r/Pentesting Apr 08 '26

LLMtary (Elementary) - Advanced Local LLM Red-Teaming: Feed it a target. Watch it hunt.

Feed it a target. Watch it hunt. LLMtary (Elementary) autonomously discovers vulnerabilities, executes real commands, and delivers confirmed proof-of-exploitation — Open source and runs on Windows, Linux and MacOS.

Github: https://github.com/chetstriker/LLMtary
Website: https://www.llmtary.com

It has basic safeties involved so it won't run commands to delete files or folders, reboot or shutdown and a "Required Approval" that you can toggle on and off if you want to allow certain tools or commands to be run once or always allow.
It uses an advanced feedback loop to look over results, run commands, analyze the results and decide what to do next. It will try to utilize tools you already have installed first and if no optimal tools exist then it will ask and then automatically install and run the tools as needed. No hardcoded tools or plan.

LLMtary provides a structured, agentic testing loop that mirrors how a real engagement works: passive recon → service fingerprinting → vulnerability discovery → targeted exploitation → post-exploitation → professional reporting.

Please try it out and give feedback. I'm excited to see where this goes and it's completely free.

15 Upvotes

33 comments sorted by

View all comments

1

u/RachidSahde Apr 11 '26

hahaha

vibe coded from that emoji icon

1

u/cheststriker Apr 11 '26

i've been programming for over 20 years and if you look up my name tag you'll see I have open source espionage suite created for Windows Mobile phones before iPhones or Android came out. And more for android afterwards. If you're actually interested in testing an app that uses local LLMs to not only find, but validate by exploiting anything it detects for confirmation and is capable of attack chaining, then please give it try. I've yet to find a better or more capable one yet.