pentest-mcp-server

Offline methodology engine for authorized penetration testing, CTF, and security research.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
97%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~7,499Tokens (tool definitions)
~13.5 KBTypical response size
Significant attention impact (5.86% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "pentest-mcp-server": {
      "command": "bun",
      "args": [
        "@cyanheads/pentest-mcp-server"
      ]
    }
  }
}

Runnable packages

npm@cyanheads/pentest-mcp-server0.1.9streamable-http

Remote endpoints

https://pentest.caseyjhand.com/mcpstreamable-http

What it can do

Tool inventory

Tools (7)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢pentest_guide(vector, target_context, phase)

Return an authorized-testing methodology for a selected vector and optional target context. The playbook covers reconnaissance, enumeration, exploitation, and post-exploitation phases with objectives, techniques, detection signals, mitigations, common pitfalls, references, and context-derived tool suggestions across 15 vectors.

Input Schema

{
  "type": "object",
  "properties": {
    "vector": {
      "type": "string",
      "enum": [
        "auth_bypass",
        "idor",
        "ssrf",
        "xss",
        "sqli",
        "xxe",
        "path_traversal",
        "cors",
        "csrf",
        "open_redirect",
        "deserialization",
        "race_condition",
        "ssti",
        "command_injection",
        "jwt_attack"
      ],
      "description": "Attack vector to retrieve methodology for. Each vector has its own methodology branch covering recon through exploitation. Authorized testing only."
    },
    "target_context": {
      "description": "Optional target profile for authorized engagement. Providing this narrows the playbook to what is most relevant for the specific environment.",
      "type": "object",
      "properties": {
        "stack": {
          "description": "Technology stack (e.g., \"Node.js + Express + PostgreSQL\", \"PHP 7.4 + Apache\", \"Spring Boot\"). Narrows methodology to stack-specific techniques.",
          "type": "string"
        },
        "waf": {
          "description": "WAF or filter in use (e.g., \"Cloudflare\", \"AWS WAF\", \"ModSecurity CRS\", \"custom regex\"). Triggers bypass-aware variants in payload suggestions.",
          "type": "string"
        },
        "recon_notes": {
          "description": "Freeform recon findings to incorporate. E.g., \"endpoint /api/users/{id} reflects user input in JSON response\". Narrows which phases are most relevant.",
          "type": "string"
        }
      }
    },
    "phase": {
      "default": "all",
      "description": "Methodology phase selector. \"all\" returns the complete playbook; a named phase returns only that phase.",
      "type": "string",
      "enum": [
        "all",
        "recon",
        "enumeration",
        "exploitation",
        "post_exploitation"
      ]
    }
  },
  "required": [
    "vector"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "vector": {
      "type": "string",
      "description": "The requested attack vector."
    },
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that this methodology applies to authorized testing only. Included in every response."
    },
    "phases": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "phase": {
            "type": "string",
            "description": "Phase name (e.g., \"Reconnaissance\", \"Exploitation\")."
          },
          "objectives": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "An objective for this phase."
            },
            "description": "Discovery or execution objectives for this phase."
          },
          "techniques": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "name": {
                  "type": "string",
                  "description": "Technique name."
                },
                "description": {
                  "type": "string",
                  "description": "How to perform the technique in authorized testing."
                },
                "detection": {
                  "type": "string",
                  "description": "Observable logs, signatures, and anomalies for this technique."
                },
                "mitigation": {
                  "type": "string",
                  "description": "Configuration or control that prevents or reduces impact."
                },
                "stack_note": {
                  "description": "Stack-specific variant or consideration. Present only when target_context.stack was provided and a relevant note exists.",
                  "type": "string"
                }
              },
              "required": [
                "name",
                "description",
                "detection",
                "mitigation"
              ],
              "additionalProperties": false,
              "description": "A specific technique for this phase with detection and mitigation context."
            },
            "description": "Applicable techniques for this phase."
          },
          "tools_commonly_used": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "A tool commonly used in this phase."
            },
            "description": "Named tools commonly associated with this phase."
          },
          "common_mistakes": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "A common mistake."
            },
            "description": "Pitfalls that lead to missed findings or noisy testing."
          }
        },
        "required": [
          "phase",
          "objectives",
          "techniques",
          "tools_commonly_used",
          "common_mistakes"
        ],
        "additionalProperties": false,
        "description": "A methodology phase covering one stage of the authorized testing workflow."
      },
      "description": "Ordered methodology phases. Contains only the requested phase when phase input is not \"all\"."
    },
    "owasp_references": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "An OWASP test case ID."
      },
      "description": "Relevant OWASP Testing Guide test case IDs (e.g., \"WSTG-INPV-01\")."
    },
    "attack_technique_ids": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "An ATT&CK technique ID."
      },
      "description": "Relevant ATT&CK technique IDs for cross-referencing with pentest_lookup_technique."
    },
    "nextToolSuggestions": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "toolName": {
            "type": "string",
            "description": "Suggested tool name (e.g., \"pentest_generate_payloads\")."
          },
          "reason": {
            "type": "string",
            "description": "Relationship between the playbook and the suggested tool."
          },
          "args": {
            "type": "object",
            "propertyNames": {
              "type": "string"
            },
            "additionalProperties": {},
            "description": "Arguments derived from the methodology context."
          }
        },
        "required": [
          "toolName",
          "reason",
          "args"
        ],
        "additionalProperties": false,
        "description": "A suggested tool with arguments derived from the playbook."
      },
      "description": "Suggested tools and arguments derived from the playbook."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode."
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "vector",
        "authorized_use_reminder",
        "phases",
        "owasp_references",
        "attack_technique_ids",
        "nextToolSuggestions"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢pentest_analyze_response(response_headers, response_body, status_code, context)

Analyze an HTTP response from authorized probing for information leakage, fingerprinting signals, and related exposure. Structured findings cover version disclosures, stack traces, debug headers, internal paths, authentication patterns, CORS configuration, detection signals, remediation, and associated methodology vectors.

Input Schema

{
  "type": "object",
  "properties": {
    "response_headers": {
      "description": "Raw HTTP response headers, optionally including the status line. Maximum 20,000 characters.",
      "type": "string",
      "maxLength": 20000
    },
    "response_body": {
      "description": "Raw HTML, JSON, XML, or error response body text. Maximum 10,000 characters.",
      "type": "string",
      "maxLength": 10000
    },
    "status_code": {
      "description": "HTTP status code (100–599). Helps classify the response type.",
      "type": "integer",
      "minimum": 100,
      "maximum": 599
    },
    "context": {
      "description": "Freeform context about the authorized test target — e.g., \"login endpoint\", \"GraphQL API\", \"file upload handler\". Narrows the pattern matching to relevant categories. Max 2,000 characters.",
      "type": "string",
      "maxLength": 2000
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that response analysis is for authorized testing only. Rendered first."
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "category": {
            "type": "string",
            "enum": [
              "version_disclosure",
              "stack_trace",
              "internal_path",
              "debug_header",
              "technology_fingerprint",
              "auth_pattern",
              "cors_misconfiguration",
              "security_header_missing",
              "interesting_field",
              "error_message"
            ],
            "description": "Finding category. version_disclosure = server/app version exposed; stack_trace = exception stacktrace leaked; internal_path = filesystem/internal route visible; debug_header = diagnostic header present; technology_fingerprint = framework/language signal; auth_pattern = JWT/cookie/auth mechanism visible; cors_misconfiguration = permissive CORS policy; security_header_missing = CSP/X-Frame-Options absent; interesting_field = non-obvious field worth noting; error_message = application/database error text."
          },
          "severity": {
            "type": "string",
            "enum": [
              "info",
              "low",
              "medium",
              "high"
            ],
            "description": "Relative impact in an authorized testing context. info = fingerprinting only; low = indirect exposure; medium = useful for chaining; high = directly exploitable."
          },
          "finding": {
            "type": "string",
            "description": "What was detected and where — header name, body excerpt, or field path with surrounding context."
          },
          "significance": {
            "type": "string",
            "description": "Why this finding matters for an authorized penetration test."
          },
          "detection": {
            "type": "string",
            "description": "Observable signals associated with exploitation of this finding."
          },
          "remediation": {
            "type": "string",
            "description": "Recommended fix for the target application."
          },
          "suggested_vector": {
            "description": "Pentest_guide vector name for follow-up when this finding maps to an attack vector. Absent when no direct vector mapping exists.",
            "type": "string"
          }
        },
        "required": [
          "category",
          "severity",
          "finding",
          "significance",
          "detection",
          "remediation"
        ],
        "additionalProperties": false,
        "description": "A single leakage or fingerprinting finding."
      },
      "description": "Structured findings ordered by severity descending (high first)."
    },
    "fingerprints": {
      "type": "object",
      "properties": {
        "server_software": {
          "description": "Detected server software and version (e.g., \"Apache/2.4.54\", \"nginx/1.25\").",
          "type": "string"
        },
        "framework": {
          "description": "Detected framework or runtime (e.g., \"Express 4.x\", \"Spring Boot\").",
          "type": "string"
        },
        "language": {
          "description": "Detected backend language (e.g., \"PHP\", \"Python\", \"Java\").",
          "type": "string"
        },
        "database": {
          "description": "Detected database technology if disclosed.",
          "type": "string"
        },
        "cloud_provider": {
          "description": "Detected cloud provider or CDN.",
          "type": "string"
        },
        "other": {
          "type": "array",
          "items": {
            "type": "string",
            "description": "A technology signal."
          },
          "description": "Other technology signals detected."
        }
      },
      "required": [
        "other"
      ],
      "additionalProperties": false,
      "description": "Detected server, framework, language, database, cloud, and other technology signals."
    },
    "summary": {
      "type": "string",
      "description": "One-paragraph summary of findings and associated follow-up actions."
    },
    "nextToolSuggestions": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "toolName": {
            "type": "string",
            "description": "Suggested tool name (e.g., \"pentest_guide\")."
          },
          "reason": {
            "type": "string",
            "description": "Relationship between the analysis findings and the suggested tool."
          },
          "args": {
            "type": "object",
            "propertyNames": {
              "type": "string"
            },
            "additionalProperties": {},
            "description": "Arguments derived from detected fingerprints and findings."
          }
        },
        "required": [
          "toolName",
          "reason",
          "args"
        ],
        "additionalProperties": false,
        "description": "A suggested tool with arguments derived from the analysis."
      },
      "description": "Suggested tools derived from detected fingerprints and findings."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `no_input`: Neither response_headers nor response_body was provided. Other values are possible when a failure originates below the handler.",
              "examples": [
                "no_input"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "authorized_use_reminder",
        "findings",
        "fingerprints",
        "summary",
        "nextToolSuggestions"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢pentest_lookup_technique(query, include_subtechniques)

Look up a MITRE ATT&CK technique by exact ID or keyword. Results include tactics, platforms, description, detection data, public procedure examples, mitigations, related sub-techniques, and dataset version.

Input Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "ATT&CK technique ID (e.g., \"T1190\", \"T1059.001\") or keyword describing the technique (e.g., \"sql injection\", \"pass the hash\", \"web shell upload\"). ID lookup is exact; keyword lookup returns the best match plus related techniques."
    },
    "include_subtechniques": {
      "default": true,
      "description": "Include sub-techniques in the result. Set to false when only the parent technique summary is needed.",
      "type": "boolean"
    }
  },
  "required": [
    "query"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that technique data is for authorized testing and research only. Rendered first."
    },
    "technique_id": {
      "type": "string",
      "description": "ATT&CK technique ID (e.g., \"T1190\")."
    },
    "name": {
      "type": "string",
      "description": "Technique name."
    },
    "tactics": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "A tactic name."
      },
      "description": "ATT&CK tactics this technique belongs to (e.g., \"Initial Access\", \"Execution\")."
    },
    "description": {
      "type": "string",
      "description": "ATT&CK description of the technique."
    },
    "platforms": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "A target platform."
      },
      "description": "Target platforms (e.g., \"Windows\", \"Linux\", \"Web Application\")."
    },
    "detection": {
      "type": "object",
      "properties": {
        "summary": {
          "type": "string",
          "description": "Overview of how defenders detect this technique."
        },
        "data_sources": {
          "type": "array",
          "items": {
            "type": "string",
            "description": "A relevant ATT&CK data source."
          },
          "description": "ATT&CK data sources relevant to detection."
        },
        "indicators": {
          "type": "array",
          "items": {
            "type": "string",
            "description": "A behavioral indicator or signature."
          },
          "description": "Concrete behavioral indicators and signatures."
        }
      },
      "required": [
        "summary",
        "data_sources",
        "indicators"
      ],
      "additionalProperties": false,
      "description": "ATT&CK detection context for the technique."
    },
    "mitigations": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "mitigation_id": {
            "type": "string",
            "description": "ATT&CK mitigation ID (e.g., \"M1050\")."
          },
          "name": {
            "type": "string",
            "description": "Mitigation name."
          },
          "description": {
            "type": "string",
            "description": "How this mitigation reduces the technique's effectiveness."
          }
        },
        "required": [
          "mitigation_id",
          "name",
          "description"
        ],
        "additionalProperties": false,
        "description": "A recommended ATT&CK mitigation with its ID, name, and effect description."
      },
      "description": "Recommended mitigations from ATT&CK."
    },
    "procedure_examples": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "group_or_software": {
            "type": "string",
            "description": "Threat group name or malware name that used this technique."
          },
          "description": {
            "type": "string",
            "description": "How the group or software used this technique, from public ATT&CK reporting."
          }
        },
        "required": [
          "group_or_software",
          "description"
        ],
        "additionalProperties": false,
        "description": "A real-world usage example from ATT&CK public reporting."
      },
      "description": "Real-world usage examples from ATT&CK public reporting."
    },
    "sub_techniques": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "description": "Sub-technique ID (e.g., \"T1059.001\")."
          },
          "name": {
            "type": "string",
            "description": "Sub-technique name."
          },
          "description": {
            "type": "string",
            "description": "Brief description of the sub-technique (first 200 chars)."
          }
        },
        "required": [
          "id",
          "name",
          "description"
        ],
        "additionalProperties": false,
        "description": "A sub-technique ID, name, and brief description."
      },
      "description": "Sub-techniques of this parent technique. Empty when querying a sub-technique itself, or when include_subtechniques is false."
    },
    "attack_version": {
      "type": "string",
      "description": "ATT&CK dataset version used (e.g., \"Enterprise v19.1\")."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `no_match`: No technique matched the query. Other values are possible when a failure originates below the handler.",
              "examples": [
                "no_match"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "authorized_use_reminder",
        "technique_id",
        "name",
        "tactics",
        "description",
        "platforms",
        "detection",
        "mitigations",
        "procedure_examples",
        "sub_techniques",
        "attack_version"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢pentest_lookup_group(query)

Look up a MITRE ATT&CK threat group or software entry by ID, name, or keyword. Results include ATT&CK identity, aliases, type, description, and associated techniques with procedure-level context from public ATT&CK reporting.

Input Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "ATT&CK threat group ID (e.g., \"G0007\"), software ID (e.g., \"S0002\"), or name/keyword (e.g., \"APT28\", \"Mimikatz\", \"Lazarus Group\"). ID lookup is exact and case-insensitive; name/keyword search returns the best match."
    }
  },
  "required": [
    "query"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that threat group data is for authorized testing and research only. Rendered first."
    },
    "id": {
      "type": "string",
      "description": "ATT&CK ID (e.g., \"G0007\" for a group, \"S0002\" for software)."
    },
    "name": {
      "type": "string",
      "description": "Primary display name (e.g., \"APT28\", \"Mimikatz\")."
    },
    "aliases": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "An alternate name for this group or software."
      },
      "description": "Known alternate names from ATT&CK."
    },
    "type": {
      "type": "string",
      "enum": [
        "group",
        "software"
      ],
      "description": "\"group\" for intrusion sets (threat actors), \"software\" for malware and tools."
    },
    "description": {
      "type": "string",
      "description": "ATT&CK description (truncated to 800 characters)."
    },
    "techniques_used": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "technique_id": {
            "type": "string",
            "description": "ATT&CK technique ID (e.g., \"T1190\")."
          },
          "technique_name": {
            "type": "string",
            "description": "Technique name."
          },
          "description": {
            "type": "string",
            "description": "How this group or software used the technique, from public ATT&CK reporting."
          }
        },
        "required": [
          "technique_id",
          "technique_name",
          "description"
        ],
        "additionalProperties": false,
        "description": "A technique used by this group or software with procedure context."
      },
      "description": "Up to 20 techniques associated with the group or software, including procedure-level context and technique IDs."
    },
    "attack_version": {
      "type": "string",
      "description": "ATT&CK dataset version used (e.g., \"Enterprise v19.1\")."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `no_match`: No group or software entry matched the query. Other values are possible when a failure originates below the handler.",
              "examples": [
                "no_match"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "authorized_use_reminder",
        "id",
        "name",
        "aliases",
        "type",
        "description",
        "techniques_used",
        "attack_version"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢pentest_map_techniques(stack, services, auth_type, os, limit)

Rank ATT&CK techniques and OWASP test cases against an authorized target profile of technology stack, exposed services, authentication type, and operating system. Results include profile-specific relevance, detection opportunities, mitigations, and associated methodology vectors.

Input Schema

{
  "type": "object",
  "properties": {
    "stack": {
      "description": "Technology stack components (e.g., [\"Node.js\", \"Express\", \"PostgreSQL\", \"Redis\"]). Each element matched against technique platform and procedure examples.",
      "type": "array",
      "items": {
        "type": "string",
        "description": "A technology stack component."
      }
    },
    "services": {
      "description": "Exposed services and interfaces (e.g., [\"REST API\", \"GraphQL\", \"file upload\", \"admin panel\"]). Narrows technique relevance.",
      "type": "array",
      "items": {
        "type": "string",
        "description": "An exposed service or interface."
      }
    },
    "auth_type": {
      "description": "Authentication mechanism in use. Surfaces auth-specific attack techniques.",
      "type": "string",
      "enum": [
        "jwt",
        "session_cookie",
        "api_key",
        "oauth2",
        "basic_auth",
        "ntlm",
        "kerberos",
        "none",
        "unknown"
      ]
    },
    "os": {
      "description": "Target operating system. Narrows to OS-specific techniques.",
      "type": "string",
      "enum": [
        "linux",
        "windows",
        "macos",
        "unknown"
      ]
    },
    "limit": {
      "default": 15,
      "description": "Maximum number of techniques to return (1–50, default 15). Higher values give broader coverage; lower values focus on highest-relevance items.",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that technique mapping is for authorized testing engagements only. Rendered first."
    },
    "ranked_techniques": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "technique_id": {
            "type": "string",
            "description": "ATT&CK technique ID (e.g., \"T1190\")."
          },
          "name": {
            "type": "string",
            "description": "Technique name."
          },
          "tactic": {
            "type": "string",
            "description": "Primary tactic (e.g., \"Initial Access\")."
          },
          "relevance_score": {
            "type": "number",
            "description": "Relative relevance to the supplied target profile; higher scores indicate stronger matches."
          },
          "relevance_rationale": {
            "type": "string",
            "description": "Explanation of why this technique is relevant to the provided target profile."
          },
          "detection_opportunity": {
            "type": "string",
            "description": "Primary observable detection opportunity (truncated to 200 characters)."
          },
          "mitigation_summary": {
            "type": "string",
            "description": "Key mitigation recommendation for this technique."
          },
          "pentest_guide_vector": {
            "description": "Associated pentest_guide methodology vector. Absent when no direct mapping exists.",
            "type": "string"
          }
        },
        "required": [
          "technique_id",
          "name",
          "tactic",
          "relevance_score",
          "relevance_rationale",
          "detection_opportunity",
          "mitigation_summary"
        ],
        "additionalProperties": false,
        "description": "A ranked ATT&CK technique with relevance rationale and defense context."
      },
      "description": "Techniques ordered by relevance_score descending."
    },
    "owasp_test_cases": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "test_id": {
            "type": "string",
            "description": "OWASP Testing Guide test case ID (e.g., \"WSTG-INPV-01\")."
          },
          "name": {
            "type": "string",
            "description": "Test case name."
          },
          "relevance": {
            "type": "string",
            "description": "Why this test case applies to the provided target profile."
          }
        },
        "required": [
          "test_id",
          "name",
          "relevance"
        ],
        "additionalProperties": false,
        "description": "An OWASP test case relevant to the target profile."
      },
      "description": "Relevant OWASP Testing Guide test cases for the profile (up to 10)."
    },
    "profile_summary": {
      "type": "string",
      "description": "One-sentence normalized summary of the supplied target profile."
    },
    "attack_version": {
      "type": "string",
      "description": "ATT&CK dataset version used for technique data."
    },
    "truncated": {
      "type": "boolean",
      "description": "True when ranked_techniques was capped by limit."
    },
    "shown": {
      "type": "number",
      "description": "Number of ranked techniques returned."
    },
    "cap": {
      "type": "number",
      "description": "The limit applied to ranked_techniques."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `no_profile`: No profile fields were provided. Other values are possible when a failure originates below the handler.",
              "examples": [
                "no_profile"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "authorized_use_reminder",
        "ranked_techniques",
        "owasp_test_cases",
        "profile_summary",
        "attack_version",
        "truncated",
        "shown",
        "cap"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢pentest_generate_payloads(category, injection_context, waf_profile, encoding, count)

Generate context-specific payload templates for authorized systems. Each template includes its vulnerability category, context rationale, WAF/IDS detection signature, mitigation, optional WAF research note, and optional encoded variant.

Input Schema

{
  "type": "object",
  "properties": {
    "category": {
      "type": "string",
      "enum": [
        "xss",
        "sqli",
        "ssrf",
        "xxe",
        "path_traversal",
        "ssti",
        "command_injection",
        "open_redirect",
        "csrf",
        "deserialization",
        "jwt",
        "ldap_injection",
        "nosql_injection",
        "http_header"
      ],
      "description": "Vulnerability category for payload generation."
    },
    "injection_context": {
      "type": "string",
      "enum": [
        "html_attribute",
        "html_body",
        "js_string",
        "js_template",
        "js_script_block",
        "url_parameter",
        "url_path",
        "sql_where",
        "sql_integer",
        "xml_element",
        "xml_attribute",
        "http_header",
        "json_value",
        "cookie_value",
        "file_name",
        "generic"
      ],
      "description": "Precise injection context. Critical for XSS: an HTML attribute payload differs from a JS string payload. Provide the most specific context for the best results."
    },
    "waf_profile": {
      "default": "none",
      "description": "WAF or filter in front of the authorized test target. When a specific WAF is named, bypass variants referencing known public research are included.",
      "type": "string",
      "enum": [
        "cloudflare",
        "aws_waf",
        "modsecurity_crs",
        "imperva",
        "akamai",
        "f5_bigip_asm",
        "nginx_modsecurity",
        "fortinet_fortiwaf",
        "none",
        "unknown"
      ]
    },
    "encoding": {
      "description": "Optional encoding chain applied left to right to each returned template.",
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "none",
          "url",
          "double_url",
          "html_entity",
          "unicode",
          "hex",
          "base64",
          "js_escape"
        ],
        "description": "An encoding step to apply."
      }
    },
    "count": {
      "default": 5,
      "description": "Number of payload variants to return (1–20, default 5). More variants cover different bypass approaches for the same context.",
      "type": "integer",
      "minimum": 1,
      "maximum": 20
    }
  },
  "required": [
    "category",
    "injection_context"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "category": {
      "type": "string",
      "description": "Requested payload category."
    },
    "injection_context": {
      "type": "string",
      "description": "Requested injection context."
    },
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that these templates are for authorized testing only."
    },
    "payloads": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "template": {
            "type": "string",
            "description": "The payload template string. Adapt to the specific authorized target — replace placeholder values as annotated."
          },
          "description": {
            "type": "string",
            "description": "What this payload tests and why it works in the specified injection context."
          },
          "detection_signature": {
            "type": "string",
            "description": "Signature a WAF or IDS might match, such as keywords or patterns."
          },
          "mitigation": {
            "type": "string",
            "description": "Input validation or encoding control that prevents this payload class."
          },
          "waf_bypass_note": {
            "description": "WAF-specific bypass technique and public research reference. Present only when waf_profile is not \"none\".",
            "type": "string"
          },
          "encoded_variant": {
            "description": "Encoded form of the template per the requested encoding chain. Absent when no encoding was requested.",
            "type": "string"
          }
        },
        "required": [
          "template",
          "description",
          "detection_signature",
          "mitigation"
        ],
        "additionalProperties": false,
        "description": "A payload template annotated with offense context (what it tests, how it works) and defense context (detection signature, mitigation)."
      },
      "description": "Payload templates ordered by coverage breadth, each annotated with offense and defense context."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode."
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "category",
        "injection_context",
        "authorized_use_reminder",
        "payloads"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢pentest_encode(payload, chain, explain)

Transform a payload string through an ordered encoding chain for authorized filter research. Results include the final value, intermediate values, optional decode path and rationale, and detection guidance. All transforms are local; no live probing occurs.

Input Schema

{
  "type": "object",
  "properties": {
    "payload": {
      "type": "string",
      "minLength": 1,
      "maxLength": 10000,
      "description": "Input payload string to encode. Max 10,000 characters."
    },
    "chain": {
      "minItems": 1,
      "maxItems": 6,
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "url",
          "double_url",
          "html_entity",
          "unicode",
          "hex",
          "base64",
          "js_escape",
          "null_byte",
          "mixed_case",
          "comment_break"
        ],
        "description": "An encoding step."
      },
      "description": "Ordered list of encodings to apply (1–6 steps). Applied left to right. E.g., [\"unicode\", \"url\"] applies Unicode escape first, then URL-encodes the result."
    },
    "explain": {
      "default": true,
      "description": "Whether to include the decode path and bypass rationale.",
      "type": "boolean"
    }
  },
  "required": [
    "payload",
    "chain"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "authorized_use_reminder": {
      "type": "string",
      "description": "Reminder that encoding transforms are for authorized bypass research only."
    },
    "original": {
      "type": "string",
      "description": "The input payload."
    },
    "encoded": {
      "type": "string",
      "description": "Final encoded payload after all chain steps applied."
    },
    "intermediate_steps": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "encoding": {
            "type": "string",
            "description": "Encoding name applied at this step."
          },
          "result": {
            "type": "string",
            "description": "Payload value after this encoding step."
          }
        },
        "required": [
          "encoding",
          "result"
        ],
        "additionalProperties": false,
        "description": "One encoding step in the chain with its output."
      },
      "description": "Intermediate values at each encoding step, for tracing the chain."
    },
    "decode_path": {
      "description": "Step-by-step explanation of how a decoder (WAF, server, browser) would reverse the encoding chain. Included when explain is true.",
      "type": "string"
    },
    "bypass_rationale": {
      "description": "Why this encoding combination might bypass common filter patterns. Included when explain is true.",
      "type": "string"
    },
    "detection_note": {
      "type": "string",
      "description": "Detection methods for encoded variants, including normalization and behavior signals."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `encoding_error`: An encoding step produced invalid output (e.g., base64 on invalid input). Other values are possible when a failure originates below the handler.",
              "examples": [
                "encoding_error"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "authorized_use_reminder",
        "original",
        "encoded",
        "intermediate_steps",
        "detection_note"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded7 tools
verifiedversion not recorded7 tools