Skip to main content

AI-assisted offensive reconnaissance and attack surface mapping.

Project description

 ██████╗ ██████╗ ███████╗ ██████╗ ██████╗
██╔═══██╗██╔══██╗██╔════╝██╔═══██╗██╔══██╗
██║   ██║██████╔╝█████╗  ██║   ██║██████╔╝
██║   ██║██╔═══╝ ██╔══╝  ██║   ██║██╔══██╗
╚██████╔╝██║     ██║     ╚██████╔╝██║  ██║
 ╚═════╝ ╚═╝     ╚═╝      ╚═════╝ ╚═╝  ╚═╝

AI-assisted offensive reconnaissance and attack surface mapping.

One generic engine drives every scenario, web, internal network, AI agents, phishing. You change scenario by swapping data, plugins, and knowledge, never by editing the engine.

opfor mirrors codejury's "generic engine, knowledge as data" decoupling. The difference is that codejury reads code and judges, while opfor acts on live targets: it grows a live situation graph, gates every action by authorized scope, survives async waits, and keeps an audit ledger.

Layers

Layer What it owns Form
Capabilities How to reach a target and report the raw facts Capability, one tool per verb
Planner What to try next, gated on facts RuleSet under a scenario
Knowledge What a finding is and how severe Markdown the triage reads
Triage The verdict, the only place findings are minted Rule-based or model-backed
Kernel The blackboard, phase spine, scope, ledger, budget opfor/core/

The kernel is generic and names no host, contract, or person. A scenario is a plugin under opfor/scenarios/<name>/ that supplies capabilities, a planner, a triage, a declared terminal phase, and a knowledge/ tree.

Install

pip install opfor

The base install is keyless. Triage runs on the operator's Claude Code subscription by default, and a vendor API is used instead when a key is set. For the vendor SDKs install an extra, opfor[anthropic] or opfor[openai].

Use

opfor scenarios
opfor run attacksurface --root example.com

Develop

python -m venv .venv && . .venv/bin/activate
pip install -e ".[dev]"
pytest

See AGENTS.md for the architecture and the non-negotiable invariants.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opfor-0.3.0.tar.gz (198.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

opfor-0.3.0-py3-none-any.whl (194.3 kB view details)

Uploaded Python 3

File details

Details for the file opfor-0.3.0.tar.gz.

File metadata

  • Download URL: opfor-0.3.0.tar.gz
  • Upload date:
  • Size: 198.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for opfor-0.3.0.tar.gz
Algorithm Hash digest
SHA256 bdea4a6f4ef72de73d9f7c5d2d8e80ba8cad6d9ce86909887f17f202a31a1dd6
MD5 3d37afaadf8606d45db0c400929a3bc9
BLAKE2b-256 8bf54ff08064584297aff7106f06fb2c2b9d387b5d47331f874e6414c2393c31

See more details on using hashes here.

Provenance

The following attestation bundles were made for opfor-0.3.0.tar.gz:

Publisher: publish.yml on aiseclabs/opfor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opfor-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: opfor-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 194.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for opfor-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 db1f89338c2b35826d212130a4091f751ff14d878b4a0d09d91ba8c277d8a11c
MD5 6e101b37780364cdb38f5a47df302233
BLAKE2b-256 053c088c908f505aa2feda378f747a1cc0f8b235fec5e327f67ca9978bd80cf0

See more details on using hashes here.

Provenance

The following attestation bundles were made for opfor-0.3.0-py3-none-any.whl:

Publisher: publish.yml on aiseclabs/opfor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page