voodooEntity

The following rant is not against the owner/project - but...

What an irony. I cant publish a attack surface mapping / pentesting tool i wrote which runs fully deterministic and really controlable due to "dual use" legal problems - but llm driven tools hit public space......

sorry for the rant....

show comments
vctrnk

This looks interesting. My current phone is an Asus ROG Phone 3, which I think suffices (Snapdragon 865+ plus 12Gb RAM) but isn't rooted. Even on outdated Android 12 this phone covers everything I could possibly need as-is, and I don't intend to replace it. But, this might be the final push to upgrade ROM to something newer. I saw crDroid 16.0 still supports this ROG variant.

Will this work with Nethunter Rootless, or ir Magisk support w/root imperative?

haeseong

What does the 50% look like when it fails? Garbage the parser throws out is easy to handle, but a well formed command aimed at the wrong host gets past the scope check, and you would only catch that reading the report afterward.

aaa_aaa

Judas Priest reference?

baddash

little bit unrelated, but I watched the IG video and I thought the visual design of the app was cool af! what inspired the style?

kreidema

I completely forgot that AI can very much also attack networks/devices in the wild. Interesting project.

oquidave

Why phone? This cuts out a lot of phones. Why not on a computer?

show comments
imranshah10140

Will this work on iphones as well.

NickySlicks

I built Nightcrawler, an open-source autonomous penetration-testing agent that runs entirely on an Android phone.

The project started with a question: how much of a real pentesting workflow could I run locally on relatively old mobile hardware, without relying on a cloud model or API?

Nightcrawler runs a 1.2B-parameter model locally on the Adreno GPU of a OnePlus 8. The model chooses targets and tools, while a separate scope-enforcement proxy validates every command before execution. The system maintains per-host memory in SQLite, rotates between targets, matches detected versions against a local CVE database, executes multi-step playbooks, and generates a structured report.

A few implementation details that may be interesting:

Local inference runs at roughly 115 prompt tokens/sec and 13 generated tokens/sec. The small model only produces a usable command around 50% of the time, so much of the engineering is recovery logic, duplicate detection, persistent memory, and deterministic playbooks. Every command passes through a separate scope and safety layer rather than trusting the model to remain in scope. The project includes a dry-run mode, so the agent loop can be tested without executing real network commands or owning the phone hardware. I've had it running on my home network for the past 3 months uninterrupted

show comments