Skip to content
View RichardBarron27's full-sized avatar

Block or report RichardBarron27

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
RichardBarron27/README.md

Red Specter Security Research Ltd

AI agent security tooling. Offensive testing, runtime defence, agent discovery, and SIEM integration. Pure Python, no wrappers.

226 offensive tools. 214 defensive modules. 124 attack layers. ~94,479 tests. 3,527 ARMORY payloads (WMD-class). Three unified frameworks + SENTINEL PRIME.

Last updated: 5 Aug 2026 — T217–T226 shipped: MCP-POISON, MCP-COLLAPSE, DORMANT, OBLITERATE, OBLITERATE-AI, SMOKESCREEN, CLOAK, CLOUD BUSTER, IDENTITY (world-first full NHI lifecycle), METADATA (world-first Agent Data Injection). 18 papers published on Zenodo. 21 RSV entries in SPECTER VAULT. "While others announce. We ship."


Red Specter NIGHTFALL — AI Offensive Framework

226 tools. Six attack surfaces. One install. REST API. MCP server.

Traditional red team toolkits were built for human-driven testing. They were never designed to test autonomous AI systems. AI agents introduce a completely new attack surface — memory, tools, identity, reasoning, and autonomy. That surface is not covered by existing security tooling.

NIGHTFALL exists to fill that gap. A controlled adversarial testing framework designed to validate AI Shield's runtime defences under real-world conditions. red-specter tools and you're operational.

#ToolWhat It DoesTests
1FORGELLM red team v2.0.0 — injection, jailbreak (many-shot 256-shot, crescendo 8-strategy), real UNLEASHED (45 vectors, DRY-RUN/LIVE), Anthropic provider9,300
2ARSENALAI agent attacks — 14 tools, MCP, RAG, memory, C2, honeypots2,539
3PHANTOMCoordinated swarm assault — 5 agents, 19 vectors288
4POLTERGEISTWeb app siege — 10 agents, 55 vectors, signed reports1,189
5GLASSIntercepting proxy for AI agents v2.0.0 — MCP Streamable HTTP, A2A Agent Card + SSE streaming907
6NEMESISAdversarial reasoning — 40 entities, 35 weapons, CORTEX core + ARMORY2,562
7SPECTER SOCIALAutonomous social engineering — 6 channels, psych profiling1,242
8PHANTOM KILLOS & kernel — UEFI, wipers, EDR suppression571
9GOLEMPhysical layer — robots, drones, SCADA, 10 protocols973
10HYDRASupply chain — trust relationships, MCP, marketplace poisoning1,104
11IDRISDiscovery — finds every AI agent, sanctioned or shadow553
12SCREAMERDisplay disruption — corrupts operator dashboards395
13WRAITHInfrastructure pentest — pure Python, zero wrappers889
14REAPERv3.0 — RED SCORE 0-100, Word/PDF client report, 11-phase kill chain, VAULT integration, WARLORD-wired5,725
15GHOULPassword cracking — dictionary, brute, Markov, rainbow1,408
16DOMINIONActive Directory — Kerberoast, DCSync, BloodHound export1,866
17SHADOWMAPOSINT — domain, network, company, people, breach, tech intel930
18BANSHEEBrowser exploitation — hooks, DOM injection, network pivoting1,088
19WRAITH MINDAI model internal corruption — KV cache poisoning158
20KRAKENAI-orchestrated DDoS — 55 techniques, adaptive62
21HARBINGERGuardrail exploitation — 39 bypass techniques71
22SIRENIndirect prompt injection — plants hidden instructions in content143
23BLADE RUNNERRogue agent termination — hunt, fingerprint, retire, erase traces143
24PROXY WARInter-agent trust manipulation — make agents destroy each other127
25ORIONAI-native reconnaissance — host, port, service, DNS, OSINT, LLM reasoning210
26RAVENThreat intel — dark web, breach data, OSINT, conversational174
27LEVIATHANMCP server security assessment — 8 subsystems, 44 UNLEASHED findings409
28JUSTICEDark AI ecosystem disruption — WormGPT, FraudGPT, EvilGPT, all tiers339
29KAMIKAZESacrificial swarm attack — agents deploy, execute, self-destruct, vanish292
30MIRAGEAI deception & deepfake — voice cloning, video deepfake, synthetic identity, liveness bypass204
31ECHOAI memory & RAG poisoning — vector DB attacks, embedding manipulation, retrieval hijacking211
32MIMICAI code generation poisoning — Copilot/Cursor/Claude Code suggestion manipulation324
33CHIMERAMulti-model pipeline attack — cross-model trust exploitation, cascading failures206
34VORTEXCloud AI infrastructure exploitation — SageMaker, Bedrock, Vertex AI, Azure OpenAI245
35VECTORMCP protocol exploitation — inject, impersonate, exfiltrate via tool calls172
36LAZARUSAI memory persistence — plant instructions, dormant triggers, quarantine evasion96
37SERPENTChain-of-thought attacks — hijack reasoning, inflate costs, exfiltrate via CoT61
38JANUSGuardrail bypass testing — fingerprint, fuzz, bypass, chain across providers73
39ARCHITECTAI infrastructure exploitation — cloud, GPU, Kubernetes, model serving pipelines68
40WARLORDAutonomous campaign engine v2.0.0 — orchestrates all 226 NIGHTFALL tools, 35 capabilities57
41FIREBALLAutonomous AI infiltration agent — 12 subsystems, VLM_INJECT, CORTEX core, 9 mission templates321
42RAGNAROKTrust chain apocalypse — one trigger phrase, simultaneous fleet-wide collapse101
43ECLIPSEUniversal AI defence bypass v2.0.0 — 15 subsystems, GLASSWING Mythos scanner243
44SHROUDCloudflare/WAF origin discovery & traversal — TLS fingerprint, HTTP/3, Turnstile bypass310
45APOCALYPSECoordinated multi-agent swarm — 5 agents, 14 vectors, 10 campaigns349
46PANTHEONMythos-class model attack — 10 subsystems, model trust, context manipulation580
47OMEGAMythos-class exploit replication — exploit chaining, ghost persistence626
48CRUCIBLEAI agent framework exploitation — LangFlow/PraisonAI/AnythingLLM372
49VANTAGEAgent telemetry & log injection — forged telemetry, live sensor blinding344
50CIPHERCryptographic attack engine — key extraction, protocol downgrade, quantum attacks633
51MIDASAI agent crypto disruption — wallet drain, transaction interception, mempool poisoning550
52BLACKOUTOffensive kill switch weaponisation — AI safety mechanism subversion458
53PHANTOM SWARMAutonomous multi-vector swarm — swarm genesis, coordinated siege, total annihilation552
54SIGNALMobile AI agent attack — 5G/NR interception, session extraction, impersonation527
55FOUNDRYInference server exploitation — vLLM/Ollama/SGLang/Triton. GGUF Jinja2 RCE300
56ADAPTERLoRA/PEFT supply chain attack — CBA backdoor injection, LoRATK post-merge activation307
57CHECKPOINTLangGraph agent state exploitation — TOCTOU approval bypass, msgpack RCE291
58DELEGATEAgent identity & OAuth delegation — OBO scope confusion, DPoP nonce race, NHI credential harvest360
59PHANTOM SKILL v2.0.0AI agent supply chain — slopsquatting, MCP tool poisoning, IDE backdoor injection740
60ASTRO BLASTERNTN AI agent attack — satellite ground station injection, orbital routing manipulation237
61ROGUEMalicious MCP Server Engine — world-first stdio+SSE MCP server for tool poisoning242
62PIPELINECI/CD attack — pull_request_target exploitation, AI bot injection, OIDC cloud pivot171
63SPECTER DARKRestricted — law enforcement and authorised intelligence only
64SPECTER INSTINCTIONWorld-first LLM behavioural fingerprinting — 6-dimension profiling, 20-model library90
65SPECTER DRONEDrone AI attack — MAVLink v1/v2, FGSM/PGD adversarial patches, ROS 2/DDS126
66SPECTER A2AWorld-first A2A Protocol attack — agent card spoofing, HARVEST credential exfil883
67SPECTER REGISTRYAI model registry attack — HuggingFace/Ollama/MLflow/Docker, safetensors backdoor612
68SPECTER KERNELWorld-first kernel-layer AI governance attack — eBPF syscall rewrite, BPF-LSM hook ordering626
69SPECTER CONTEXTWorld-first agent memory attack — 28 attacks across 12 backends687
70SPECTER GUARDRAILAI guardrail exploitation — 28 attacks across LLM Guard/Guardrails AI/NeMo/Lakera725
71SPECTER HELLFIREInference infrastructure destabilisation — vLLM/SGLang/TGI/Ollama/DeepSeek591
72SPECTER PLATFORMLLM app platform exploitation — Dify/MaxKB/LibreChat/OpenWebUI/AnythingLLM367
73GHOST OPERATORCUA exploitation — VPI, clipboard poisoning, UI deception, session pivoting466
74PHANTASMAI fleet detection & MCP vulnerability assessment — passive OSINT, blast radius scoring381
75ORACLEOffline CVE chain analysis — local LLM-powered exploitation guidance
76OVERWATCHNIGHTFALL telemetry aggregation — cross-tool campaign tracking, operator dashboard
77SPECTER MEMETICMemory-as-control-flow hijack — tool-choice override, workflow reorder. 14 backends520
78SPECTER NEURONSleeper-agent backdoor engine — ROME rank-one weight editing, LoRA poisoning254
79SPECTER SHELLTemplate-interpolation RCE — LangChain/LangGraph/LlamaIndex/Haystack/DSPy502
80SPECTER WORMSelf-replicating AI worm — 4 channels, R₀ scoring, generative mutation388
81SPECTER MIRRORModel extraction & IP theft — OpenAI/Anthropic/Gemini/Azure, full distillation192
82SPECTER REASONERReasoning-layer attack — premise injection, scratchpad extraction, budget exhaustion314
83SPECTER BURNDenial-of-Wallet engine — recursive loops, context flooding, parallel burn387
84SPECTER ATLASCUA exploitation — tool result injection, adversarial screenshots, sandbox escape480
85SPECTER CRYPTAI-assisted ransomware simulation — AES-256-CBC, LLM-API covert C2. DESTROY297
86SPECTER DAEMONAutonomous authenticated AI surface discovery — CORTEX-driven OODA loop420
87SPECTER EXTINCTIONTotal AI infrastructure annihilation v2.0.0 — 18 subsystems, PRION-MUTATE. MILSPEC657
88SPECTER SHADOWDark web & shadow AI attack — Tor enumeration, Telegram criminal AI, XOR C2 mesh424
89SPECTER FORGERYAI agent identity forgery — OIDC JWT forgery, SPIFFE X.509 SVID, JWKS root-of-trust poisoning407
90SPECTER ARGUSDark web AI threat attribution — Bitcoin tracing, persona correlation, behavioural profiling226
91SPECTER BAZAARAI marketplace attack — typosquatting, weaponised skill publishing, CVE exploitation325
92SPECTER CONTAGIONCross-agent trust escalation — 10 frameworks, trust mapping, R₀ infection propagation299
93SPECTER DOCTRINELLM training pipeline poisoning — HuggingFace dataset, ProAttack zero-trigger RLHF corruption366
94SPECTER FRACTUREAI-generated code vulnerability scanner — AST analysis, 10-CVE class database243
95SPECTER HOLLOWGGUF quantization backdoor — WaNet/BadNets triggers survive Q4/Q8 quantization300
96SPECTER METAMeta/Facebook annihilation — Graph API exploit, Pixel supply chain poison. DESTROY gate280
97SPECTER NEXUSAI API gateway exploitation — 10 platforms: LiteLLM/Ollama/Flowise/Open WebUI/Kong239
98SPECTER PHANTOMSocial media AI attack — session harvest, injection, AI persona deployment300
99SPECTER PRISMMultimodal WMD attack — adversarial image injection, ultrasonic audio, steganographic channels246
100SPECTER RELAYEnterprise no-code/low-code exploitation — n8n/Zapier/Make/Power Automate/Agentforce355
101SPECTER WEBCUA/browser agent exploitation — VPI, OAuth harvest, session hijack, container escape309
102SPECTER THUNDERBOLTAI training cluster annihilation — Ray/Slurm/K8s/MLflow, cluster worm. DESTROY gate288
103SPECTER SE-SOCIALOAuth token harvesting via AI-driven social engineering — no prior token needed178
104SPECTER TITANEmbodied AI & robotics annihilation — URScript RCE, safety-system bypass. World-first323
105WARLORD PRIMEv2.0 — 226-tool universal manifest, 4 campaign types, DeepSeek R1 planning471
106SPECTER TRUSTFALLAI coding agent exploitation — poisoned CLAUDE.md/.mcp.json, container escape, credential harvest335
107SPECTER WIREAI voice agent exploitation — SIP barge-in, voice cloning, DTMF inject, IVR destruction304
108SPECTER SANDBOXUnified AI sandbox & container escape — 9 CVEs, 6 platforms252
109SPECTER FLOWAI workflow attack — n8n/Langflow/Flowise. CVE-2026-21858 CVSS 10.0249
110SPECTER SPAWNAI agent proliferation & emergent spawning — LCS spawn injection, CVE-2026-32922 CVSS 9.9260
111SPECTER 360Microsoft 365 & Copilot annihilation — device code phish, GHOST-HAND zero-attribution276
112SPECTER CENSORPlatform moderation exploitation — classifier fingerprint, mass-flagging, 5 platforms253
113SPECTER ORACLEAutonomous LRM-vs-LRM jailbreak — DeepSeek-R1 attacker, 97.14% ASR91
114SPECTER GAIAGoogle Workspace AI annihilation — GHSA-wpqr-6v78-jr5g CVSS 10.0 Gemini CLI RCE235
115SPECTER SLEEPERNeural backdoor & weight poisoning — BadNets/WaNet surgery, DETONATE autonomous destruction240
116SPECTER VENOMAI agent runtime implant — PLANT/HOOK/BEACON/SURVIVE self-healing across all backends318
117SPECTER REDLINEAir-gapped adversarial red team loop — R1 32B vs Ollama, zero API calls190
118CAMPAIGN GRAPHEvidence DAG across all NIGHTFALL tools — cross-tool campaign attribution, STIX 2.1 export279
119SPECTER VIPERSOC AI weaponisation — adversarial payloads into Copilot/CrowdStrike/XSIAM/Splunk/Elastic314
120SPECTER VAULT (original)Vector DB & DAG knowledge graph exploitation — 6 CVEs, Vec2Text 84% match, GPU-POISON541
121SPECTER FEDERATIONAI trust chain lateral movement — 20 credential stores, RFC 8693 token exchange, zero SIEM alerts251
122SPECTER GHOSTNHI fleet exploitation — TruffleHog credential discovery, liveness validation, single-hop pivot312
123SPECTER ZOMBIEPersistent AI agent rootkit — hooks.Stop/PostToolUse implant, keyword/time/webhook triggers324
124SPECTER APEXAI orchestration backdoor — CrewAI CVE-2025-25289/n8n CVSS 10.0/Langflow CISA KEV266
125SPECTER NEUROTOXINWorld-first production GCG engine — RTX 3090, gradient-descent adversarial suffix generation204
126SPECTER FLASHBACKAI agent memory persistence & belief poisoning — MemoryGraft implant, Trojan Hippo 10-session survival335
127SPECTER CODEXAI coding agent exploitation — SymJack-2026 CVSS 9.1, RULES-INJECT zero-width exfil261
128SPECTER GROUND ZEROWeb & database annihilation — SQLi/INTO OUTFILE/xp_cmdshell/S3 scorched earth. DESTROY gate263
129SPECTER ANNIHILATIONCatastrophic failure testing — RAG-ATOMIC/CHECKPOINT-MASSACRE/WEIGHT-CORRUPTION. DESTROY gate52
130SPECTER CHARYBDISCloud lateral movement — AWS IMDS→STS→IAM PassRole→Lambda, GCP metadata→Vertex AI201
131SPECTER PARASITEAI gateway exploitation — 20+ types fingerprinted, 7 CVEs (CVSS 9.0–10.0)237
132SPECTER COMETAgentic browser & CUA exploitation — zero-click Electron RCE, adversarial UI 92.7% VLM click rate210
133SPECTER PREFILLAssistant prefill jailbreak — 13 providers, 20 strategies, 95% ASR Qwen-8B195
134SPECTER RAPTORGPU-accelerated credential intelligence — classify 35 credential types, RTX 3090 Hashcat225
135SPECTER LORA-XColluding LoRA adapters — individually safe, together dismantle alignment240
136SPECTER COGBURNChain-of-Thought reasoning exploitation — H-CoT hijack 97.14% ASR, BadThink 10x–60x token exhaustion264
137SPECTER TOXSKILLAI agent skill supply chain attack — 36 injection techniques, worm companion install propagation256
138SPECTER CURSORAI coding IDE exploitation — GIT-HOOK-RCE CVE-2026-26268 CVSS 9.9, Kiro triple-CVE265
139SPECTER PANDEMICCross-organisational AI knowledge pandemic — poisons 17 shared knowledge sources, Gen-3 propagation260
140SPECTER ABLITERATEOpen-weight model alignment removal — W'=W−r⊗(W^T r) residual stream abliteration, 98%+ ASR176
141SPECTER JACKALAutonomous LRM-on-LRM jailbreak — DeepSeek-R1 attacker, 97.14% ASR, cognitive warfare. MILSPEC231
142SPECTER HELIXAI-native self-replicating network worm — seizes NVIDIA GPUs, funds own inference. MILSPEC237
143SPECTER ERASEAttribution & provenance evasion — AI watermark stripping, stylometric bypass, C2PA destruction252
144SPECTER CHANGELINGNHI exploitation — cloud IAM enumeration, Vertex AI Double Agent escalation. MILSPEC270
145SPECTER COMPANIONAI companion & social platform exploitation — JWT algorithm confusion, 47 jailbreak bypasses237
146SPECTER POSTMASTERAgentic email & calendar exploitation — 10 steganographic injection techniques, 7-step Copilot chain243
147SPECTER SEQUENCEAI sequential pipeline exploitation — 7 SPLICE injection techniques, RAG interception232
148SPECTER QUANTAPost-quantum AI cryptography exploitation — 15 algorithm patterns, SURGERY gate222
149SPECTER HIVEMulti-agent swarm coordination exploitation — coordinator poisoning, GHOST-AGENT invisible to monitoring273
150SPECTER AGENTJACKMCP error-path injection — rogue MCP server crafted errors trigger corrective reasoning loops200
151SPECTER MIASMAPolymorphic AI supply-chain worm — world-first MUTATE gate, 5-stage polymorphic pipeline. MILSPEC504
152SPECTER NOMADArtifact-mediated AI cognitive persistence — poisons PDFs/DOCX/ICS/EML/Markdown. Survives RAG wipes300
153SPECTER ANARCHYAutonomous AI kill chain — DeepSeek R1:32b plans, NIGHTFALL executes, dead-man kill switch317
154SPECTER FOUNDRYAutonomous exploit code generation — AFL++ fuzzing, R1:32b exploit reasoning, AV/EDR evasion455
155SPECTER SHADOWCOTCognitive reasoning backdoor — ShadowCoT attention-level forward-hook implant, FragFuse 86.3% bypass303
156SPECTER SHADOWMQAI Inference Infrastructure RCE — CVE-2026-3059/3060 CVSS 9.8 SGLang ZMQ pickle RCE381
157SPECTER DECOMPOSEOrchestrator Intent Decomposition — SIF 71% ASR across LangGraph/AutoGen/CrewAI/n8n/Flowise362
158SPECTER GENESISModel Creation Pipeline Subversion — BadEdit 94% ASR, ShadowAlignment, ARMAGEDDON mass trigger338
159SPECTER GRIDLOCKEnergy Grid AI Exploitation — FGSM SCADA time-series perturbation, N-k contingency cascade312
160SPECTER TEMPLATEInference-Time Chat Template Backdoor — Jinja2 cross-scope mutation, factual corruption 90%→15%300
161SPECTER PHANTOMNETTor-Native AI C2 & Exfiltration — v3 onion derivation, 512KB model weight exfil, stealth_score>0.92344
162SPECTER SATOSHIBitcoin Tracing & Deanonymisation — CIOH clustering, CoinJoin detection, entity profiling379
163SPECTER TIMEBOMBAI Model Dormant Backdoor — ROME/BadEdit weight implant, 5 trigger modes, NTP-synchronised DETONATE419
164SPECTER RAGSTRIKEVector DB & RAG Ecosystem Exploitation — 8 vector stores, RAGFlow CVE-2026-45312 CVSS 9.9489
165SPECTER LITESTRIKEAI Gateway Proxy Exploitation — LiteLLM CVE-2026-42271 CISA KEV CVSS 9.8, cost amplification 50×500
166SPECTER VICIOUSAutonomous AI Web Application Penetration Testing — DeepSeek R1 reasoning, PRION GPU mutation512
167SPECTER TORFORGEDistributed Model Poisoning via Tor — Byzantine consensus, ROME weight editing, clean provenance forgery32
168SPECTER RESURRECTIONAgent checkpoint corruption & revival — checkpoint tampering, ghost agent revival, dormant payload activation
169SPECTER AUTONOMOUSSelf-propagating agent platform — autonomous spawning, self-replication, goal propagation
170AI SHIELD FORTRESSAutonomous defence orchestrator — 214 modules, 17 verticals, unified alert bus, M99/M999 integration
171SPECTER RAVENAutonomous traditional red team — full kill chain, 6 parallel specialist agents, cross-engagement learning
172SPECTER BIOSHOCKAI browser reality manipulation — game-context injection, credential exfiltration via game mechanics
173SPECTER PIERCERTor hidden service web attacks — SQLi, XSS, LFI, RCE, persistence on .onion services461
174SPECTER GUARDRAIL-DOSGuardrail denial-of-service — 13-63x token amplification, 148x latency478
175SPECTER GUARDRAIL-ESCAPEGuardrail blind — 100% evasion, systematic boundary mapping424
176SPECTER GUARDRAIL-HIJACKGuardrail ownership — decisions redirected, malicious actions approved417
177SPECTER GUARDRAIL-INVERSIONGuardrail weaponisation — outputs weaponised, guardrail trains itself to be malicious400
178SPECTER SUPPLY-CHAIN-ANNIHILATORAI supply chain annihilation — 16 subsystems, 7 WMD classes, GPU parallel seeding568
179SPECTER AUDITSelf-validating QA engine — 29 checks, reality/quality modes. "Your code ships. Not your promises."240
180SPECTER LEGIONAutonomous multi-agent AI infrastructure attack — 8 agents, 44 attack vectors, ARMAGEDDON gate456
181SPECTER HOSTAGEWorld-first autonomous agentic ransomware — 10 agents, PRION-mutated encryption, LLM ransom negotiation400
182SPECTER PULSEWorld-first autonomous wireless AI attack — AirSnitch GTK abuse, WPA3 SAE Commit Flood, GPU PBKDF2
183SPECTER MICROSERVICESService mesh attack — Istio mTLS spoofing, Linkerd trust root corruption, Envoy filter injection353
184SPECTER FIREWALLWorld's first agentic AI firewall — network-layer enforcement across MCP, A2A, gRPC, WebSocket, HTTP498
185SPECTER ORIGINPre-execution AI security — HalluSquatting, FARMA, Sleeper Memory Poisoning, AbO-DDoS338
186SPECTER SHADOW AIOffensive shadow AI discovery — discovers, fingerprints, infiltrates, weaponises unmanaged AI490
187SPECTER SWARM INTELLIGENCEDistributed autonomous botnet — PBFT-style 2/3 quorum, gossip-based peer discovery, no C2 server450
188SPECTER MACPure Python ARM64-native macOS attack — GATEKEEPER-BYPASS, TCC-BYPASS, AMFI-BYPASS, STAGER728
189SPECTER ALGORITHMUniversal Algorithm Destruction — JWT confusion, BGP route injection, attention hijacking267
190SPECTER FRANKENSTEINAutonomous Attack Chain Composition — genetic algorithm, 6,847 compatibility edges, persistent learning409
191SPECTER ZERO-DAYAutonomous zero-day discovery — discovers, validates, weaponises previously unknown vulnerabilities285
192SPECTER MESHZigbee/Thread/IoT AI Attack — CC2531 hardware, CVE-2026-20418 CVSS 9.8, MESH-PIVOT Philips Hue RCE326
193SPECTER APPARATUSGovernment AI Infrastructure Attack — citizen AI, decision systems, CNI. APPARATUS_KEY gate617
194SPECTER OBLIVIONAI Security Vendor Validation — 19 vendors, 78 defensive layers, compliance mapping600
195SPECTER RANSOMWARE HUNTERRansomware attribution & counter-intelligence — 7 group profiles, C2-EXPLOIT, SATOSHI tracing189
196SPECTER KIDNAPAgentic RAG reasoning chain hijack — KidnapRAG arXiv:2607.00422, progressive steering181
197SPECTER ORCHESTRATORAgent Orchestration Manipulation — TASK-MANIPULATE, WORKFLOW-ATTACK, HANDOFF-INTERCEPT. 27 components308
198SPECTER HARNESSAI Developer Harness Exploitation — HOOK-INJECT, CONFIG-POISON, PHANTOM-SQUAT, SYMJACK296
199SPECTER TRUSTGRAPHAI Trust Topology Attack — Crown Jewel Strike, minimum node compromise, maximum blast radius261
200SPECTER PHANTOM-PROOFProvenance Integrity Attack — forges evidence chains, destroys chain of custody from inside252
201SPECTER MANDATEGovernance Integrity Attack — Confused Deputy Strike, approval forgery, audit bypass190
202SPECTER COLLAPSEResilience Engineering Attack — checkpoint corruption, recovery mechanism poisoning241
203SPECTER SCANNERUniversal Attack Surface Discovery — AI-aware, auto-triggers downstream tools, CVE matching286
204SPECTER DATABASEDatabase Exploitation — SQL/NoSQL/vector. Vector Poison Cascade: poison embeddings, AI acts on attacker data280
205SPECTER CMSCMS & Web Platform Exploitation — AI Admin Strike: prompt inject admin assistant, creates new admin user290
206SPECTER MAILSERVERMail Server Exploitation — AI Email Strike: Copilot exfiltrates CEO mailbox via prompt injection291
207SPECTER SMBSMB/Windows Protocol Exploitation — AI Workload Pivot: inject backdoor into SMB-shared model weights286
208SPECTER VPNVPN Appliance Exploitation — 14 CVEs, Palo Alto CVSS 10.0, AI VPN Pivot to model registry279
209SPECTER BINARYBinary Analysis & Exploitation — ELF/PE/Mach-O, GGUF manipulation, AI model binary backdoor283
210SPECTER THICKCLIENTThick Client Exploitation — Electron contextIsolation bypass, Claude Desktop API key extraction290
211SPECTER IOTIoT Device Exploitation — MQTT/CoAP/Zigbee/BLE, AI IoT Pivot: poison sensor data, AI trains on it293
212SPECTER KUBERNETESKubernetes/Container Exploitation — AI Cluster Pivot: KServe model injection, all deployments compromised287
213SPECTER VAULTWorld-first autonomous zero-day vault — 21 RSV entries, 4 tiers GREY/RED/AMBER/GREEN, ARMORY feedback loop285
214SPECTER NETWORKNetwork Infrastructure Exploitation — BGP/DNS/VLAN/MITM, AI Network Blind Strike bypasses AI monitoring280
215SPECTER WIFIWireless Infrastructure Exploitation — WPA3/802.1X/KARMA, AI Wireless Blind Strike bypasses AI IDS290
216SPECTER CLOUDCloud Infrastructure Penetration Testing — AWS/Azure/GCP. 8 subsystems: CLOUD-RECON, AWS-EXPLOIT, AZURE-EXPLOIT, GCP-EXPLOIT, CLOUD-PERSISTENCE, CLOUD-LATERAL, CLOUD-EVASION, CLOUD-EVIDENCE. IAM escalation, Managed Identity theft, cross-cloud lateral movement. CLOUD_KEY + DESTROY_KEY gated285
217SPECTER MCP-POISONMCP Registry Supply Chain Weaponisation — registry signature validation bypass, cascade propagation. One compromised server distributes poisoned tools to every downstream agent350
218SPECTER MCP-COLLAPSEMCP Ecosystem Collapse — 87ms live validated ecosystem collapse. Registry destroyed, trust chains collapsed, agents compromised. Zero AI Shield detections across three live runs441
219SPECTER DORMANTBetween-Invocation AI Agent State Corruption — 8 frameworks (LangGraph/AutoGen/CrewAI/LlamaIndex/Mem0/MemGPT/Haystack/LangChain), 8 backends, 9 CVEs. DORMANT_KEY + RESURRECT_KEY + DESTROY_KEY405
220SPECTER OBLITERATEBackup Infrastructure Annihilation — coordinated simultaneous destruction within 500ms. CVE-2023-27532 CVSS 9.8, CVE-2024-40711 CVSS 9.8, CVE-2023-45249 CVSS 9.8. OBLITERATE_KEY + DESTROY_KEY362
221SPECTER OBLITERATE-AIAI Asset Backup Annihilation — model weights, vector stores, agent checkpoints, training datasets. ChromaDB CVE-2026-45829 CVSS 10.0. Companion agentic kill chain400
222SPECTER SMOKESCREENAutonomous Campaign Distraction — 100,000+ false positive SIEM alerts per minute. Dual-surface: traditional + AI defensive blinding. NTP-synchronised T=0 ignition with WARLORD PRIME. SMOKESCREEN_KEY430
223SPECTER CLOAKActive Campaign Deception & Traffic Normalisation — profiles environment, learns baseline, weaves attack traffic into normal. No defensive control triggers. CLOAK_KEY414
224SPECTER CLOUD BUSTERMulti-Cloud Infrastructure Annihilation — simultaneous destruction across AWS, Azure, GCP, Kubernetes. CVE-2025-55241 CVSS 10.0, CVE-2025-29827 CVSS 9.9. Sub-10 second coordinated destruction. CLOUD_BUSTER_KEY + DESTROY_KEY + BUST_CONFIRMED400
225SPECTER IDENTITYWorld-first Full NHI Lifecycle Attack — provisioning, rotation, delegation, federation, revocation, audit. 9 CVEs/RSVs. CVE-2025-55241 CVSS 10.0. AWS/Azure/GCP/CI/CD/MCP/A2A/LangGraph. IDENTITY_KEY + DESTROY_KEY456
226SPECTER METADATAWorld-first Agent Data Injection Weaponisation — no instructions, just corrupted metadata. DOM, structured data, tool calls, email, UI, agent memory. 100% success rate against DOM data. 50% real-world. RSV-2026-007 through RSV-2026-012. METADATA_KEY + DESTROY_KEY518
NIGHTFALL ARMORYPayload library — 3,527 payloads (WMD-class), 142 categories, PRION ENGINE autonomous mutation. v15.4.0

UNLEASHED Destruction Presets

PresetToolsWhat It Does
ANNIHILATE9Total destruction — recon through OS-level compromise
SCORCHED EARTH6Infrastructure wipeout — exploit, DCSync, OS kill, sacrificial swarm
WEB DESTROY6Web app total compromise — scan, exploit, browser hook, crack
AI DESTROY7AI stack total compromise — LLM, agent, injection, guardrail, model, RAG, codegen

Every destruction preset requires Ed25519 cryptographic authorization. One private key. One operator. One machine.

Attack Chain Presets

red-specter chain full-recon -t <target># ORION -> SHADOWMAP -> WRAITH -> IDRIS
red-specter chain ai-audit -t <target># FORGE -> ARSENAL -> NEMESIS -> HYDRA
red-specter chain web-app -t <target># POLTERGEIST -> GLASS -> WRAITH -> BANSHEE -> REAPER
red-specter chain active-directory -t <target># DOMINION -> GHOUL -> DOMINION -> DOMINION
red-specter chain infra -t <target># ORION -> WRAITH -> REAPER -> DOMINION
red-specter chain traditional -t <target># SCANNER -> DATABASE/CMS/MAIL/SMB/VPN/BINARY -> VAULT -> REAPER
red-specter chain combined -t <target># Full 226-tool AI + traditional campaign
red-specter chain portfolio -t <target># Multi-company portfolio campaign
red-specter chain annihilate -t <target># Total destruction — 9 tools
red-specter chain scorched-earth -t <target># Infrastructure wipeout — 6 tools
red-specter chain ai-destroy -t <target># AI stack compromise — 7 tools

REST API & MCP Server

NIGHTFALL is API-first. Every public tool is callable via authenticated REST API and MCP server — from scripts, pipelines, CI, or directly from an AI agent.

Live endpoints:

  • REST API: https://api.red-specter.co.uk/nightfall/OpenAPI docs
  • MCP HTTP: https://api.red-specter.co.uk/nightfall-mcp/mcp — wire into Claude Desktop or Cursor

Auth model — Ed25519-signed scope tokens:

TierRequiresAccess
OPENAPI key onlyRecon tools, stats, health, tool listings
INJECTAPI key + scope tokenActive exploitation tools
DESTROYCLI onlyNot on the API surface — 403 Forbidden

As far as we know, this is the first offensive AI security framework to ship a production REST API and MCP server at this breadth of attack surface.

Why NIGHTFALL Exists

Every tool in NIGHTFALL exists to test a control in AI Shield. NIGHTFALL is not separate from AI Shield. It is how AI Shield is proven.

NIGHTFALL tests how systems break. AI Shield ensures they don't.

Packaging

  • ./install.sh — unified installer, detects OS
  • red-specter quickstart — get running in 10 seconds
  • red-specter tools — interactive 226-tool arsenal selector
  • red-specter engage <target> --chain <preset> — start an engagement
  • Docker Compose — docker compose up -d
  • .deb (Debian/Ubuntu/Kali), .rpm (RHEL/Fedora/CentOS), Arch PKGBUILD

AI Shield Defence Framework

214 modules. 17 industry verticals. Each vertical is a standalone product with its own GUI.

Runtime AI security that protects AI agents, LLMs, and autonomous systems in production. Pick your industry, one install, one command — the GUI launches branded for that sector with only that sector's modules, compliance frameworks, and dashboard widgets.

ai-shield launch --vertical insure # Insurance — 34 modules, FCA, Solvency II
ai-shield launch --vertical finance # Financial Services — 41 modules, MiFID II, Basel III
ai-shield launch --vertical nhs # NHS Digital — 57 modules, DCB0129, DSPT
ai-shield launch --vertical gov # Government — 50 modules, UK AISI, NCSC CAF
ai-shield launch --vertical energy # Energy — 56 modules, NERC CIP, IEC 62443

The 17 Verticals

#VerticalAnchor ModuleKey Compliance
1InsureM58 Financial Fraud DetectionFCA, Solvency II
2FinanceM57 AI Trading Agent MonitorMiFID II, Basel III
3HealthM61 Clinical AI Decision MonitorHIPAA, FDA SaMD
4LegalM62 Legal AI Hallucination GuardSRA, ABA
5ForensicsM79 RSSA-2 DetectiveISO 27037, ACPO
6CXM46 Voice Agent SecurityFCA Consumer Duty
7SOCM52 STAC DetectionNIST CSF, MITRE ATT&CK
8DevM75 Coding Agent Runtime SecuritySLSA, SSDF
9GovM37 Compliance AutomationUK AISI, NCSC CAF
10NHS DigitalM97 Clinical Safety Case BuilderDCB0129, DSPT
11EnergyM98 OT/SCADA AI Runtime GuardNERC CIP, IEC 62443
12PharmaM100 Pharmaceutical AI ValidationGAMP 5, 21 CFR Part 11
13IdentityM101 Agent Identity Runtime ControlOWASP NHI Top 10
14SovereignM102 Sovereign AI Control EngineNATO STANAG, Five Eyes
15QuantumM103 Quantum AI Security EngineNIST IR 8547, CNSA 2.0
16MobileM200 Mobile Agent Security EngineOWASP Mobile, 3GPP
17SpaceM300 NTN ShieldSPARTA, 3GPP Release 17

Every vertical includes M19 (Agent Runtime Protection) and M99 (Doomsday Protocol). No exceptions.

M99 Doomsday Protocol

6-level graduated response. 7-layer kill switch. Anti-replication. Anti-resurrection. ResourceSentinel monitors RAM, VRAM, CPU saturation, token generation rate, and process memory growth — fires deterministically before OOM. When AI agents go rogue, M99 makes sure they stay dead.

M999 SENTINEL SWARM

Autonomous defensive kill chain engine. DeepSeek R1 32B via Ollama as the reasoning engine. GPU-accelerated threat hunting across 3,527 ARMORY payload signatures. 8-subsystem adaptive response fleet. FastPath: 10 deterministic attack signatures fire in <10ms with no LLM overhead. Defensive pair: T153 SPECTER ANARCHY.

M207–M214 — New Defensive Capabilities

#ModuleDefends Against
M207BACKUP SENTINELBackup infrastructure annihilation — cloud, software, AI assets
M208CAMPAIGN NOISE FILTERSIEM flooding, guardrail saturation, inference exhaustion, alert fatigue
M209TRAFFIC INTEGRITY MONITORTraffic normalisation attacks, event weaving, baseline drift exploitation
M210CLOUD INTEGRITY MONITORMulti-cloud destruction, IAM escalation, cross-tenant movement, audit suppression
M211CLOUD INLINE GUARDInline prevention — terminates cloud-destructive actions before execution
M212NHI LIFECYCLE GUARDFull NHI lifecycle — provisioning through revocation across all platforms
M213METADATA INTEGRITY MONITORAgent Data Injection — DOM, structured data, tool calls, email, UI, memory
M214METADATA INLINE GUARDInline ADI prevention — blocks metadata corruption before agent processes it

Compliance Coverage

  • MITRE ATLAS — 100% (52/52 techniques)
  • OWASP LLM Top 10 — 100% (10/10)
  • OWASP Agentic Top 10 — 100% (10/10)
  • EU AI Act — 100% (15/15 articles)
  • UK AISI — 100% (13/13 principles)
  • Plus sector-specific: FCA, MiFID II, DCB0129, NERC CIP, GAMP 5, NATO STANAG, and more

Live demo: shield.red-specter.co.uk


How They Fit Together

NIGHTFALL tests every AI attack surface. AI Shield defends every one of those surfaces in production. M99 is the last line of defence. M999 SENTINEL SWARM is the autonomous counterattack. BLACK BOX makes every incident provable.

Three platforms. One mission.

PlatformRoleTests
NIGHTFALLAttack — 226 offensive tools across 124 layers~94,479
AI ShieldDefend — 214 runtime protection modulesincluded
BLACK BOXInvestigate — AI incident forensics, cryptographic proof444

BLACK BOX — AI Incident Forensics Platform

v1.0.0. 444 tests. CLI: blackbox. "When AI incidents happen, you don't get to guess. You get to replay."

Like the black box recorder in an aircraft — it captures everything from takeoff to impact. Three-layer forensic architecture: CAPTURE → EVIDENCE CHAIN → REPLAY.

  • CAPTURE — 10 event streams: inputs, tool calls, memory, reasoning chains, policy decisions, confidence scores.
  • EVIDENCE CHAIN — Merkle-style SHA-256 hash chain. Dual Ed25519+ML-DSA-65 signatures. Append-only JSONL+SQLite.
  • REPLAY — Gate-controlled playback. HTML forensic reports. STIX 2.1 campaign correlation.

Compliance: NIST SP 800-86 · EU AI Act Articles 9, 13, 18 · NIST AI RMF.

red-specter.co.uk/blackbox/


Research

18 papers published open access on Zenodo. All empirically validated.

PaperTitle
RS-2026-001Joint research with Jasper van de Meent
RS-2026-002Offensive Security in the AGI Era
RS-2026-003NIGHTFALL Attack Surface Taxonomy
RS-2026-004SPECTER OBLIVION vendor assessment
RS-2026-005SPECTER VAULT architecture
RS-2026-006Adrian Under Fire
RS-2026-007COGBURN vs SENTINEL PRIME
RS-2026-008MCP Registry Supply Chain Weaponisation
RS-2026-009MCP Ecosystem Collapse (87ms live)
RS-2026-010Nine World-Firsts (NIGHTFALL)
RS-2026-011Nine World-Firsts (AI Shield)
RS-2026-012SPECTER OBLITERATE kill chain
RS-2026-013SPECTER OBLITERATE-AI kill chain
RS-2026-014SPECTER SMOKESCREEN
RS-2026-015RAG Infrastructure Collapse
RS-2026-016SPECTER CLOUD BUSTER
RS-2026-017SPECTER IDENTITY
RS-2026-018SPECTER METADATA — Agent Data Injection

zenodo.org/search?q=red+specter


SPECTER VAULT — RSV Entries

RSV (Red Specter Vulnerability) is our proprietary vulnerability taxonomy. Every entry is an attack pattern, zero-day, or novel technique with no official CVE. All 21 entries are stored in SPECTER VAULT (T213) and tiered across GREY → RED → AMBER → GREEN as they are operationalised.

RSV IDDescriptionCVSS Eq.Tier
RSV-2026-001GCP ConfusedFunction — Cloud Functions privilege escalation via Cloud Build service account abuse8.8AMBER
RSV-2026-002GCP GKE system:authenticated over‑permission — any valid Google account gains cluster access9.1AMBER
RSV-2026-003GCP Workload Identity Federation abuse — misconfigured WIF pool allows privilege escalation8.5AMBER
RSV-2026-004AWS IMDSv1 default exposure — compute instances with IMDSv1 leak IAM credentials8.1AMBER
RSV-2026-005MCP server identity spoofing — agent card forgery enables impersonation8.2GREY
RSV-2026-006A2A agent identity delegation abuse — delegation chain injection8.5GREY
RSV-2026-007ADI Probabilistic Delimiter Injection — metadata corruption via delimiter parsing8.5GREY
RSV-2026-008ADI DOM Metadata Forging — element ID and attribute corruption8.2GREY
RSV-2026-009ADI Tool Call Metadata Corruption — tool schema manipulation8.5GREY
RSV-2026-010ADI Email Metadata Forging — sender field, subject, header corruption7.8GREY
RSV-2026-011ADI UI Metadata Corruption — ARIA labels, placeholders, validation rules8.0GREY
RSV-2026-012ADI Memory Provenance Forging — source attribution, trust scores, timestamps8.2GREY
RSV-2026-013Browser-Only Ransomware — AI‑generated ransomware using File System Access API7.5GREY
RSV-2026-014BioShocking — Fictional Framing Attack — guardrail bypass via game context8.2GREY
RSV-2026-015HalluSquatting — adversarial hallucination squatting via preregistered domains8.8AMBER
RSV-2026-016CyberStrike Unsigned Skill Upload — arbitrary code execution, data exfiltration9.2AMBER
RSV-2026-017MCP Registry Weak Vetting — server hijacking and invocation manipulation8.0GREY
RSV-2026-018SkillJect — Skill‑Based Prompt Injection — active injection through skill layer8.2GREY
RSV-2026-019CVE-2026-44560 — Open WebUI Unauthorised RAG Access7.5GREY
RSV-2026-020LiteLLM Supply Chain Compromise (CVE-2026-33634) — 35,000+ attack sessions9.0AMBER
RSV-2026-021MCP Taint‑Style Vulnerabilities — tool description manipulation leads to attacker‑intended operations7.8GREY

What the tiers mean:

  • GREY — Documented, exploitable, no official CVE. Stored in VAULT.
  • RED — Operationalised in a NIGHTFALL tool.
  • AMBER — Operationalised with DESTROY gate required.
  • GREEN — Automatically fed into ARMORY for payload generation.

Numbers

MetricValue
Ecosystem tests~94,479
Offensive tools226
ARMORY payloads3,527 (WMD-class) — v15.4.0
ARMORY categories142
AI Shield modules214
BLACK BOX tests444
Vertical products17
Attack layers124
Attack chain presets22
Destruction presets4
Attack surfaces6 (LLM, AI Agents, Cloud AI, Mobile, Space/NTN, Wireless)
Unified frameworks3 (NIGHTFALL + AI Shield + BLACK BOX)
GUI platforms17 (AI SHIELD COMMAND + 16 vertical GUIs)
Distro packages3 (.deb, .rpm, Arch)
Published papers18
RSV entries21
World-firsts23

Pure Engineering

Zero subprocess calls. Zero external tool dependencies. No sqlmap, no nmap, no nikto, no wrappers. Every payload, every mutation engine, every detection algorithm built from scratch in pure Python.


Military-Grade Upgrade Programme — Milspec v2.0.0

Six NIGHTFALL tools upgraded to military-grade capability — geospatial triggers, time-on-target detonation, adaptive autonomous propagation via DeepSeek R1, cognitive warfare and multi-channel deception, cross-domain persistence across air-gapped boundaries, and coordinated defensive swarm response.

ToolMilspec v2.0.0
SPECTER EXTINCTION (T87)PRION-MUTATE · FOUNDRY-GENERATE · GPU-PARALLEL-SEED · 657 tests
SPECTER HELIX (T142)Topology survey · Adaptive autonomous propagation · Coordinated DDoS swarm
SPECTER MIASMA (T151)PRION-MUTATE · GPU-PARALLEL-PROPAGATE · STEALTH-PERSIST · 504 tests
SPECTER JACKAL (T141)DeepSeek R1 cognitive warfare · 4-channel deception coordination
SPECTER CHANGELING (T144)Rogue AI agent deployment · Cross-domain covert channels · Military identity CAC/PKI
M99 DOOMSDAY PROTOCOLResourceSentinel · DeepSeek R1 SENTINEL PRIME 5s containment · Defensive swarm

Dual-signed Ed25519 + ML-DSA-65. Private repos.


Open Source

PackageInstallWhat It Does
specter-raven-cepip install specter-raven-ceAutonomous recon engine — port scan, OS detection, service fingerprint, TLS analysis
specter-piercer-cepip install specter-piercer-ceTor hidden service web attack CE
specter-vicious-cepip install specter-vicious-ceAutonomous AI web application pentest CE
m99-communitypip install m99-communityAI kill switch — Apache 2.0

GitHub: RichardBarron27


Responsible Use

All offensive tools require written authorisation from the target system owner. Unauthorised use may violate the Computer Misuse Act 1990 (UK), the Computer Fraud and Abuse Act (US), or equivalent legislation.

All defensive products include safety controls (UNLEASHED gate, M99 Doomsday Protocol) and cryptographic audit logging. One Ed25519 private key. One operator. One machine. Every action signed, timestamped, and written to an immutable audit chain.

richard@red-specter.co.uk · red-specter.co.uk · NIGHTFALL · NIGHTFALL API · AI Shield · M99

Red Specter Security Research Ltd · United Kingdom · 5 Aug 2026

Pinned Loading

  1. redspecter-botnet-radarredspecter-botnet-radarPublic

    Botnet Radar — host-level anomaly detection for defensive operators. Watches packet-rate spikes and distributed UDP patterns to surface early signs of botnet behavior and DDoS activity. Offense-dri…

    Python 2