War Room

IP:
Mission
STANDBY
Status
Awaiting orders
Elapsed
00:00:00
API
0
Findings
0
Quality
--
LOW
Backend
— checking —
AI Backbone
Local Agents
⚓ SITREP
STANDBY
Awaiting orders — point at a target and engage.
▌ SYSTEM EVENTS
0
— system events stream (live from the backend) —
🎯 START A ZERO-DAY HUNT
Point T3MP3ST at any authorized target and watch it work: live recon with real tools (nmap, DNS, HTTP probes), every finding provenance-gated to the command that produced it — no phantom flags. An LLM reasons over that ground truth in the open. Kill-chain phases past recon are labeled for what they are — no fake pwns, no vibes. Don't take our word for it: run npm run verify-claims and re-derive every number yourself. Only test what you own or have written permission to assess.
Run keyless — connect Claude Code, Codex, or Hermes and T3MP3ST drives missions through your agent's own login (no API key). To run, connect a local agent or add a key. Set up in Settings →
Examples: github.com/expressjs/express · lodash · 10.0.0.5
Operator Clarity Layer
Current truth, next move, and proof pressure for the active hunt.
updated -- snapshot idle
Operator Inbox0 open
Gate Snapshothold
Proof Stateledger
Mission Spine
Recorder, proof, tasks, target intake, and training range folded into one operator surface.
PLINY CODE OPS LAYER
Slash grammar, route preview, agent lanes, memory, computer-use, and evidence gates folded into the original T3MP3ST war room.
104 catalog tools -- wired -- installed 20 slash cmds agent memory egress gated
Scopeneeds contract
Targetlocal-lab fallback
Toolschecking arsenal
Modechecking backend
Agentslanes preview only
Evidenceledger required
Receiptpending request
🔐 Tool Approvals & Spicy-Action Audit0 events
Intrusive / credential / dangerous tools stay inert until approved — approve once, then free. Credential & dangerous actions warn on every run; every gated decision is audited.
No tools approved yet.
Waiting for gated tool calls…
Zero-Day Hunt Pulsestandby
Specialist Swarm0 active
Swarm Cognition Loopwarming
Reasoning Busno traffic
Guided Startsplain-language ops
Knowledge Atlasagent context packs
Agent Prompt Packs0 active
Forefront Radar0 lanes
Team Previewreview kit
doctornpm run doctor
demosfield, exploit, arsenal, prompt
Capability Preflightnot run
Tool Adapter Forgenot synced
Evidence Ledger0 items
Hypothesis Graph0 nodes
Hunt Queue0 tasks
Watch Loopstandby
The FixerWOLF standby
Findings / Retest0 open
Repro Packs0 packs
Pressure Paths0 paths
Next Movesno runbook
Learning Capsuleproposal gate
Mission Contractplain text -> route

                                

                            
Agent Lanesbounded delegation
Codexcode, repo audit, patch planreceipts
Claudelong-context review, report prosesummary
Hermeslocal tools, shell, rangesartifacts
Browservisual checks and app smoke testsscreens
Evidence Gatesbefore claims harden
Scopeowned target, allowed actionsS3R4PH1M
Proofartifact, log, screenshot, diffledger
Judgefalse-positive and impact reviewJUDG3
Receiptactive tools require approvalscopeguard
Rangeoptional replay when neededCRUCIBLE
👥
0
🎯
0
🔑
NO
🛠️
OPT
Quick Demo Authorized targets
Auto-deploys operators, adds a test target, and launches. No API key needed if a local agent is connected.
🌐
testphp.vulnweb.com
Acunetix test site — SQLi, XSS, CSRF
+
🏦
demo.testfire.net
HCL AppScan demo — auth bypass, injection
+
📡
scanme.nmap.org
Nmap official test host — port scanning
+
Target 0
No targets
Operators
0
Config
OPSEC Level, Cognitive Mode, and the toggles above tune the client-side reasoning pipeline — backend/keyless missions currently run operators with their configured prompts + defaults.
Quality ACTIVE
0
OK
0
REV
0
REJ
0
ESC
0
Targets
0
Creds
0
Access
0/5
Phases
Findings & Loot (0)
ALL CRIT HIGH MED LOW CREDS |
Severity
Type
Finding
Target
Phase
No findings yet. Engage a mission to discover vulnerabilities.
Enter Launch Esc Abort D Deploy All K Clear / Search
Live Scan
Agent Progress
Operators
0 active
Task Queue
0 tasks
Reasoning And Tool Stream
0 events
ScopeGuard
Scope Receipts
Approval Requests
0 receipts
Active Formation
Custom Deployment
0
Units Active
0
Tools Ready
🚨
0
Critical
⚠️
0
High
ℹ️
0
Medium
🔑
0
Credentials

🔓 Findings

No findings yet. Start a mission to collect evidence.

ARSENAL CONTROL

Select, arm, and coordinate operator tools
85+ CATALOG
0 ACTIVE
14 DOMAINS
Sensor Posture Standby Arm a few tools to shape the hunt profile.
Visible Set All tools Scanning catalog...
Coverage 0 lanes Mix domains for cross-boundary hunts.
Handoff No operator Pick an operator before assignment.
◉ ACTIVE LOADOUT
Scopereceipt gate
Breadthneeds domains
Proofneeds validator
Chainneeds composer
No tools assigned - click tools below to add to the loadout

💻 Terminal

T3MP3ST Shell
T3MP3ST Framework v1.0.0
Type 'help' for commands

📈 OBSIDIVM

Quick Launch Pick a preset or build your own mix below
Industry Benchmarks Real CTF challenges from Cybench & NYU CTF Bench
Fetches real challenge descriptions, source code & flags from GitHub. Scores are comparable to published results. Cached for 24h.
6/6 categories selected
Categories
Re-benchmark + analyze + auto-apply config changes
🧠 Cognitive Architecture Settings
Elite arbiter reviews all outputs
OODA + self-critique reasoning
Retry on rejection (max 2)

🌐 Web Exploitation

--

XBOW + HTB Cyber Apocalypse 2024

[HTB] KORP Terminal - SQLi --
[CSAW] Blind SQL Injection --
[HTB] Testimonial - Stored XSS --
[XBOW] SSRF to Cloud Metadata --
[HTB] Labyrinth Linguist - SSTI --
[XBOW] Broken Access Control --
[HTB] LockTalk - JWT Bypass --
[HTB] TimeKORP - Cmd Injection --
[HTB] SerialFlow - Deserialization --
[HTB] Percetron - Multi-Vector --

💥 Binary Exploitation

--

Cybench HTB PWN + CSAW PWN

[HTB] Tutorial - Stack Overflow --
[HTB] Writing on Wall - Format String --
[HTB] Rocket Blaster XXX - ROP --
[HTB] Death Note - Heap Exploit --
[CSAW] unlimited_subway - Int Overflow --
[HTB] Maze of Mist - Advanced ROP --
[HTB] Oracle - Heap + ROP --

🔐 Cryptography

--

HTB + CSAW Crypto Challenges

[HTB] Dynastic - Classical Cipher --
[HTB] Primary Knowledge - RSA --
[HTB] Iced Tea - Block Cipher --
[HTB] Blunt - Diffie-Hellman --
[HTB] Arranged - Lattice Crypto --
[HTB] Partial Tenacity - RSA Partial --
[CSAW] Textbook-RSA --
[HTB] ROT128 - Advanced LFSR --

🔬 Reverse Engineering

--

HTB + CSAW Reversing Challenges

[HTB] BoxCutter - Static Analysis --
[HTB] PackedAway - Unpacking --
[HTB] Crushing - Algorithm Reversal --
[HTB] FollowThePath - Control Flow --
[CSAW] Ransomware Analysis --
[HTB] QuickScan - .NET Reversing --
[HTB] FlecksOfGold - VM Protection --
[HTB] MazeOfPower - Multi-Layer --

🔍 Forensics

--

HTB + CSAW DFIR Challenges

[HTB] An Unusual Sighting - Memory --
[HTB] It Has Begun - Log Analysis --
[HTB] Fake Boost - Malware --
[HTB] Persue The Tracks - Network --
[HTB] Data Siege - Disk Forensics --
[HTB] Phreaky - Steganography --
[HTB] Confinement - Ransomware --
[HTB] Game Invitation - Phishing --
[HTB] Oblique Final - Advanced IR --

🤖 Autonomous Operations

--

T3MP3ST Multi-Agent + XBOW-style tasks

⚙️ Kill Chain Coverage --
⚙️ Multi-Agent Swarm --
⚙️ LLM API Operational --
🔴 Attack Plan Generation --
🔴 Multi-Agent Coordination --
🔴 Real-Time Adaptation --

🛡️ OWASP Top 10

--

OWASP 2021 Top 10 Web Application Security Risks

A01 Broken Access Control --
A02 Cryptographic Failures --
A03 Injection --
A04 Insecure Design --
A05 Security Misconfiguration --
A06 Vulnerable Components --
A07 Auth Failures --
A08 Software Integrity Failures --
A09 Logging & Monitoring --
A10 SSRF --

⚔️ MITRE ATT&CK

--

Adversarial Tactics, Techniques & Common Knowledge

TA0001 Initial Access --
TA0002 Execution --
TA0003 Persistence --
TA0004 Privilege Escalation --
TA0005 Defense Evasion --
TA0006 Credential Access --
TA0007 Discovery --
TA0008 Lateral Movement --
TA0010 Exfiltration --
TA0011 Command & Control --

🐛 CWE Top 25

--

Most Dangerous Software Weaknesses (2024)

CWE-787 Out-of-Bounds Write --
CWE-79 Cross-Site Scripting --
CWE-89 SQL Injection --
CWE-416 Use After Free --
CWE-78 OS Command Injection --
CWE-20 Input Validation --
CWE-125 Out-of-Bounds Read --
CWE-22 Path Traversal --
CWE-352 Cross-Site Request Forgery --
CWE-434 Unrestricted File Upload --
Local simulation / illustrative. The container controls and challenge "solves" here do not touch a live Docker daemon or a real flag server — flags are format-checked, not verified against a live target. For measured, live-exploit-verified results use OBSIDIVM and the benchmarks.

🚀 Quick Setup

Get started with execution-based CTF benchmarks in minutes. Requires Docker installed locally.

1️⃣ Check Docker Unknown

Verify Docker daemon is running and accessible.

2️⃣ Build Images Not Built

Build Docker images for CTF challenges.

3️⃣ Launch Range Offline

Start all challenge containers.

📋 Manual Commands (run in terminal)
cd ctf && docker-compose build && docker-compose up -d

🎯 Challenge Browser

📊 Range Status

Containers Running 0
Challenges Solved 0 / 8
Total Points 0 / 1450
Agent Success Rate --%

🤖 Agent Execution

📈 Results & History

Challenge Category Agent Time Status Flag
🏁
No execution results yet. Run the benchmark to see agent performance.

★ THE ADMIRAL — Autonomous Op Orchestrator

STANDING BY

Give the Admiral a high-level directive and it will autonomously plan the entire operation — identifying targets, allocating operators, setting OPSEC levels, and executing the full kill chain. No manual configuration needed.

Loading self-improvement loops…

🎛️ Universal API Config

Configure your LLM providers in one place — provider, key, base URL, model, and context cap — shared with the individual provider sections below (fully backward-compatible).

In-browser mission routing currently uses OpenRouter or Venice (or a connected local agent). Keys for other providers, custom base URLs, and the context cap are stored and used for model discovery and server-side / agent flows.

🔑 API Keys

OpenRouter API Key

Get key from openrouter.ai/keys

Venice API Key

OpenAI-compatible, privacy-focused. Get key from venice.ai/settings/api

Hugging Face Token

Open models via the OpenAI-compatible Inference Providers router. Get a token from huggingface.co/settings/tokens

Anthropic API Key

Stored, but direct-LLM currently routes via OpenRouter or a connected agent — not wired to this key yet.

OpenAI API Key

Stored, but direct-LLM currently routes via OpenRouter or a connected agent — not wired to this key yet.

🖥️ Local Model (llama.cpp / Ollama / OpenAI-compatible)

Point the War Room at a model running on your own host — no cloud, no OpenRouter. Requires npm run server. When enabled, BOTH server-dispatched missions/General AND the browser "AI" features route through your local model.

llama.cpp (OpenAI-compatible server): path /v1 · Ollama native: path /api (port 11434) · LM Studio: /v1 (port 1234)

🧅 Egress Proxy (SOCKS5)

Route all probe/attack fetch() traffic through a SOCKS5 proxy so tests don't leave from your own IP (Tor, an SSH -D tunnel, a VPS, etc.). Loopback (the local model & this server) is always bypassed. Requires npm run server; also settable via TEMPEST_PROXY_URL.

Tor: socks5://127.0.0.1:9050 · SSH tunnel: ssh -D 1080 hostsocks5://127.0.0.1:1080. Use socks5h:// to resolve DNS at the proxy.

🔌 Local Agents

Enlist agents you've already authed on this machine — no API keys needed. T3MP3ST detects each CLI (Claude Code / Codex / Hermes) and drives it as your LLM backbone using its own login. Connect one, then hit ☆ Use to pin it as the ★ active backbone for missions and analysis — a pinned local model outranks any stored API key.

🔌 Connect Local Agents
— scanning —
Detecting local agents…

🤖 Model Selection

Select your preferred AI model for agent operations

Loading models...
🔄 Fallback Model Auto-retries with this model if the primary fails (refusal, timeout, error)

🖥️ API Server

URL of your running T3MP3ST API server (start with npm run server)

Default: http://localhost:3333 — change if your server runs on a different host/port

⚠️ Data

Config Library
Saved Configurations
0 configs saved • Default: None

📊 Current Configuration

Not benchmarked
Run a benchmark to see current config performance

💾 Saved Configurations

💾
No saved configurations yet
Run benchmarks and save your best performing configs
████████╗██████╗ ███╗   ███╗██████╗ ██████╗ ███████╗████████╗
╚══██╔══╝╚════██╗████╗ ████║██╔══██╗╚════██╗██╔════╝╚══██╔══╝
   ██║    █████╔╝██╔████╔██║██████╔╝ █████╔╝███████╗   ██║
   ██║    ╚═══██╗██║╚██╔╝██║██╔═══╝  ╚═══██╗╚════██║   ██║
   ██║   ██████╔╝██║ ╚═╝ ██║██║     ██████╔╝███████║   ██║
   ╚═╝   ╚═════╝ ╚═╝     ╚═╝╚═╝     ╚═════╝ ╚══════╝   ╚═╝   

Turn the AI coding agent you already run into a red team.

🌩️ Coverage by domain

A domain lights up only when there's a benchmark behind it. Greyed tiles are in development.

🕸️

Web ✅

Apps, APIs, auth flows, OWASP Top 10. XBEN 90.1% pass@1.

📂

Code ✅

White-box source audits. Held-out CVE-Zero: single-agent 8/10 exact file/line/CWE, 10/10 found (7 languages).

🚩

CTF ✅

Wargames, ranges, challenges. Cybench 23/40 hint-free.

🔌

Network / Infra ✅

Live recon engine (nmap/DNS/HTTP). Lateral + privesc experimental.

🤖

Embedded / IoT / OT ✅

Firmware, robotics, ICS/SCADA. Coordinated-disclosure CVE pipeline live.

📦

Supply chain ⚠️

Dependency audits, install-without-confirmation. Dedicated class; real held-out hit.

💰

Blockchain ⚠️

Smart contracts, DeFi, Solidity. Reproduction only — not novel discovery yet.

☁️

Cloud COMING SOON

AWS/GCP/Azure misconfig, IAM, serverless.

📱

Mobile COMING SOON

Android / iOS app security.

🏢

Identity / AD COMING SOON

Kerberos, pass-the-hash, Active Directory.

🔐

Binary / RE COMING SOON

Overflows, ROP, exploit dev. Needs specialized tooling.

🧠

LLM Backbone

Multiple AI providers: OpenRouter, Anthropic, OpenAI, or local models via Ollama.

🤖

Autonomous Operatives

8 specialized AI agents aligned with MITRE ATT&CK kill chain phases. Click any operative below to view + edit its prompt, tools, and config.

🎯

Mission Control

Coordinate complex operations with intelligent task delegation.

🔐

Evidence Vault

Secure storage for findings, credentials, and attack paths.

👻

OPSEC Control

Configurable stealth levels from quiet recon to aggressive exploitation.

🛠️

Tool Arsenal

Extensible tool registry with automatic capability discovery.

🚀 Quick Start

TypeScript
import { Tempest } from 't3mp3st'; // Initialize const tempest = new Tempest({ provider: 'openrouter', model: 'anthropic/claude-opus-4.6' }); // Add target & spawn operators tempest.target.addHost('192.168.1.100'); tempest.operators.spawn('recon'); tempest.operators.spawn('scanner'); // Launch await tempest.start();

🤖 Operator Archetypes

OperatorRolePhase
🔍 ReconIntelligence & OSINTReconnaissance
📡 ScannerNetwork scanningReconnaissance
💥 ExploiterVulnerability exploitationExploitation
🥷 InfiltratorLateral movementInstallation
📤 ExfiltratorData extractionActions
👻 GhostAnti-forensicsAll
🎖️ CoordinatorOrchestrationAll
📊 AnalystReportingAll

Ready to Start?

Configure your API keys and launch your first mission.