{"id":48289797,"url":"https://github.com/yashab-cyber/metasploit-ai","last_synced_at":"2026-04-04T23:02:43.082Z","repository":{"id":307551918,"uuid":"1029907584","full_name":"yashab-cyber/metasploit-ai","owner":"yashab-cyber","description":"Metasploit-AI is a cutting-edge cybersecurity framework that combines the power of Metasploit with advanced artificial intelligence and machine learning capabilities. Designed for cybersecurity professionals, ethical hackers, and penetration testers, ","archived":false,"fork":false,"pushed_at":"2025-08-09T17:42:25.000Z","size":671,"stargazers_count":5,"open_issues_count":0,"forks_count":5,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-08-09T19:28:02.681Z","etag":null,"topics":["cybersecurity","ethicalhacking","hacking","kali-linux","metasploit","pentesting","zehrasec"],"latest_commit_sha":null,"homepage":"https://zehrasec.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yashab-cyber.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-07-31T19:10:19.000Z","updated_at":"2025-08-09T17:42:28.000Z","dependencies_parsed_at":"2025-07-31T22:53:01.977Z","dependency_job_id":null,"html_url":"https://github.com/yashab-cyber/metasploit-ai","commit_stats":null,"previous_names":["yashab-cyber/metasploit-ai"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/yashab-cyber/metasploit-ai","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yashab-cyber%2Fmetasploit-ai","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yashab-cyber%2Fmetasploit-ai/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yashab-cyber%2Fmetasploit-ai/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yashab-cyber%2Fmetasploit-ai/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yashab-cyber","download_url":"https://codeload.github.com/yashab-cyber/metasploit-ai/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yashab-cyber%2Fmetasploit-ai/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31418287,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-04T20:09:54.854Z","status":"ssl_error","status_checked_at":"2026-04-04T20:09:44.350Z","response_time":60,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cybersecurity","ethicalhacking","hacking","kali-linux","metasploit","pentesting","zehrasec"],"created_at":"2026-04-04T23:02:11.411Z","updated_at":"2026-04-04T23:02:43.066Z","avatar_url":"https://github.com/yashab-cyber.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 🤖 Metasploit-AI Framework\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"src/public/Metaspolit-AI.png\" alt=\"Metasploit-AI Logo\" width=\"400\"/\u003e\n\u003c/p\u003e\n\n**Advanced AI-Powered Penetration Testing and Cybersecurity Framework**\n\n[![License: Apache 2.0](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![Python 3.8+](https://img.shields.io/badge/python-3.8+-blue.svg)](https://www.python.org/downloads/)\n[![AI Powered](https://img.shields.io/badge/AI-Powered-green.svg)](https://github.com/yashab-cyber/metasploit-ai)\n[![Security](https://img.shields.io/badge/Security-Enhanced-red.svg)](https://github.com/yashab-cyber/metasploit-ai)\n[![ZehraSec](https://img.shields.io/badge/By-ZehraSec-purple.svg)](https://www.zehrasec.com)\n\n## 🚀 Overview\n\nMetasploit-AI is a cutting-edge cybersecurity framework that combines the power of Metasploit with advanced artificial intelligence and machine learning capabilities. Designed for cybersecurity professionals, ethical hackers, and penetration testers, this framework automates and enhances traditional penetration testing workflows with intelligent vulnerability assessment, exploit recommendation, and payload optimization.\n\n**Created by [Yashab Alam](https://github.com/yashab-cyber), Founder \u0026 CEO of [ZehraSec](https://www.zehrasec.com)**\n\n## ✨ Features\n\n### 🧠 AI-Powered Core\n- **Intelligent Vulnerability Analysis**: Machine learning models for vulnerability classification and risk assessment\n- **Smart Exploit Recommendation**: AI-driven exploit selection based on target characteristics\n- **Adaptive Payload Generation**: Dynamic payload creation and optimization using neural networks\n- **Automated Evasion**: AI-based techniques to evade detection systems\n\n### 🔍 Advanced Scanning\n- **Multi-threaded Network Scanning**: Fast and comprehensive network reconnaissance\n- **Service Enumeration**: Detailed service detection and version identification\n- **OS Fingerprinting**: Advanced operating system detection\n- **Stealth Scanning**: Evasive scanning techniques to avoid detection\n\n### 💥 Intelligent Exploitation\n- **Automated Exploit Execution**: Smart exploit chaining and execution\n- **Success Probability Prediction**: ML-based exploit success rate estimation\n- **Session Management**: Advanced post-exploitation session handling\n- **Real-time Monitoring**: Live exploitation status and progress tracking\n\n### 🌐 Multi-Interface Support\n- **Web Interface**: Modern, responsive web dashboard with Bootstrap 5\n- **Desktop GUI**: CustomTkinter-based desktop application with dark theme\n- **CLI Interface**: Rich command-line interface with syntax highlighting and auto-completion\n- **REST API**: Comprehensive API endpoints for integration and automation\n- **Real-time Updates**: WebSocket support for live updates across all interfaces\n\n### 📊 Comprehensive Reporting\n- **Automated Report Generation**: AI-enhanced penetration testing reports\n- **Risk Assessment**: Intelligent risk scoring and prioritization\n- **Compliance Mapping**: NIST, OWASP, and other framework alignment\n- **Executive Summaries**: Business-focused security summaries\n\n## 🛠️ Installation\n\n### Prerequisites\n\n- **Python 3.8+**\n- **Metasploit Framework**\n- **Operating System**: Linux (Kali Linux recommended), macOS, or Windows WSL\n\n### Quick Install\n\n```bash\n# Clone the repository\ngit clone https://github.com/yashab-cyber/metasploit-ai.git\ncd metasploit-ai\n\n# Run the setup script\npython setup.py\n\n# Install dependencies\npip install -r requirements.txt\n\n# Initialize the framework\npython app.py --mode web\n```\n\n### Docker Installation\n\n```bash\n# Build the Docker image\ndocker build -t metasploit-ai .\n\n# Run the container\ndocker run -d -p 8080:8080 --name msf-ai metasploit-ai\n```\n\n### Advanced Installation\n\nFor detailed installation instructions, including Metasploit setup and configuration, see the [Installation Guide](docs/installation.md).\n\n## 🚀 Quick Start\n\n### Interface Selection\n\nThe framework supports multiple interfaces to suit different use cases:\n\n| Interface | Best For | Command |\n|-----------|----------|---------|\n| 🖥️ **CLI** | Automation, scripting, remote access | `python app.py --mode cli` |\n| 🌐 **Web** | Team collaboration, remote access | `python app.py --mode web` |\n| 🖱️ **GUI** | Desktop users, visual workflow | `python app.py --mode gui` |\n\n### 1. Web Interface (Recommended for Teams)\n\n```bash\n# Start the web interface\npython app.py --mode web --host 0.0.0.0 --port 8080\n\n# Open your browser to http://localhost:8080\n# Default credentials: admin/admin\n```\n\n**Features:**\n- Modern Bootstrap 5 dashboard\n- Real-time updates via WebSocket\n- Multi-user session management\n- Responsive design for mobile/tablet\n- Comprehensive API endpoints\n\n### 2. Desktop GUI Interface (Recommended for Desktop Users)\n\n```bash\n# Install GUI dependencies\npip install customtkinter pillow\n\n# Start the desktop GUI\npython app.py --mode gui\n```\n\n**Features:**\n- Modern dark-themed interface with CustomTkinter\n- Native desktop integration\n- Real-time scanning and exploitation\n- AI-powered recommendations and analysis\n- Interactive session management\n- Comprehensive reporting tools\n- Drag-and-drop target import\n\n### 3. Command Line Interface (Default - Recommended for Automation)\n\n```bash\n# Start the CLI\npython app.py --mode cli\n\n# Basic commands\nmsf-ai\u003e status                    # Check framework status\nmsf-ai\u003e scan 192.168.1.0/24      # Scan network\nmsf-ai\u003e recommend                 # Get exploit recommendations\nmsf-ai\u003e exploit 1                 # Execute recommended exploit\nmsf-ai\u003e sessions list             # List active sessions\n```\n\n### 4. API Usage (Coming Soon)\n\n```bash\n# API mode will be available in future releases\n# Currently available through web interface endpoints\npython app.py --mode web --port 8080\n\n# Example API calls\ncurl -X POST http://localhost:8080/api/scan \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"target\": \"192.168.1.100\", \"scan_type\": \"comprehensive\"}'\n```\n\n## 📖 Usage Examples\n\n### Automated Penetration Testing\n\n```python\n# Python API example\nfrom src.core.framework import MetasploitAIFramework\nfrom src.core.config import Config\n\n# Initialize framework\nconfig = Config.load_config()\nframework = MetasploitAIFramework(config)\nawait framework.initialize()\n\n# Run automated penetration test\ntargets = [\"192.168.1.100\", \"192.168.1.101\"]\nresults = await framework.automated_penetration_test(targets)\n\n# Generate report\nreport = await framework.report_generator.generate_pentest_report(results)\n```\n\n### Custom Vulnerability Analysis\n\n```python\n# Advanced vulnerability analysis\nscan_result = await framework.scan_target(\"192.168.1.100\", \"comprehensive\")\nvulnerabilities = await framework.vuln_analyzer.analyze(scan_result)\n\n# Get AI recommendations\nrecommendations = await framework.recommend_exploits(\"192.168.1.100\", vulnerabilities)\n\n# Execute top recommendation\nif recommendations:\n    result = await framework.execute_exploit(\n        \"192.168.1.100\", \n        recommendations[0]['exploit_name']\n    )\n```\n\n## 🔧 Configuration\n\n### Basic Configuration\n\nEdit `config/default.yaml`:\n\n```yaml\nframework:\n  name: \"Metasploit-AI\"\n  version: \"1.0.0\"\n  debug: false\n\nmetasploit:\n  host: \"127.0.0.1\"\n  port: 55553\n  username: \"msf\"\n  password: \"msf\"\n\nai:\n  enabled: true\n  models_path: \"data/models\"\n  openai_api_key: \"your-openai-key\"\n\nsecurity:\n  api_key_required: true\n  rate_limit: 100\n  max_concurrent_scans: 5\n```\n\n### Advanced Configuration\n\nFor advanced configuration options, see the [Configuration Guide](docs/configuration.md).\n\n## 🤖 AI Models\n\nThe framework includes several pre-trained AI models:\n\n- **Vulnerability Classifier**: Categorizes and scores vulnerabilities\n- **Exploit Recommender**: Suggests optimal exploits for targets\n- **Payload Optimizer**: Generates and optimizes payloads\n- **Evasion Engine**: Applies anti-detection techniques\n\n### Training Custom Models\n\n```bash\n# Train vulnerability classifier\npython scripts/train_models.py --model vulnerability_classifier --data data/vulns.csv\n\n# Train exploit recommender\npython scripts/train_models.py --model exploit_recommender --data data/exploits.csv\n```\n\n## 📊 Reporting\n\n### Report Types\n\n- **Executive Summary**: High-level business impact analysis\n- **Technical Report**: Detailed vulnerability and exploit information\n- **Compliance Report**: NIST, ISO 27001, PCI DSS compliance mapping\n- **Remediation Guide**: Step-by-step fix recommendations\n\n### Custom Reports\n\n```python\n# Generate custom report\nfrom src.modules.report_generator import ReportGenerator\n\ngenerator = ReportGenerator(config)\nreport = await generator.generate_custom_report(\n    scan_results=results,\n    template=\"custom_template.html\",\n    include_charts=True,\n    include_raw_data=False\n)\n```\n\n## 🔒 Security Considerations\n\n### Ethical Usage\n\n⚠️ **IMPORTANT**: This framework is designed for authorized penetration testing and security research only. Users must:\n\n- Obtain proper authorization before testing any systems\n- Comply with all applicable laws and regulations\n- Use responsibly and ethically\n- Not use for malicious purposes\n\n### Security Features\n\n- **Audit Logging**: Comprehensive logging of all activities\n- **Access Control**: Role-based access control and API keys\n- **Encryption**: Encrypted communications and data storage\n- **Rate Limiting**: Protection against abuse and DoS\n\n## 🤝 Contributing\n\nWe welcome contributions from the cybersecurity community!\n\n### Development Setup\n\n```bash\n# Clone and setup development environment\ngit clone https://github.com/yashab-cyber/metasploit-ai.git\ncd metasploit-ai\n\n# Install development dependencies\npip install -r requirements-dev.txt\n\n# Run tests\npytest tests/\n\n# Run linting\nflake8 src/\nblack src/\n```\n\n### Contribution Guidelines\n\n1. Fork the repository\n2. Create a feature branch (`git checkout -b feature/amazing-feature`)\n3. Commit your changes (`git commit -m 'Add amazing feature'`)\n4. Push to the branch (`git push origin feature/amazing-feature`)\n5. Open a Pull Request\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) for detailed guidelines.\n\n## 📚 Documentation\n\n- [Installation Guide](docs/installation.md)\n- [User Manual](docs/user-manual.md)\n- [API Documentation](docs/api.md)\n- [Developer Guide](docs/developer.md)\n- [AI Models Documentation](docs/ai-models.md)\n\n## 🧪 Testing\n\n```bash\n# Run all tests\npytest\n\n# Run specific test category\npytest tests/test_scanner.py\npytest tests/test_ai_models.py\npytest tests/test_exploits.py\n\n# Run with coverage\npytest --cov=src tests/\n```\n\n## 🐛 Troubleshooting\n\n### Common Issues\n\n1. **Metasploit Connection Failed**\n   ```bash\n   # Start Metasploit RPC server\n   sudo msfconsole -x \"load msgrpc ServerHost=127.0.0.1 ServerPort=55553 User=msf Pass=msf\"\n   ```\n\n2. **AI Models Not Loading**\n   ```bash\n   # Download pre-trained models\n   python scripts/download_models.py\n   ```\n\n3. **Permission Errors**\n   ```bash\n   # Fix permissions\n   sudo chown -R $USER:$USER data/ logs/\n   ```\n\nFor more troubleshooting help, see [TROUBLESHOOTING.md](docs/troubleshooting.md).\n\n## 🤝 Contributing\n\nWe welcome contributions from the cybersecurity community! Please read our contributing guidelines before getting started.\n\n### 📚 Documentation\n- [Contributing Guide](CONTRIBUTING.md) - How to contribute to the project\n- [Code of Conduct](CODE_OF_CONDUCT.md) - Community standards and expectations\n- [Security Policy](SECURITY.md) - Security vulnerability reporting\n- [Development Setup](docs/development.md) - Setting up your development environment\n- [API Documentation](docs/api.md) - Complete API reference\n\n### 🔒 Security\nPlease review our [Security Policy](SECURITY.md) for information on:\n- Reporting security vulnerabilities\n- Responsible disclosure guidelines\n- Security best practices\n- Bug bounty information\n\n### 💰 Support the Project\nIf you find this project helpful, consider supporting its development:\n- ⭐ Star the repository\n- 🍴 Fork and contribute\n- 💝 [Make a donation](DONATE.md)\n- 📢 Share with the community\n\n## 📄 License\n\nThis project is licensed under the Apache License 2.0 - see the [LICENSE](LICENSE) file for details.\n\n## ⚠️ Disclaimer\n\nThis software is provided for educational and authorized testing purposes only. The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have proper authorization before using this tool on any systems.\n\n## 🙏 Acknowledgments\n\n- **Metasploit Framework** - The foundational exploitation framework\n- **NIST Cybersecurity Framework** - Security guidelines and standards\n- **OWASP** - Web application security methodology\n- **CVE/NVD** - Vulnerability database and scoring\n- **The Cybersecurity Community** - For continuous research and innovation\n\n## 📞 Support \u0026 Contact\n\n### 🌐 Connect with ZehraSec\n- **Website**: [www.zehrasec.com](https://www.zehrasec.com)\n- **Instagram**: [@_zehrasec](https://www.instagram.com/_zehrasec?igsh=bXM0cWl1ejdoNHM4)\n- **Facebook**: [ZehraSec Official](https://www.facebook.com/profile.php?id=61575580721849)\n- **X (Twitter)**: [@zehrasec](https://x.com/zehrasec?t=Tp9LOesZw2d2yTZLVo0_GA\u0026s=08)\n- **LinkedIn**: [ZehraSec Company](https://www.linkedin.com/company/zehrasec)\n\n### 👨‍💻 Connect with Yashab Alam (Creator)\n- **GitHub**: [@yashab-cyber](https://github.com/yashab-cyber)\n- **Instagram**: [@yashab.alam](https://www.instagram.com/yashab.alam)\n- **LinkedIn**: [Yashab Alam](https://www.linkedin.com/in/yashab-alam)\n- **Email**: yashabalam707@gmail.com\n\n### 🔧 Technical Support\n- **Documentation**: [Installation Guide](docs/installation.md)\n- **Issues**: [GitHub Issues](https://github.com/yashab-cyber/metasploit-ai/issues)\n- **Discussions**: [GitHub Discussions](https://github.com/yashab-cyber/metasploit-ai/discussions)\n- **WhatsApp Business**: [ZehraSec Channel](https://whatsapp.com/channel/0029Vaoa1GfKLaHlL0Kc8k1q)\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n**Made with ❤️ by [Yashab Alam](https://github.com/yashab-cyber) and the [ZehraSec](https://www.zehrasec.com) Team**\n\n*Advancing Cybersecurity Through AI Innovation*\n\n\u003c/div\u003e\n\n[ZehraSec Website](https://www.zehrasec.com) • [GitHub Repository](https://github.com/yashab-cyber/metasploit-ai) • [Issues](https://github.com/yashab-cyber/metasploit-ai/issues) • [Documentation](docs/README.md)\n\n\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyashab-cyber%2Fmetasploit-ai","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyashab-cyber%2Fmetasploit-ai","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyashab-cyber%2Fmetasploit-ai/lists"}