zeroforge
Enables adaptive binary 0day research with persistent knowledge graph and adaptive planning, automating vulnerability analysis and exploit development through HexStrike and local tools via MCP.
README
ZeroForge
An adaptive binary-0day research brain that sits on top of HexStrike AI.
HexStrike is an excellent executor: 150+ security tools wrapped behind an HTTP API and MCP. But it is stateless — every tool returns raw text to the LLM and the target model is forgotten the moment the call returns, and its "decision engine" is a hard-coded effectiveness table that never adapts.
ZeroForge adds the part that was missing: memory and reasoning.
┌── LLM (Claude via MCP) ──┐
│ reasons & decides │
└────────────┬──────────────┘
│ small stateful verbs (zf_ingest / zf_plan / zf_assess …)
┌───────▼─────────┐
│ ZeroForge │ persistent knowledge graph (SQLite)
│ • model │ adaptive planner (state → ranked actions)
│ • planner │ action log (never repeat work)
└───────┬─────────┘
│ executes via …
┌──────────▼───────────┐ ┌───────────────┐
│ HexStrike /api/tools │ or → │ local tools │ (fallback if HS down)
└──────────────────────┘ └───────────────┘
Why it's more powerful than raw HexStrike
| HexStrike | ZeroForge | |
|---|---|---|
| Target model | none — raw tool text per call | persistent knowledge graph that accumulates across runs |
| Tool selection | static effectiveness table | adaptive planner reacting to discovered facts |
| Repeated work | re-runs freely | action log dedup — never repeats a completed step |
| Reasoning | in the LLM only, each turn cold | LLM + a growing state it can query |
| Backend | its own wrappers | reuses HexStrike, with local fallback |
Install
python3 -m pip install requests # only hard dep for the core
# MCP mode additionally needs fastmcp (already in the HexStrike venv)
Use — CLI
python3 -m zeroforge.cli ingest ./target # characterize + enumerate + gadgets
python3 -m zeroforge.cli assess # narrative state
python3 -m zeroforge.cli plan # ranked next actions + rationale
python3 -m zeroforge.cli exploit ./target # autonomous ret2win -> real shell
python3 -m zeroforge.cli show sink # dump graph nodes
python3 -m zeroforge.cli log # what has already run
Autonomous exploitation (proven end-to-end)
Against a no-canary stack overflow with a win()/system("/bin/sh") function,
zeroforge exploit runs the whole chain by itself — no offsets hard-coded:
[*] Attempting autonomous ret2win on ./vuln_test
detail: ret2win -> win@0x401166 offset=72 align_ret=0x401016
[+] EXPLOIT SUCCESSFUL — code execution proven:
| ZEROFORGE_PWNED_1000
| uid=1000(benny) gid=1000(benny) groups=1000(benny),...
[+] Reproducible exploit written to: ./vuln_test.zeroforge_exploit.py
It (1) detects the input vector from the discovered sinks, (2) computes the
saved-RIP offset by crashing the target under GDB with a cyclic pattern,
(3) locates a win/system function, (4) builds a stack-aligned payload and
(5) runs the binary to obtain a shell — then records GOAL ACHIEVED: shell
into the knowledge graph and emits a standalone pwntools script.
tests/test_exploit.py compiles a fresh target and asserts the shell.
Example against a scanf/strcpy/system("/bin/sh") binary with no canary:
[ 98] Trace reachability to system()/popen() (exploit)
↳ system()/popen() present and a /bin/sh string exists — likely a one-shot command-injection path.
[ 93] Dynamically confirm stack overflow (offset) (exploit)
↳ Unbounded copy sink present. No stack canary → saved-return overwrite is viable.
[ 82] Probe format-string primitive (exploit)
↳ Non-constant format sink present → test for arbitrary read/write & leaks.
Use — MCP (drive it from Claude)
Point your MCP client at zeroforge.mcp_server. Verbs: zf_ingest,
zf_plan, zf_assess, zf_show, zf_note, zf_run_hexstrike.
{
"mcpServers": {
"zeroforge": {
"command": "/home/you/hexstrike-ai/hexstrike-env/bin/python",
"args": ["-m", "zeroforge.mcp_server"],
"env": { "ZEROFORGE_DB": "engagement.db", "HEXSTRIKE_URL": "http://localhost:8888" }
}
}
}
Status
v0.2 — working core: knowledge graph, triage capabilities (file/checksec/sinks/
strings/ROP gadgets), adaptive planner, CLI, MCP server (7 verbs incl.
zf_exploit), and autonomous ret2win exploitation proven end-to-end.
Roadmap: ret2libc / full ROP chaining, format-string primitive, taint-based
reachability (angr), fuzzing orchestration + crash triage, agentic run-loop.
Legal
For authorized security research, CTFs and pentesting engagements only. You are responsible for having permission to test any target.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。