Open-source AI-assisted red-team orchestration framework
Vigil is an MIT-licensed Python project for orchestrating authorized red-team workflows from a CLI or Textual TUI. It combines phase-specific tool registries, multi-step orchestration, SQLite-backed runtime state, and deterministic reporting.
License
This project is open source under the MIT License.
Features
- 18 canonical engagement phases from passive recon through reporting
- CLI entrypoint:
vigil - Textual TUI for interactive operation
- controller-driven engagement flow with queueing, snapshots, and resume support
- SQLite runtime state with schema normalization and legacy phase alias cleanup
- deterministic final reporting from persisted evidence
- direct phase commands and controller-driven
engage-*commands - support for Anthropic and OpenAI-compatible backends
Install
Requires Python 3.11+.
curl -sSfL https://raw.githubusercontent.com/zimkk/vigil/main/install.sh | bash
Or install from Python tooling:
pipx install zimkk-vigil
# or
pip install zimkk-vigil
For development:
pip install -e .[dev]
Until first PyPI release is published, Git install also works:
pipx install git+https://github.com/zimkk/vigil.git
Canonical phase model
Published package name is zimkk-vigil. Installed command remains vigil.
Vigil currently uses these 18 canonical phases:
passive_reconactive_reconvulnerability_assessmentvalidationexploitationpost_exploitationprivilege_escalationcredential_accessdiscoverylateral_movementpersistencedefense_evasionc2collectionexfiltrationimpactcleanupreporting
Legacy aliases such as enumeration and vuln_assessment are normalized to canonical names in runtime maintenance and reporting flows.
Main commands
Direct phase commands
| Command | Canonical phase |
|---|---|
vigil enumerate |
passive_recon |
vigil active |
active_recon |
vigil assess |
vulnerability_assessment |
vigil validate |
validation |
vigil exploit |
exploitation |
vigil post-exploit |
post_exploitation |
vigil privesc |
privilege_escalation |
vigil cred-access |
credential_access |
vigil discover |
discovery |
vigil lateral |
lateral_movement |
vigil persist |
persistence |
vigil evade |
defense_evasion |
vigil c2 |
c2 |
vigil collect |
collection |
vigil exfil |
exfiltration |
vigil impact |
impact |
vigil cleanup |
cleanup |
vigil report |
reporting |
Controller and maintenance commands
vigil engage-runvigil engage-phasevigil engage-statusvigil engage-reportvigil db-maintainvigil tools
Architecture summary
Current core architecture:
- redteam/cli.py: CLI surface and entrypoint routing
- redteam/tui/app.py: interactive TUI
- redteam/core/controller.py: engagement controller, scheduler, snapshots
- redteam/core/phase_execution.py: normalized phase execution contract
- redteam/core/context_store.py: low-level SQLite access
- redteam/core/repositories.py: higher-level repository layer
- redteam/core/runtime_schema.py: runtime schema versioning and normalization
- redteam/modules/reporting/orchestrator.py: deterministic report assembly
For fuller detail, see current_architecture.md.
Usage
Passive recon:
vigil enumerate example.com
Controller-driven run:
vigil engage-run 127.0.0.1 --authorize --notes "Authorized lab target only"
Single phase through controller:
vigil engage-phase 127.0.0.1 --phase reporting
Export engagement status:
vigil engage-status 127.0.0.1 --json-output snapshot.json
Generate final report:
vigil report 127.0.0.1 --authorize --output report.md --json-output report.json
List registered tools for a phase:
vigil tools enumerate
LLM backend
Vigil works with Anthropic by default and also supports OpenAI-compatible endpoints such as Ollama, vLLM, LM Studio, and OpenRouter.
Example .env:
# Anthropic
VIGIL_BACKEND=anthropic
VIGIL_API_KEY=sk-ant-...
VIGIL_MODEL=claude-sonnet-4-6
# OpenAI-compatible
VIGIL_BACKEND=openai_compat
VIGIL_BASE_URL=http://localhost:11434/v1
VIGIL_API_KEY=ollama
VIGIL_MODEL=qwen2.5:7b
External tools
Vigil integrates with real security binaries. Install supported dependencies:
curl -sSfL https://raw.githubusercontent.com/zimkk/vigil/main/install-tools.sh | bash
Support spans multiple tool families including recon, scanning, validation, and reporting helpers. Tool registration still relies on module import side effects, so keeping imports intact is part of runtime correctness.
Testing
Current test layout:
tests/conftest.pytests/contracts/tests/integration/tests/e2e/
Recent verified local state on August 11, 2026:
32 passed
Release and PyPI publishing
Repository now includes GitHub Actions workflows for CI and PyPI publishing:
.github/workflows/ci.yml.github/workflows/publish-pypi.yml
PyPI publishing path is configured for Trusted Publishing with distribution name zimkk-vigil.
One-time setup still required on GitHub and PyPI:
- In GitHub repository settings, create environment
pypi. - In PyPI, create or prepare project
zimkk-vigil. - In PyPI project settings, add Trusted Publisher:
- owner:
zimkk - repository:
vigil - workflow:
publish-pypi.yml - environment:
pypi
- owner:
- Publish a GitHub Release to trigger upload.
After first publish, public install should be:
pipx install zimkk-vigil
Legal and safety
Use Vigil only against systems you own or are explicitly authorized to test. Many commands invoke real reconnaissance and offensive-security tooling. Operator is responsible for scope control, authorization, and safe usage.
Software is provided under MIT License, without warranty. See LICENSE.
Metadata
Release files for zimkk-vigil 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| zimkk_vigil-0.1.0.tar.gz | 572.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| zimkk_vigil-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.3 MB
Release files / zimkk_vigil-0.1.0.tar.gz
| Download URL | zimkk_vigil-0.1.0.tar.gz |
|---|---|
| Size | 572.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
eb72ee4aa5f4ce37a409ec71692caf9f85bce97301b57e50a342765e4befe2a9
|
|
BLAKE2b-256 checksum How to use checksums |
8711e6308cab0c85f8a806a6d4c2420626cd5921641a81641bbb78c6c168c5f8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / zimkk_vigil-0.1.0-py3-none-any.whl
| Download URL | zimkk_vigil-0.1.0-py3-none-any.whl |
|---|---|
| Size | 706.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0ad839e54bc77da393703df3d6d859d1fcd4675d5cb58b3d1bb8136f083b0770
|
|
BLAKE2b-256 checksum How to use checksums |
7e04d655f1d8af9195848acfec979216248582171da3343100b0a0d377a4a31a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|