NeuralReaper
AI-native security research platform that integrates Claude with MCP to execute real offensive security tools in an isolated Docker container, enabling natural language-driven recon, CVE scanning, Active Directory enumeration, and cryptographic posture assessment.
README
███╗ ██╗███████╗██╗ ██╗██████╗ █████╗ ██╗
████╗ ██║██╔════╝██║ ██║██╔══██╗██╔══██╗██║
██╔██╗ ██║█████╗ ██║ ██║██████╔╝███████║██║
██║╚██╗██║██╔══╝ ██║ ██║██╔══██╗██╔══██║██║
██║ ╚████║███████╗╚██████╔╝██║ ██║██║ ██║███████╗
╚═╝ ╚═══╝╚══════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝
██████╗ ███████╗ █████╗ ██████╗ ███████╗██████╗
██╔══██╗██╔════╝██╔══██╗██╔══██╗██╔════╝██╔══██╗
██████╔╝█████╗ ███████║██████╔╝█████╗ ██████╔╝
██╔══██╗██╔══╝ ██╔══██║██╔══██╗██╔══╝ ██╔══██╗
██║ ██║███████╗██║ ██║██║ ██║███████╗██║ ██║
╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
<div align="center">
AI-Native Security Research Platform — Claude × MCP × Real Offensive Tooling
Natural language in. Real recon, real CVE matches, real AD attack paths, real crypto posture out.
Table of Contents
- Why NeuralReaper
- Design Philosophy — Detection, Not Weaponization
- Architecture
- Tool Arsenal
- Quick Start
- Detailed Setup
- Usage Examples
- Security & Safety Design
- Engineering Notes — Real Problems Solved
- Project Structure
- Roadmap
- Contributing
- Disclaimer
- License
Why NeuralReaper
Most "AI + security" demos wire a chatbot up to a single API and call it a day. NeuralReaper instead gives Claude direct, sandboxed execution access to a real offensive security toolchain — the same binaries a human pentester would run from a terminal — through the Model Context Protocol.
The result: you describe an objective in plain English, and Claude plans and executes the actual recon — choosing tools, chaining scans, and reasoning over real output — instead of guessing from training data.
What makes it worth putting on a resume rather than just a script:
- A live, auto-updating CVE engine. Nuclei ships 12,000+ community templates and is updated continuously, so the scanner isn't frozen at whatever existed when the image was built.
- Isolated by design. Every tool runs inside a locked-down, non-root Ubuntu container — never on the host.
- A real engineering trail. Built across Windows + WSL2 + Docker Desktop + Claude Desktop, hitting (and solving) the exact integration failures documented below instead of glossing over them.
- Breadth across the full modern assessment surface — network/web recon, Active Directory attack-path enumeration, cryptographic/post-quantum posture, supply-chain dependency auditing, and local fuzzing — not just a wrapper around one scanner.
Design Philosophy — Detection, Not Weaponization
Comparable AI-agent pentest frameworks exist, and some — most notably HexStrike AI — ship an automated exploit-generation layer on top of recon/scanning. Within hours of HexStrike's public release, researchers observed threat actors discussing how to weaponize it against a Citrix NetScaler zero-day (CVE-2025-7775), compressing what used to take days of manual exploit development into roughly 10 minutes.
NeuralReaper deliberately stops one step earlier. Every tool here identifies, enumerates, and reports — it does not generate exploit payloads, and it never will. The CVE watchlist is lookup-only: it calls existing Nuclei templates and ExploitDB entries for matches, writing zero new detection or exploitation logic of its own.
That's a constraint, not a missing feature — and worth saying explicitly: building security tooling with an eye on how it could be misused is itself a skill.
Architecture
graph LR
U[Operator] -->|Natural language| CD[Claude Desktop]
CD <-->|MCP / stdio| DC[Docker Container]
subgraph "Isolated Container — non-root"
DC --> FM[FastMCP Server<br/>server.py — 46 tools]
FM --> NET[Network Recon<br/>nmap · masscan · whois · dig]
FM --> WEB[Web Scanning<br/>nikto · curl · openssl]
FM --> DIR[Content Discovery<br/>gobuster · ffuf · dirb]
FM --> CVE[Auto-CVE Engine<br/>nuclei — 12k+ templates]
FM --> WATCH[CVE Watchlist<br/>curated 2026 lookup]
FM --> INJ[Injection Testing<br/>sqlmap · xsstrike]
FM --> CMS[CMS Scanning<br/>wpscan]
FM --> AD[Active Directory<br/>certipy · bloodhound · bloodyAD · impacket]
FM --> CRYPTO[Crypto / PQC<br/>TLS+SSH algo inventory · HNDL risk]
FM --> HOST[Host Hardening<br/>chkrootkit · rkhunter · lynis]
FM --> SUPPLY[Supply Chain<br/>osv-scanner]
FM --> FUZZ[Fuzzing<br/>AFL++]
FM --> ORCH[full_recon Orchestrator<br/>+ session report generator]
FM --> EXP[Exploit Research<br/>searchsploit]
end
Claude Desktop spawns the container per-session over stdio — there is no persistent network listener, no exposed port, and no state retained between runs beyond what Docker itself caches (e.g. Nuclei's template directory) and the in-memory session log used by generate_report().
Tool Arsenal
| Category | Tool(s) | What it does |
|---|---|---|
| Network Recon | nmap, masscan, whois, dig, traceroute, ping |
Service/version detection, full-range port sweeps, DNS/WHOIS enumeration |
| Web Scanning | nikto, curl, openssl |
Misconfig checks, header inspection, TLS/cert validation |
| Content Discovery | gobuster, ffuf, dirb |
Directory/DNS brute-force, high-speed fuzzing |
| Auto-CVE Engine | nuclei |
12,000+ templates — CVEs, misconfig, exposures, default creds |
| Curated CVE Watchlist | cve_watchlist_scan |
Lookup-only orchestration of Nuclei + ExploitDB against a curated list of recent high-severity CVE IDs |
| Injection Testing | sqlmap, xsstrike |
SQL injection and XSS detection with WAF fingerprinting |
| CMS Scanning | wpscan |
WordPress core/plugin/theme vulnerability enumeration |
| Active Directory & Identity | certipy, bloodhound-python, bloodyAD, Impacket (GetUserSPNs.py, GetNPUsers.py) |
ADCS misconfig (ESC1–16), AD data collection, ACL/object enumeration, Kerberoast/AS-REProast detection |
| Cryptographic Inventory / Post-Quantum | nmap ssl-enum-ciphers / ssh2-enum-algos |
TLS & SSH algorithm inventory; Harvest-Now-Decrypt-Later risk classification |
| Host Hardening & Rootkit Detection | chkrootkit, rkhunter, lynis |
Signature-based rootkit checks and general Linux hardening audit |
| Ransomware-Relevant Exposure | nmap + nuclei (curated tags) | External RDP/SMB/VPN exposure check — attack-surface only, not infection detection |
| Supply Chain | osv-scanner |
Dependency CVE audit against the OSV.dev database |
| Fuzzing | AFL++ |
Crash-finding fuzzing harness automation against a local instrumented binary |
| OWASP Reference | — | Static Top-10 (Web) and Top-10 (Agentic/AI) checklists mapped to tool coverage |
| Recon Orchestrator | — | full_recon chains DNS/WHOIS/port/tech-fingerprint recon into one attack-surface summary with suggested test priorities by detected stack |
| Session Reporting | — | generate_report compiles every tool call this session into one Markdown report with a severity summary |
| Exploit Research | searchsploit |
Offline ExploitDB lookup by product or CVE |
46 MCP tools total — run tool_help inside Claude for the full callable list with parameters.
Quick Start
git clone https://github.com/the-artist111/NeuralReaper.git
cd NeuralReaper
docker build -t neuralreaper:latest .
Point Claude Desktop at it by merging claude_desktop_config.json into your own config, then restart Claude Desktop. Full instructions below.
Detailed Setup
<details> <summary><strong>Linux</strong></summary>
git clone https://github.com/the-artist111/NeuralReaper.git
cd NeuralReaper
docker build -t neuralreaper:latest .
mkdir -p ~/.config/Claude
cp claude_desktop_config.json ~/.config/Claude/claude_desktop_config.json
# restart Claude Desktop
</details>
<details> <summary><strong>Windows via WSL2 (recommended on Windows)</strong></summary>
- Install Docker Desktop for Windows.
- In Docker Desktop → Settings → Resources → WSL Integration, enable your distro (e.g. Ubuntu) and Apply & Restart.
- Inside your WSL2 distro:
git clone https://github.com/the-artist111/NeuralReaper.git cd NeuralReaper docker build -t neuralreaper:latest . - Copy the config to Windows (run from PowerShell, not WSL — cross-filesystem writes from WSL into
AppDataare frequently permission-denied):New-Item -ItemType Directory -Force -Path "$env:APPDATA\Claude" Copy-Item "\\wsl.localhost\Ubuntu\home\<user>\NeuralReaper\claude_desktop_config.json" "$env:APPDATA\Claude\claude_desktop_config.json" - Docker Desktop must be running before Claude Desktop launches the container — Claude calls
docker.exedirectly, and if the daemon isn't up yet you'll seefailed to connect to the docker API at npipe:////./pipe/dockerDesktopLinuxEngine. - Fully quit and reopen Claude Desktop (system tray → Quit, not just close-the-window).
</details>
<details> <summary><strong>Verifying the install</strong></summary>
bash tests/smoke_test.sh
Or check directly inside Claude Desktop: Settings → Developer → Local MCP servers. NeuralReaper should show a running badge. If it shows failed, click View Logs — the error is almost always either "Docker Desktop isn't running" or a stale docker path in the config.
</details>
Usage Examples
"Update Nuclei templates, then run a full CVE scan on 192.168.1.10"
"Check my lab DC against the curated CVE watchlist, then check its TLS for post-quantum readiness"
"Run certipy_find against my lab domain, then check for kerberoastable accounts"
"Run a full_recon on target.local and tell me what to prioritize testing"
"Audit this container's hardening with lynis, then run chkrootkit"
"Check 192.168.1.50 for ransomware-relevant exposure, then generate a report of everything we've found this session"
Sample tail of a real nuclei_scan run:
=== NUCLEI SCAN: http://192.168.56.10 [severity=critical,high,medium] ===
[CVE-2026-41940] [http] [critical] Apache HTTP Server path traversal — 192.168.56.10
[exposed-panel:phpmyadmin] [http] [medium] phpMyAdmin panel exposed — 192.168.56.10/pma/
[tech-detect:nginx] [http] [info] nginx 1.24.0 detected
Sample pqc_readiness_check output:
=== PQC / HNDL READINESS: target.local:443 ===
HNDL Risk Level: HIGH (classical-only key exchange — prioritize for PQ migration if data sensitivity/longevity is high)
- [HNDL RISK] No post-quantum hybrid key exchange group detected. Traffic captured today could be
decrypted retroactively once a sufficiently large quantum computer exists.
- [CLASSICAL] RSA key exchange/signature present — broken by Shor's algorithm on a sufficiently
large quantum computer. Long-lived sensitive data is the highest-priority migration candidate.
Security & Safety Design
This is a security tool, so it's held to its own standard:
- Non-root execution. The container runs as an unprivileged
pentesteruser; onlynmapandmasscanget the specificCAP_NET_RAW/CAP_NET_ADMINcapabilities they need viasetcap— nothing runs--privileged. - Input sanitization. Every target string is validated against a strict allow-list pattern before it touches a subprocess call; nothing is passed through a shell, so there's no string-concatenation injection surface.
- Hard timeouts. Every tool call is bounded (
MAX_TOOL_RUNTIME, default 180s) so a hung scan can't hang the MCP session indefinitely. - No persistent listener. The container is spawned per-session over stdio and torn down with
--rm— there's no exposed port or standing service to leave open by accident. - Stateless between runs. No scan history, credentials, or target lists are written to disk inside the container.
Known limitation: --network host is a native-Linux Docker feature. On Docker Desktop (Windows/macOS) it runs inside a managed VM, so host-network-dependent scans (e.g. raw ARP discovery) behave correctly on Linux hosts but may need bridge-network + port-mapping adjustments on Windows/macOS — tracked in Roadmap.
Engineering Notes — Real Problems Solved
Authentic build log, kept here deliberately instead of polished away — this is the part that's actually interesting in an interview.
| Problem | Root Cause | Fix |
|---|---|---|
apt-get install failed on gcc-16/libexpat1 with 404s |
Kali rolling repo had a transient broken dependency chain at build time (libgcc-15-dev requiring an unavailable libtsan2 version) |
Migrated base image from kalilinux/kali-rolling to ubuntu:24.04; replaced Kali-only packages (wpscan, ffuf, exploitdb) with gem install, a pinned GitHub binary release, and a direct GitLab clone respectively |
wpscan / ffuf not found via apt-get |
Not Ubuntu-packaged | gem install wpscan (it's a Ruby gem); ffuf pulled as a prebuilt release binary |
docker: command not found inside WSL2 despite Docker Desktop running |
Docker Desktop's WSL Integration toggle was off for that specific distro | Settings → Resources → WSL Integration → enable the distro → Apply & Restart |
mkdir: Permission denied writing to /mnt/c/Users/.../AppData/Roaming/Claude from WSL2 |
Cross-filesystem writes from WSL2 into Windows AppData hit Windows ACL restrictions even as root inside WSL2 |
Did the copy from native PowerShell instead, reading the WSL2 file via the \\wsl.localhost\ UNC path |
| Tool never appeared in Claude's tool list at all | Claude was running as the Microsoft Store package (...\WindowsApps\Claude_...), which is sandboxed and never reads %APPDATA%\Claude\claude_desktop_config.json |
Uninstalled the Store package, installed the direct .exe from claude.ai/download instead |
MCP server showed failed — Server disconnected |
Logs showed failed to connect to the docker API at npipe:////./pipe/dockerDesktopLinuxEngine |
Docker Desktop simply wasn't running yet when Claude Desktop tried to spawn the container — config and image were already correct |
The takeaway that mattered most: read the actual log file before changing anything. Every fix above came from %APPDATA%\Claude\logs\mcp-server-NeuralReaper.log, not guesswork.
Project Structure
NeuralReaper/
├── server.py # FastMCP server — 46 tool wrappers across 13 modules
├── Dockerfile # Ubuntu 24.04 base + full tool install
├── docker-compose.yml # Alternative to manual `docker run`
├── requirements.txt # Python deps (mcp, fastmcp)
├── claude_desktop_config.json # Drop-in Claude Desktop MCP config
├── docs/
│ ├── ARCHITECTURE.md # System design deep-dive
│ └── portfolio-kit.md # GitHub/LinkedIn/resume presentation content
├── examples/
│ └── full_recon_workflow.md # Real end-to-end usage walkthrough
├── tests/
│ └── smoke_test.sh # Verifies the server initializes over MCP
├── .gitignore
├── CHANGELOG.md
├── CONTRIBUTING.md
├── SECURITY.md
├── LICENSE
└── README.md
Roadmap
- [ ] Native bridge-network mode with explicit port mapping for Windows/macOS Docker Desktop
- [ ] Structured JSON output mode per tool (for downstream parsing instead of raw text)
- [x]
Session report generator that aggregates a full engagement into a single Markdown document— shipped asgenerate_report - [ ] PDF export option for
generate_report(currently Markdown only) - [ ] CI pipeline that builds the image and runs
tests/smoke_test.shon every push - [ ] PingCastle integration — currently skipped; it's a .NET/Windows-only tool meant to run on a domain-joined host, not from a Linux container against a remote target. Best used as a separate, complementary tool rather than forced into this container via Wine/Mono.
- [ ] Autonomous PoV generation (à la FuzzingBrain/Revelio) — a genuinely research-grade capability.
fuzz_binarygives the practical building block (crash discovery via AFL++); full automated hypothesis-generation-and-verification on arbitrary codebases is a much larger system and isn't implemented here. Listed honestly as a stretch goal, not oversold as already working.
Contributing
Adding a new tool wrapper is intentionally mechanical — see CONTRIBUTING.md for the exact constraints (Claude Desktop's MCP gateway is picky about type hints and docstrings) before opening a PR.
Disclaimer
NeuralReaper is built for authorized penetration testing and security research — systems you own, or have explicit written permission to test. Running these tools against infrastructure you don't have authorization for is illegal in most jurisdictions. The author assumes no liability for misuse.
License
MIT — see file for details.
<div align="center">
Built with Anthropic MCP · ProjectDiscovery Nuclei · XSStrike
</div>
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。