledger, budget opfor/core/

The kernel is generic and names no host, contract, or person. A scenario is a plugin under opfor/scenarios/<name>/ that supplies capabilities, a planner, a triage, a declared terminal phase, and a knowledge/ tree.

Install

pip install opfor

The base install is keyless. Triage runs on the operator's Claude Code subscription by default, and a vendor API is used instead when a key is set. For the vendor SDKs install an extra, opfor[anthropic] or opfor[openai].

Use

opfor scenarios
opfor run attacksurface --root example.com

Develop

python -m venv .venv && . .venv/bin/activate
pip install -e ".[dev]"
pytest

See AGENTS.md for the architecture and the non-negotiable invariants.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opfor-0.1.0.tar.gz (90.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

opfor-0.1.0-py3-none-any.whl (96.9 kB view details)

Uploaded Python 3

File details

Details for the file opfor-0.1.0.tar.gz.

File metadata

  • Download URL: opfor-0.1.0.tar.gz
  • Upload date:
  • Size: 90.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for opfor-0.1.0.tar.gz
Algorithm Hash digest
SHA256 ebd111541669ad21783e4cf572127cdf2902cc14bf2f151021d09bbf071c4473
MD5 b8c22b4c872514fbbfccde2c2912a9c6
BLAKE2b-256 ee28589d8480ece0f2674e28c0c78a347990e879d959eb543ea155ad9daa1ffa

See more details on using hashes here.

Provenance

The following attestation bundles were made for opfor-0.1.0.tar.gz:

Publisher: publish.yml on aiseclabs/opfor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opfor-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: opfor-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 96.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for opfor-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c613e8f81c788c77ed86630f0d0b0ee31c002371fc687589ec51de57fe6e1192
MD5 4d4f4262c2d5861986b13a990f196ab1
BLAKE2b-256 689aa9fa0425ae3d811f3f7ea1da2172c7b594752cb8827999a2d74efbfda31e

See more details on using hashes here.

Provenance

The following attestation bundles were made for opfor-0.1.0-py3-none-any.whl:

Publisher: publish.yml on aiseclabs/opfor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page