Token导航 LogoToken导航TokenDH.com
MCP Pentest (Adriyansyah Mf) logo
安全风控未说明官方级别未说明来源级核验

MCP Pentest (Adriyansyah Mf)

MCP Server

MCP Pentest是一个智能自动化渗透测试框架,能够自动执行侦察、漏洞扫描和受控利用,适用于授权安全测试和安全研究。

工具数

0

提示词数

0

GitHub Stars

6

资源数

0
渗透测试安全TypeScriptClaudeClaude

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

作者 / 组织

adriyansyah-mf

提供方

adriyansyah-mf

最后核验

2026/5/17 20:21

快速接入

先看主来源和安装命令,再打开仓库或文档;下面只保留这个条目的关键接入事实。

详细介绍

MCP Pentest - Automated Penetration Testing Framework

MCP (Model Context Protocol) server untuk automated penetration testing yang cerdas. Framework ini dapat secara otomatis melakukan reconnaissance, vulnerability scanning, dan controlled exploitation berdasarkan teknologi target yang terdeteksi.

🚀 Features

🔍 Reconnaissance Tools

  • Port Scanning - Comprehensive Nmap integration dengan berbagai scan modes
  • Subdomain Enumeration - Certificate transparency logs + DNS bruteforcing
  • Technology Detection - Automatic web technology fingerprinting
  • Directory Bruteforcing - Intelligent directory and file discovery

🛡️ Vulnerability Assessment

  • Nuclei Integration - Automated vulnerability scanning dengan template database
  • Nikto Scanning - Web server vulnerability detection
  • SQLMap Integration - SQL injection testing
  • Custom Web Vulnerability Checks - XSS, Directory Traversal, Command Injection, dll

⚡ Exploitation Modules

  • Metasploit Integration - Automatic exploit search dan execution
  • Custom Exploit Attempts - Framework-specific exploitation
  • Technology-Specific Exploits - Targeted attacks berdasarkan tech stack
  • Proof-of-Concept Generation - Automated PoC creation

🤖 Intelligent Workflow Engine

  • Adaptive Decision Making - AI-driven next step recommendations
  • Risk-Based Prioritization - Smart vulnerability prioritization
  • Technology-Aware Testing - Customized testing berdasarkan detected technologies
  • Automated Workflow Management - Sequential phase execution dengan dependency handling

📊 Comprehensive Reporting

  • Multi-Format Reports - HTML, PDF, JSON, Markdown output
  • Executive Summaries - Business-friendly risk assessments
  • Technical Details - Detailed vulnerability descriptions dan remediation
  • Evidence Collection - Automatic proof collection dan documentation

📋 Prerequisites

Required Tools

Pastikan tools berikut sudah terinstall di sistem:

# Network scanning
sudo apt install nmap

# Web vulnerability scanning
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

# Web server scanning
sudo apt install nikto

# SQL injection testing
sudo apt install sqlmap

# Optional: Metasploit (untuk advanced exploitation)
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall
chmod 755 msfinstall
sudo ./msfinstall

Node.js Dependencies

npm install

🛠️ Installation

  1. Clone repository
git clone 
cd mcp-pentest
  1. Install dependencies
npm install
  1. Build project
npm run build
  1. Configure MCP client

Tambahkan ke file konfigurasi MCP client Anda:

{
  "mcpServers": {
    "pentest": {
      "command": "node",
      "args": ["path/to/mcp-pentest/dist/index.js"],
      "env": {}
    }
  }
}

🎯 Usage Examples

Basic Automated Pentest

// Full scope automated pentest
await mcp.call("auto_pentest", {
  target: "example.com",
  scope: "full",
  intensity: "active"
});

Reconnaissance Only

// Port scanning
await mcp.call("nmap_scan", {
  target: "192.168.1.1",
  scan_type: "aggressive"
});

// Technology detection
await mcp.call("tech_detection", {
  url: "https://example.com"
});

// Subdomain enumeration
await mcp.call("subdomain_enum", {
  domain: "example.com"
});

Vulnerability Scanning

// Nuclei scan with specific templates
await mcp.call("nuclei_scan", {
  target: "https://example.com",
  templates: ["cves", "vulnerabilities"],
  severity: "high"
});

// SQL injection testing
await mcp.call("sqlmap_scan", {
  url: "https://example.com/login.php",
  data: "username=admin&password=test"
});

Exploitation Attempts

// Search for Metasploit modules
await mcp.call("metasploit_search", {
  service: "Apache 2.4.41",
  platform: "linux"
});

// Attempt exploitation
await mcp.call("exploit_attempt", {
  target: "192.168.1.100",
  vulnerability: "SQL Injection",
  payload: "UNION SELECT"
});

Intelligent Next Steps

// Get AI-powered recommendations
await mcp.call("suggest_next_steps", {
  scan_results: JSON.stringify(previousResults)
});

Report Generation

// Generate comprehensive report
await mcp.call("generate_report", {
  target: "example.com",
  format: "html"
});

🔧 Configuration

Scan Intensity Levels

Passive

  • Certificate transparency logs
  • DNS enumeration
  • Header analysis
  • Public information gathering

Active

  • Port scanning
  • Directory bruteforcing
  • Vulnerability scanning
  • Service enumeration

Aggressive

  • Full port range scanning
  • Intensive directory bruteforcing
  • Active exploitation attempts
  • Comprehensive vulnerability testing

Scope Options

Network

  • Port scanning
  • Service enumeration
  • Network vulnerability assessment

Web

  • Web application testing
  • Technology fingerprinting
  • Web vulnerability scanning

Full

  • Comprehensive assessment
  • Network + Web testing
  • Complete attack surface analysis

🛡️ Security Considerations

Ethical Usage

⚠️ IMPORTANT: Framework ini hanya boleh digunakan untuk:

  • Authorized penetration testing
  • Security research dengan permission
  • Testing terhadap sistem milik sendiri
  • Educational purposes

Safety Features

  • Rate limiting - Automatic request throttling
  • Timeout controls - Prevent long-running scans
  • Scope validation - Target validation dan restriction
  • Safe exploitation - Controlled dan reversible tests

Legal Compliance

  • Pastikan ada written authorization sebelum testing
  • Comply dengan local laws dan regulations
  • Respect responsible disclosure practices
  • Document semua testing activities

📊 Sample Output

Automated Pentest Results

{
  "workflow": {
    "target": "example.com",
    "scope": "full",
    "phases": [
      {
        "name": "reconnaissance",
        "status": "completed",
        "tools": ["nmap_scan", "subdomain_enum", "tech_detection"]
      }
    ],
    "results": {
      "reconnaissance": {
        "open_ports": [
          {"port": 80, "service": "http", "version": "Apache 2.4.41"},
          {"port": 443, "service": "https", "version": "Apache 2.4.41"}
        ],
        "technologies": [
          {"technology": "WordPress", "version": "5.8", "confidence": 95}
        ]
      },
      "vulnerabilities": [
        {
          "name": "Outdated WordPress",
          "severity": "medium",
          "description": "WordPress version 5.8 has known vulnerabilities"
        }
      ],
      "risk_score": 65,
      "threat_level": "medium"
    }
  }
}

🔄 Workflow Engine

Framework menggunakan intelligent workflow engine yang dapat:

  1. Analyze scan results - Automatically interpret findings
  2. Make decisions - Determine next testing steps
  3. Adapt strategy - Modify approach based on discoveries
  4. Prioritize actions - Focus on high-impact vulnerabilities
  5. Generate insights - Provide actionable recommendations

Decision Making Logic

Reconnaissance → Technology Detection → Vulnerability Assessment → Risk Analysis → Exploitation → Reporting
     ↓              ↓                    ↓                    ↓             ↓            ↓
 Port Discovery → CMS/Framework → Targeted Scanning → Priority Queue → Controlled → Evidence
 Subdomain Enum → Version Info → Custom Checks → Risk Scoring → Attempts → Collection

🏗️ Architecture

┌─────────────────┐    ┌──────────────────┐    ┌─────────────────┐
│   MCP Client    │    │  MCP Protocol    │    │  Pentest Server │
│  (Claude/etc)   │◄──►│   Transport      │◄──►│    (Node.js)    │
└─────────────────┘    └──────────────────┘    └─────────────────┘
                                                        │
                                               ┌─────────────────┐
                                               │ Tool Integration │
                                               │   - Nmap        │
                                               │   - Nuclei      │
                                               │   - Nikto       │
                                               │   - SQLMap      │
                                               │   - Metasploit  │
                                               └─────────────────┘

🤝 Contributing

  1. Fork repository
  2. Create feature branch
  3. Implement changes dengan tests
  4. Submit pull request
  5. Follow security best practices

📜 License

MIT License - See LICENSE file for details

⚠️ Disclaimer

Tool ini dibuat untuk tujuan educational dan authorized security testing. User bertanggung jawab untuk memastikan penggunaan yang legal dan ethical. Developer tidak bertanggung jawab atas penyalahgunaan tool ini.

🆘 Support

目录标签

目录标签

渗透测试安全TypeScriptClaude本地部署安全评估漏洞扫描自动化测试网络安全

支持客户端

Claude

接入字段

传输方式(transport,传输协议)

未说明

鉴权方式(authType,认证方式)

session

部署方式(deploymentType,部署类型)

local-only

工具数量(toolCount,工具数)

0

资源数量(resourceCount,资源数)

0

提示词数量(promptCount,提示词数)

0

权限和风险

未说明sessionlocal-only

接入前请确认传输方式、认证方式和部署位置,并根据实际工具能力限制访问范围。

安装前确认

不要直接授予不必要的文件、网络或账号权限;先核对安装命令和配置内容。

仍需确认:installCommand

来源信息

继续浏览同类 MCP