Skip to main content

AI-Powered Penetration Testing Platform with 40+ integrated tools

Project description

SoulEyez — AI-Powered Penetration Testing Platform

CI codecov Python 3.9+ Code style: black Security: bandit


What is SoulEyez?

SoulEyez is your penetration testing command center. Instead of juggling dozens of terminal windows and text files, SoulEyez gives you one organized place to:

  • Run security scans — Execute tools like Nmap, Gobuster, SQLMap with simple commands
  • Auto-discover next steps — When one scan finds something interesting, SoulEyez automatically suggests (or runs) the next logical tool
  • Stay organized — Keep all your targets, findings, and credentials in one searchable database
  • Generate reports — Export professional reports when you're done

Who is this for?

  • Security professionals conducting authorized penetration tests
  • CTF players who want better organization during competitions
  • Students learning penetration testing methodology

Important: Only use SoulEyez on systems you have explicit authorization to test. Unauthorized scanning or exploitation is illegal.


Features

Core Capabilities

  • 🎯 Interactive Dashboard — Real-time engagement monitoring with live updates
  • 🔗 Smart Tool Chaining — Automatic follow-up scans based on discoveries
  • 📊 Findings Management — Track and categorize vulnerabilities by severity
  • 🔑 Credential Vault — Encrypted storage for discovered credentials
  • 🌐 Network Mapping — Host discovery and service enumeration
  • 📈 Progress Tracking — Monitor scan completion and tool execution
  • 💾 SQLite Storage — Local database for all engagement data
  • 🔄 Background Jobs — Queue-based tool execution with status monitoring

Integrated Tools (40+)

  • Reconnaissance: nmap, masscan, theHarvester, whois, dnsrecon
  • Web Testing: nikto, gobuster, ffuf, sqlmap, nuclei, wpscan
  • Enumeration: enum4linux-ng, smbmap, crackmapexec, snmpwalk
  • Exploitation: Metasploit integration, searchsploit
  • Password Attacks: hydra, hashcat, john
  • Post-Exploitation: impacket suite, bloodhound

Pentest Workflow & Intelligence

  • 📁 Evidence Vault — Unified artifact collection organized by PTES phases
  • 🎯 Attack Surface Dashboard — Track what's exploited vs pending with priority scoring
  • 💣 Exploit Suggestions — Automatic CVE/Metasploit recommendations for discovered services
  • 🔗 Correlation Engine — Cross-phase attack tracking and gap analysis
  • 📝 Report Generator — Professional reports in Markdown/HTML/PDF formats
  • Deliverable Tracking — Manage testing requirements and acceptance criteria
  • 📸 Screenshot Management — Organized visual evidence by methodology phase

SIEM Integration

  • 🛡️ SIEM Connectors — Connect to Wazuh, Splunk, and other SIEM platforms
  • Detection Validation — Verify if your attacks triggered SIEM alerts
  • 🔍 Vulnerability Management — View CVEs from SIEM vulnerability data
  • ⚖️ Gap Analysis — Compare passive (SIEM) vs active (scan) findings
  • 🗺️ MITRE ATT&CK Reports — Detection coverage heatmaps by technique
  • 📡 Real-time Alerts — Monitor SIEM alerts during live engagements

FREE vs PRO

Feature FREE PRO
Core features (scans, findings, credentials)
Report generation
AI-powered suggestions & auto-chaining
Metasploit integration & exploit suggestions
SIEM integration & detection validation
MITRE ATT&CK reports

Quick Start

Step 1: Install Prerequisites

sudo apt install pipx    # Install pipx
pipx ensurepath          # Add pipx apps to your PATH
source ~/.bashrc         # Reload shell (Kali: use ~/.zshrc)

Step 2: Install SoulEyez

pipx install souleyez

Step 3: Launch SoulEyez

souleyez interactive

Step 4: First-Time Setup

On your first run, the setup wizard guides you through:

  1. Vault Password — Create a master password that encrypts sensitive data
  2. First Engagement — Set up your first project and select engagement type
  3. Tool Check — Detect and optionally install missing security tools
  4. AI Setup — Configure Ollama for AI features (optional)
  5. Tutorial — Option to run the interactive tutorial (recommended)

Step 5: You're Ready!

Once setup completes, you'll see the main menu.


System Requirements

Component Minimum Recommended
OS Ubuntu 22.04+ Kali Linux
Python 3.9+ 3.11+
RAM 4GB 8GB+
Disk 10GB 50GB+

Supported Operating Systems

OS Status Notes
Kali Linux ✅ Recommended All pentesting tools pre-installed
Ubuntu 22.04+ ✅ Supported Tools installed via souleyez setup
Parrot OS ✅ Supported Security-focused distro
Debian 12+ ✅ Supported Stable base system
macOS/Windows ❌ Not Supported Use Linux in a VM

Common Commands

Command What it does
souleyez interactive Launch the main interface
souleyez dashboard Real-time monitoring view
souleyez doctor Check if everything is set up correctly
souleyez setup Install/update pentesting tools
souleyez --help Show all available commands

Security & Encryption

SoulEyez encrypts all stored credentials using Fernet (AES-128-CBC + HMAC-SHA256) with PBKDF2 key derivation (600k iterations).

  • Master password is never stored (cannot be recovered if lost)
  • Credentials encrypted at rest with industry-standard cryptography
  • Sensitive data is masked in the UI until explicitly revealed

See SECURITY.md for complete security guidelines.


Documentation


Troubleshooting

Problem Solution
"command not found: souleyez" Run pipx ensurepath then restart terminal
"Tool not found" errors Run souleyez setup to install missing tools
Forgot vault password Data is encrypted — start fresh with rm -rf ~/.souleyez
Something seems broken Run souleyez doctor to diagnose

Glossary

New to pentesting? Here are some common terms:

Term Meaning
Engagement A project or assessment — contains all data for one test
Target/Host A computer, server, or device you're testing
Finding A security issue or vulnerability you discovered
Credential Username/password combo found during testing

Support & Feedback


License

See LICENSE for details.


Version: 2.43.21 | Maintainer: CyberSoul Security

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

souleyez-2.43.22.tar.gz (1.5 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

souleyez-2.43.22-py3-none-any.whl (1.7 MB view details)

Uploaded Python 3

File details

Details for the file souleyez-2.43.22.tar.gz.

File metadata

  • Download URL: souleyez-2.43.22.tar.gz
  • Upload date:
  • Size: 1.5 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for souleyez-2.43.22.tar.gz
Algorithm Hash digest
SHA256 bd5ec2d631a7870ac544ba5bab7af9ff4a5f3cc511a7388d45689a577e576fc5
MD5 5dbad6ac32e38f338f49254a2b201b45
BLAKE2b-256 88c524e79cec89a7a06a979323b3d399967e097e865b1de4218cbcf8606e92ee

See more details on using hashes here.

Provenance

The following attestation bundles were made for souleyez-2.43.22.tar.gz:

Publisher: python-ci.yml on cyber-soul-security/SoulEyez

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file souleyez-2.43.22-py3-none-any.whl.

File metadata

  • Download URL: souleyez-2.43.22-py3-none-any.whl
  • Upload date:
  • Size: 1.7 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for souleyez-2.43.22-py3-none-any.whl
Algorithm Hash digest
SHA256 b446e5729b1fd914a5c733370ec2ce7eb4104859d913a220e2d8bb2c06779917
MD5 a2f1aa47242066cec3d1ac999febd540
BLAKE2b-256 89190ab286b7b86711d2ee797e18306350bd4f7eaa3e58b1681f6e6930c75f87

See more details on using hashes here.

Provenance

The following attestation bundles were made for souleyez-2.43.22-py3-none-any.whl:

Publisher: python-ci.yml on cyber-soul-security/SoulEyez

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page