Research previewSwiss Applied AI Cybersecurity Research Lab

Meet , your open-source AI
cybersecurity team.

It hacks, proves the problem, and writes the fix.
Multi-model, multi-agent, but most importantly: yours.

Paste into your coding agent

Install the open-source 0sec security CLI and use it in this project. 1. Install it: curl -fsSL https://raw.githubusercontent.com/0sec-labs/0sec/main/install.sh | bash 2. Verify it: 0 --help 3. Read https://0.security/llms.txt to learn its commands, then run it directly. For example: 0 review . or 0 scan --target <url> --scope ./scope.json. Add --format sarif for machine-readable output. Only run 0sec against targets I am authorized to test. It is scope-gated and reproduces every finding before reporting, so treat unreproduced output as a lead and ask me before it changes any files.
Open in Cursorfor any other agent

The Swiss Army knife for offensive security.

Built to be extensible. Create and add your own tools as you go.

NetworkIdentity, AD, cloud and federationWeb applicationsSQLi, IDOR, XSS, SSRF, auth bypassAPIsTenant isolation, BOLA, business-logic abuseAI & LLMsPrompt injection, jailbreaks, MCP tool abuseSource codeInjection, auth, deserialization, memory safetyDependenciesSupply chain, malicious packages, CVE replayRuntimeContainer escape, sandbox and VM boundariesOperating systemPrivilege escalation, service and library flawsKernel0-day hunt into the layer beneath it all0sec goesall the way down.Where most pentests andtoday's AI tools stop.
Pentest a web app, AI/LLM endpoint, or MCP serverblack-boxwhite-box
scanevalagent-assure
Review source, packages, C/C++, or a kernel treewhite-box
reviewfile-reviewdeep-reviewaudit
Recon an attack surfaceblack-box
reconjs-reconnpm-discoveryintel
Hunt a bug class or kernel variantswhite-box
huntkernelcve
Work with the evidence a run produced
findingshistoryresumereplayverifytimelinedisclose
Generate and re-test a source fixwhite-box
fix
Assess identity and AD posture, read-only and offline
identityadgraphentragraph
Analyze a compiled binary, no sourceblack-box
0verse
Integrate it
mcp-serverconsoletuidashboard

It proves the bug before it reports it.

A blind verification agent re-exploits every finding. What it can't reproduce never ships.

Free-form agents, hard guardrails

The models decide what to probe. Turn budgets, loop detection, and scope on every call keep them in line.

Reproduce before trust

A blind agent re-exploits each finding from the PoC alone. What it can't reproduce is dropped.

Triage before verify

Class oracles and a second scanner cut the noise before the expensive step runs.

Bring your own model

Anthropic, OpenAI, Azure, OpenRouter, or local. You hold the key.

Run it your way.

Foxguard

Open-source first-pass scanner for your own codebase.

0sec harness

The full agentic engine and CLI. Self-hosted, on your own targets.

0cloud

The same engine, run for you. Isolated sandboxes, scheduling, evidence handling.

Running this across a whole company?

We come in and test it with you, using the same engine.