Nightcrawler是一款完全在智能手机上本地运行的自主渗透测试智能体,无需任何云端连接[1]。该工具采用参数量为1.2亿的LFM2.5-1.2B-Instruct-Heretic模型,直接在手机GPU上执行推理任务[1],能够自动化地发现网络主机、扫描服务、识别漏洞并生成渗透测试报告[1]。
项目在OnePlus 8(搭载Snapdragon 865芯片)上进行了测试验证[1]。系统集成了27个漏洞利用剧本和24,956条CVE数据库条目[1],内存占用保持在35-50MB的低位水平[1]。在为期72小时的运行测试中,该工具发现了30多台主机、执行了2,000多条命令并识别了10多个漏洞[1]。尽管命令成功率约为50%(这是小规模模型的固有限制),该系统仍展示了在资源受限设备上进行自主安全评估的可行性[1]。
项目采用MIT开源许可证发布[1]。开发者强调,部署该工具"需要网络所有者的书面授权才能部署,未授权使用是违法的"[1]。
Nightcrawler is an autonomous penetration testing agent that operates entirely on a smartphone without requiring cloud connectivity.[1] The tool leverages a 1.2 billion-parameter local AI model to perform inference directly on mobile GPU hardware, enabling it to automatically discover network hosts, scan services, identify vulnerabilities, and generate penetration testing reports.[1]
The system runs on a OnePlus 8 device powered by a Snapdragon 865 chipset and uses the LFM2.5-1.2B-Instruct-Heretic model for its AI capabilities.[1] Nightcrawler's functionality includes 27 vulnerability exploitation scripts and access to a database containing 24,956 CVE entries.[1] During a 72-hour operational test, the agent discovered over 30 hosts, executed more than 2,000 commands, and identified 10 or more vulnerabilities.[1] The entire system maintains stable memory consumption between 35 and 50 MB.[1]
The project operates under an MIT open-source license and achieves approximately 50 percent command success rate, a limitation inherent to small-scale models.[1] Developers emphasize that "network owner written authorization is required before deployment, and unauthorized use is illegal."[1]