Authorized testing only

VICTOR

Vulnerability Intelligence, Cyber Triage & Offensive Reconnaissance

AI-assisted vulnerability intelligence for authorized security operations.

Built for CTFs, lab environments, internal assessments and assets you own or are explicitly authorized to test. Every session requires a recorded authorization scope.

Active Sessions

4

+1 today

Assets Mapped

37

12 in lab scope

Findings

18

3 high severity

Reports Generated

6

2 this week

mission console — lab-web-01 · safe mode live
$ victor session open --scope internal-lab --auth-token ****
[ok] authorization manifest verified: lab-web-01 (owned asset)
$ victor recon service-inventory 10.10.10.25 --safe-mode
[scan] 5/5 service banners collected in 1.8s
  22/tcp   ssh    OpenSSH 7.4
  443/tcp  https  nginx 1.18.0 (TLS 1.0 enabled)
[ai] backend=ollama:llama3.1 latency=412ms tokens=1,284
[note] findings queued for analyst review — no exploitation performed

VICTOR analysis

Legacy SSH build and TLS 1.0 on the lab host indicate an outdated package baseline. Recommend authenticated configuration review and evidence capture before drafting remediation guidance. No exploitation performed.

Open source project

MIT LicensePython AgentLocal ModelsMulti-Backend AICommunity Driven

Scoped by design

Sessions require an authorization record: owned asset, lab range, CTF, or signed internal engagement.

Evidence first

Every finding tracks confidence, evidence and remediation so reports stand up to review.

Report ready

Executive summaries, technical findings, CTF notes and remediation plans in HTML, PDF, MD or JSON.