LLMtary is a Flutter-based desktop application designed to automate the full penetration testing lifecycle using large language models. It targets security professionals seeking an autonomous tool that not only identifies vulnerabilities but also confirms them through real command execution, providing actionable proof and comprehensive reports. The platform is available for Windows, macOS, and Linux, supporting both local and cloud-based AI models for flexibility in deployment, including air-gapped environments.
The tool operates through a phased engagement workflow that mirrors real-world penetration testing. Its autonomous reconnaissance engine conducts discovery tasks such as port scanning, service banner collection, DNS enumeration, and web application firewall detection, compiling enriched JSON data for subsequent analysis. The two-phase analysis pipeline begins with context-building through CVE matching, DNS/OSINT, and network service evaluation, followed by targeted vulnerability analysis across web applications, Active Directory, SSL/TLS, privilege escalation, and multiple technology-specific deep-dives. Each finding is subjected to an agentic exploit loop, where the LLM plans, executes, evaluates, and adapts commands on the target system until a vulnerability is confirmed or dismissed.
LLMtary incorporates advanced features such as attack chain reasoning, which identifies multi-step attack paths by combining confirmed vulnerabilities, and a credential bank that collects and reuses discovered credentials for deeper analysis. Post-exploitation enumeration is triggered upon confirming remote code execution or privileged access, automatically gathering information on users, credentials, network interfaces, running services, and potential escalation vectors. Safety controls are built in, including a hard blocklist for dangerous commands, scope enforcement, and an optional command approval mode for manual review before execution.
Reporting is a central capability, with the platform generating professional HTML, Markdown, or CSV reports. 1 metadata, severity badges, business risk assessments, and inline proof commands. The application supports integration with several AI providers, including local options like Ollama and LM Studio, and cloud services such as Anthropic Claude, OpenAI ChatGPT, Google Gemini, and OpenRouter. Settings for each provider are saved individually, allowing seamless switching between them. LLMtary thus serves as a comprehensive, autonomous AI-driven penetration testing platform for security practitioners.
In the Security & compliance platforms space, LLMtary takes a focused approach. It focuses on automating the penetration testing lifecycle to discover and validate vulnerabilities efficiently. LLMtary is a B2B product aimed at penetration testers and security professionals. It ships for the web, macOS, Windows, and Linux.
LLMtary first shipped in 2026. Development happens publicly on GitHub with 25 stars and 35 commits in the last 90 days. Key capabilities include autonomous recon, exploit validation, and report generation.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do