ARES - authorized red-team engagement automation with dashboard, campaign scope, module orchestration, OPSEC controls, encrypted vault, and reporting.
Python
553
435 commits
updated Sep 30, 2026
The open-core platform empowering enterprise red teams, MSSPs, and security operations centers to execute targeted offensive engagements, discover deterministic attack paths, and continuously validate defensive posture with zero collateral risk.
Platform Showcase • Why ARES? • Competitive Matrix • Architecture • MITRE Matrix • Quickstart • Sponsorship • Credits • Zero-Trust Security • Documentation
Traditional penetration testing is fundamentally flawed: it is expensive, episodic, point-in-time, and leaves organizations blind to newly introduced misconfigurations and emerging adversary tradecraft. Meanwhile, automated vulnerability scanners overwhelm SOC teams with thousands of hypothetical CVEs without demonstrating exploitability or multi-stage lateral attack paths.
ARES bridges this gap. Built from the ground up for modern enterprise infrastructure, ARES delivers an operator-directed red team engagement platform that models real-world threat actors. By combining deterministic application-layer ScopeGuard fail-closed enforcement, adaptive OPSEC noise profiling, an interactive directed acyclic graph (DAG) attack solver, and 66 active production execution modules (70 total catalogued) covering 60+ mapped adversary techniques across MITRE ATT&CK, ARES allows security teams to prove vulnerability exploitability, locate shortest compromise paths to Active Directory Crown Jewels, and generate executive-ready deliverables with zero operational downtime.
THE ARES ADVANTAGE
┌─────────────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ STRICT SCOPE ENCLAVE │ │ DIRECTED ATTACK ENGINE │ │ ZERO-TRUST ARCHITECTURE │
│ Fail-closed ScopeGuard │ │ Computes shortest paths │ │ Memory-only JWT tokens, │
│ & Egress Scope Wall │───│ to Domain Admins & Crown│───│ AES-256-GCM AEAD vault, │
│ prevents out-of-scope. │ │ Jewels deterministically│ │ strict HMAC-CSRF checks.│
└─────────────────────────┘ └─────────────────────────┘ └─────────────────────────┘
│
▼
┌─────────────────────────┐
│ INSTANT EXECUTIVE SUITE │
│ Branded PDF, HTML, JSON │
│ deliverables with zero │
│ native GTK dependencies │
└─────────────────────────┘
socket.connect, socket.sendto, asyncio.create_connection) in Python user space. Guarantees fail-closed enforcement so zero offensive packets reach unapproved IP addresses or subnets.domain_admin, full_compromise, cloud_audit), and the ARES decision engine synthesizes multi-stage execution paths using graph heuristics and optional LLM agents (Claude / OpenAI / local Ollama) under explicit operator authorization.| Operational Capability | Traditional Manual Pentest | Legacy Vulnerability Scanners | ARES Orchestration Platform |
|---|---|---|---|
| Testing Frequency | Annual / Semi-Annual | Scheduled Daily / Weekly | Continuous / On-Demand |
| Exploitability Validation | Manual & Labor Intensive | Theoretical CVE Matching (No Validation) | Deterministic Multi-Stage Proof |
| Multi-Hop Attack Paths | Manual Drawing | None | Real-Time Interactive DAG |
| Scope Enclave & Egress Guard | Operator Discipline Only | Network Firewalls Only | Fail-Closed Dual-Layer ScopeGuard & OS/Transport Firewall |
| Active Directory Lateral Paths | Slow Script Execution | No Active Paths | Native BloodHound, Kerberos Suite & Linux AD RFC Track |
| Credential Security & Storage | Loose Flat Files / Cleartext | Vulnerability Logs | AES-256-GCM Authenticated Vault |
| OPSEC & Telemetry Throttling | Manual Jitter Scripts | High Network Noise | Adaptive Noise Profiles & Governor |
| Delivery Time for Reports | 1-2 Weeks Post-Engagement | Raw Data Dumps | Instant Multi-Format Artifacts |
| Deployment Footprint | External Consultants | Bulky Cloud Agents | Air-Gapped Local / Self-Hosted |
The ARES Platform features a high-performance, responsive operator dashboard engineered with dark-tech aesthetics, low cognitive load, and audited operational control.
# Launch local development environment
.\.venv\Scripts\ares.exe dashboard dev --no-reload
Access barrier designed specifically for authorized offensive operators and security personnel.

ARES Operator Enclave - Sign In button erupts with crimson plasma fire on hover, click, and Enter key. Minimalist Rive-style showcase featuring the animated ARES Ruby Dragon mascot on the right panel.
requestAnimationFrame.InResponseTo/nonce), JIT role mapping, and strict local password lockout for federated identities. (See SSO Setup Guide).X-ARES-CSRF).Real-time operational command console providing instant posture visibility across active campaigns.

Executive Command Center displaying real-time telemetry, validated findings, attack surface metrics, and activity pulse.
Active Engagements, Validated Findings, Attack Surface, and Engine Health (P95 latency, worker pool, and queue depth). Engineered with crisp typography (Plus Jakarta Sans & JetBrains Mono), eliminating redundant counts and distracting indicator dots.Operational / Offline) with on-demand subsystem health inspection from any view.Zero-collateral target governance enforcing hard CIDR whitelist boundaries, dual-layer Scope Firewall egress interception, and encrypted evidence isolation.

Campaign Management interface showing target scopes, CIDR boundaries, noise controls, and encrypted credential vault.
OSFirewallController via Windows Defender Firewall / Linux Netfilter when elevated) with transport-level socket interception (socket.connect, socket.sendto, asyncio.create_connection) enforcing strict fail-closed CIDR boundaries. Features async ContextVar task isolation (zero bleed to database pools or web dashboard handlers), anti-re-entrancy DNS protection, loopback/Windows Proactor pipe safeguards, cloud provider allowlists, and recursive parameter scanning.<label> definitions across all campaign pickers and parameter inputs, preventing operator ambiguity during rapid engagements.Stealth, Normal, Aggressive) with randomized delay distributions.Extensive catalog of weaponized adversary techniques aligned with the MITRE ATT&CK enterprise matrix.

Module Catalog with MITRE ATT&CK categorization, dynamic parameter generation, and dry-run safety modes.
ad.kerberoast, ad.adcs, ad.enum_users), Windows (windows.uac_bypass, windows.lsass_dump), Linux, Cloud (AWS, Azure, GCP), and Network infrastructure.Interactive hierarchical lateral pivot topology graph with perimeter firewall flame effects, slide-over Tactical Inspector Drawer, and a real-time docked Beacon session terminal console.

ARES Tactical Pivot Graph & Interactive Beacon Terminal Console - Live enterprise campaign topology (Kali test), perimeter ingress firewall with animated flames, Linux/Windows compromised footholds, slide-over Tactical Inspector Drawer, and real-time interactive beacon terminal.
PERIMETER INGRESS 0.0.0.0/0), initial foothold workstations and services, internal servers, and high-value Active Directory Domain Controllers (DC01).COMPROMISED (ACTIVE) vs RECON TARGET), OS detection, and perimeter access ports (e.g. 22/TCP).T1548.001, T1552.001), and pattern summaries.×4, ×3) to preserve a clean, high-signal view.SYSTEM * for Tier-0 Domain Controllers and root access, Amber ADMIN for internal servers, Cyan BEACON for compromised user workstations, and Red Brick Firewall nodes for perimeter ingress.• PATHWAY LOCKED: [HOST] | N NODES | N HOPS). Freely zoom and pan across complex topologies without losing situational focus.CobaltSessionDock):
[HOST] root or [DC01] SYSTEM *) and heartbeat interval (last: 2s).beacon>):
whoami: Resolves integrity level and active user context (TARGET\SYSTEM * or root).hashdump / creds: Harvests and displays cached NTLM SAM/LSA hashes.ps / process: Enumerates active process trees and resolves parent PIDs.ppid <pid>: Tasks beacon to spoof parent process IDs for EDR evasion.ssh <host> <user> <pass>: Tasks interactive lateral SSH traversal.net view / hosts / recon: Lists discovered network scope and adjacent nodes.clear: Clears current session terminal scrollback buffer.help: Quick reference of supported beacon tasking commands.Mode: LIVE CAMPAIGN: Renders live scoped engagement targets and findings discovered during reconnaissance. Use the [Active Pivots Only] filter to focus exclusively on confirmed lateral compromise routes.Mode: DEMO SAMPLE: Instant reference 9-node interconnected lateral pivot topology demonstrating enterprise multi-hop infiltration chains.Instant deliverable generation producing branded, audit-ready compliance reports across multiple enterprise formats (Executive PDF, Technical Markdown, Defect CSV).

Report Engine and Artifact Library supporting multi-format exports with synchronized real-time lifecycle management.
<label> elements (Target Campaign, Export Format) and clean inline validation error feedback.Goal-directed engine that plans, prioritizes, and stages complex attack chains with operator oversight while respecting OPSEC limits.

Strategy Console for goal-based campaign planning and adaptive containment governance.
GET /api/tags) with sub-second timeouts and TTL caching, paired with dynamic server-side cloud key verification (Claude, OpenAI).Target Campaign, Strategic Objective, AI Planning Engine, Explicit Authorizations), human-readable goal descriptions, and complete elimination of server environment variable leakage in UI labels.Deterministic, multi-step kill chains orchestrating reconnaissance, credential harvesting, and lateral movement in sequence.

Automated execution chains including AD Kerberos Exposure Chain and AD Domain Enumeration Chain.
asreproast -> kerberoast -> hashcat), domain enumeration, and cloud privilege escalation.Empirical tracking of evasion efficacy across enterprise endpoint detection and response (EDR) platforms.

Bypass Knowledge Base tracking technique success rates across CrowdStrike Falcon, SentinelOne, and Microsoft Defender.
Audited multi-role access control, cryptographic API key lifecycle, and continuous platform integrity verification.

Operator profile management, scoped API key provisioning, and automated system security audits.
Team Lead, Operator, Recon, Reporter) governing module execution and evidence viewing.High-frequency WebSocket event bus streaming operational telemetry, module output, and pipeline status.

Live operational event console with buffered telemetry and high-throughput WebSocket streaming.
Standardized engagement architectures for recurring red team exercises, compliance audits, and purple team drills.

Built-in engagement templates including Internal Pentest, AD Full Compromise, Cloud Assessment, and Assumed Breach.
Fully documented, interactive REST API surface for custom tooling, SOC orchestration, and CI/CD pipeline integration.

Interactive Swagger UI documentation exposing 70+ operational endpoints for enterprise automation.
| Surface | Core Responsibility | Available Sub-Tabs | Primary Operators |
|---|---|---|---|
| Overview | Executive health, telemetry counters, finding severity metrics. | Single Pane | All Stakeholders |
| Campaigns | Scope whitelisting, noise profiles, encrypted credential vault. | List, Scope, Findings | Team Lead, Operator |
| Modules | 66 active module catalog (70 total, 60+ techniques), parameter input forms, execution console. | Catalog, Run Panel, Results | Operator |
| Reports | Deliverable builder, evidence packages, Report Library lifecycle. | Generate, Library | Operator, Reporter |
| Graph | Cobalt Strike pivot topology, lateral movement tracking, Beacon session dock. | Live Campaign, Demo Sample, Beacon Console | Operator, Recon |
| Templates | Repeatable engagement playbooks and multi-stage workflow plans. | Templates, Plan Builder | Team Lead, Operator |
| Strategy | Goal-directed attack engine, automated planner integration. | Objective, Active, Result | Team Lead, Operator |
| Security | Operator credentials, API key lifecycle, dependency audit checks. | Account, API Keys, Audit | Team Lead |
| EDR/OPSEC | Defensive telemetry, bypass tracking, detection evasion rules. | Knowledge Base, Report Outcome | Operator |
| Live | Real-time WebSocket event streams and buffered telemetry logs. | Stream, Buffer | Operator |
ARES follows a strict defense-in-depth architecture separating presentation, execution orchestration, security governance, and persistent cryptographic storage:
flowchart TB
subgraph Client["Presentation Layer (Operator Enclave)"]
UI["React 18 Dashboard<br>(Vite + TypeScript)"]
Mesh["Dynamic Architectural Grid<br>(Canvas 2D Engine)"]
WSClient["WebSocket Client<br>(Real-Time Telemetry Stream)"]
end
subgraph Gateway["Zero-Trust Security Gateway"]
FastAPI["FastAPI Async Engine<br>(Uvicorn Backend)"]
AuthGuard["Auth & Session Guard<br>(Memory-Only JWT + HttpOnly Refresh)"]
CSRF["HMAC Double-Submit CSRF<br>(X-ARES-CSRF Validation)"]
RateLimit["Rate Limiting & Brute-Force Shield"]
end
subgraph Core["ARES Core Engine & Governance"]
ScopeFirewall["Scope Firewall & Transport Egress Hook<br>(In-Process Transport & OS Packet Filtering)"]
Governor["OPSEC Noise Governor<br>(Adaptive Jitter & Throttling)"]
Orchestrator["Module Execution Orchestrator<br>(Worker Thread Pool)"]
AutoPlanner["Goal-Directed Strategy Engine<br>(DAG Heuristics / Planner)"]
end
subgraph Storage["Cryptographic Persistence Layer"]
DB[(SQLite / PostgreSQL<br>Alembic Versioned)]
Vault[(AES-256-GCM Encrypted Vault<br>Encrypted Credentials & Hashes)]
GraphEngine["Attack Graph DAG Engine<br>(BloodHound Ingest & Shortest Path)"]
end
subgraph Deliverables["Reporting Pipeline"]
PDFGen["Headless Chromium / Edge Engine<br>(Automated PDF Generation)"]
Artifacts["Evidence Library<br>(HTML, Markdown, JSON)"]
end
UI -->|HTTPS / REST| AuthGuard
WSClient -->|WSS / Ticket Barrier| AuthGuard
AuthGuard --> CSRF --> RateLimit --> FastAPI
FastAPI --> ScopeFirewall
ScopeFirewall --> Orchestrator
Orchestrator --> Governor
Orchestrator --> AutoPlanner
Orchestrator --> Storage
Storage --> GraphEngine
FastAPI --> Deliverables
ARES implements 66 active production execution modules (70 total catalogued) mapping to 60+ adversary techniques across the MITRE ATT&CK Enterprise Framework:
┌──────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│ MITRE ATT&CK MATRIX COVERAGE │
├─────────────────────┬─────────────────────┬─────────────────────┬─────────────────────┬──────────────────────────┤
│ DISCOVERY │ CREDENTIAL ACCESS │ LATERAL MOVEMENT │ PRIVILEGE ESCALATION│ DEFENSE EVASION / CLOUD │
├─────────────────────┼─────────────────────┼─────────────────────┼─────────────────────┼──────────────────────────┤
│ • T1087 User Enum │ • T1558.003 Kerberoast│ • T1021.002 SMB/RPC │ • T1548.002 UAC Byps│ • T1070 Indicator Removal│
│ • T1069 Group Enum │ • T1558.004 AS-REP │ • T1021.006 WinRM │ • T1068 Token Privs │ • T1562 Impair Defenses │
│ • T1046 Port/Net │ • T1003 LSASS Dump │ • T1550 Use Ticket │ • T1053 Scheduled │ • T1078 Cloud IAM Enum │
│ • T1018 Host Disc │ • T1649 ADCS ESC1-8 │ • T1071 App Layer │ • T1055 Injection │ • T1580 Cloud Discovery │
│ • T1082 System Info │ • T1110 Pass Spray │ • T1021.001 RDP │ • T1134 Access Token│ • T1526 Cloud Hierarchy │
└─────────────────────┴─────────────────────┴─────────────────────┴─────────────────────┴──────────────────────────┘
ad.kerberoast), AS-REP Roasting, ADCS Certificate Template abuse and enrollment checks (ad.adcs; ad.ghost_forge retained as disabled audit stub), DCSync account replication, and BloodHound data generation.linux.sssd_harvest), pure-Python Kerberos ccache ticket hunting (linux.ccache_hunt), keytab parsing & Silver Ticket generation (linux.keytab_abuse), Samba machine secrets extraction (linux.samba_secrets), and bidirectional ccache <-> kirbi ticket transcoding (credential.ticket_converter).cloud.phantom_token retained as disabled audit stub).# 1. Clone the repository
git clone https://github.com/Mafifrizi/ARES.git
Set-Location .\ARES
# 2. Setup isolated Python virtual environment
py -3.12 -m venv .venv
.\.venv\Scripts\python.exe -m pip install -U pip
.\.venv\Scripts\python.exe -m pip install -e ".[dev,pdf]"
# 3. Install frontend dependencies
Set-Location frontend
& "C:\Program Files\nodejs\npm.cmd" ci
Set-Location ..
# 4. Configure local Edge PDF rendering engine & verify doctor status
$env:ARES_PDF_BROWSER = "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"
.\.venv\Scripts\ares.exe doctor --pdf-smoke
# 5. Launch development server (Frontend + Backend proxy)
.\.venv\Scripts\ares.exe dashboard dev --no-reload
Open your browser to http://127.0.0.1:5173/dashboard/.
adminARES_DEFAULT_ADMIN_PASSWORD in .env (default: Admin123456!)ares update & ares upgrade)ARES includes a built-in Nuclei-style update engine. Operators do not need to git clone or manually recompile the frontend when new capabilities or visual improvements are released:
ares update # Scan GitHub and install newly released modules
ares update --module <id> # Install a specific new module
ares update --dry-run # Preview new modules without modifying disk
ares upgrade # Full-system upgrade (Core platform + DB migrations + Modules + UI)
ares upgrade --system # Upgrade core framework engine and apply database schema migrations
ares upgrade --check # Check commit delta and available updates without modifying disk
ares upgrade --ui # Upgrade Frontend Web UI dashboard bundle
ares upgrade --modules # Upgrade installed modules to latest revisions
ares upgrade --dry-run # Preview upgrades without modifying disk
[!NOTE] Zero Data Loss Guarantee: User databases (
~/.ares/ares.dbor PostgreSQL), credentials, configuration files (config.yaml), audit reports, and custom user plugins (~/.ares/plugins/) are mathematically blacklisted from modification. Pre-flight Python AST verification and atomic file writes ensure zero risk of corruption.
ARES was designed for environments with the most stringent compliance and confidentiality requirements:
localStorage or sessionStorage.ares_refresh) with one-time rotation and automatic reuse revocation.X-ARES-CSRF headers matched against cryptographically secure cookie tokens.ARES enforces strict RBAC permissions across all API endpoints, background jobs, and UI surfaces:
| Role | API Value | Operational Scope | Administrative Authority |
|---|---|---|---|
| Team Lead | team_lead | Complete platform authority: campaign creation/deletion, user provisioning, security audits, high-noise module overrides. | Full System Admin |
| Operator | operator | Day-to-day operations: execute authorized modules, review findings, explore attack graph, generate reports. Cannot register users. | Operational Tier |
| Recon | recon | Read-heavy reconnaissance: execute safe discovery and network fingerprinting modules. Execution of disruptive modules is blocked. | Read-Heavy |
| Reporter | reporter | Stakeholder review: read-only access to campaign analytics, findings, attack graphs, and generated deliverables. No execution rights. | Read-Only Audit |
row = await db.resolve_access_token_principal(...)). Tampered JWT claims are mathematically discarded.team_lead via POST /auth/register (guarded by require_team_lead()) or automatically mapped from enterprise Identity Providers during SP-initiated SAML/OIDC SSO.PUT /users/{id} does not exist), eliminating horizontal and vertical privilege escalation vectors (e.g., recon escalating to team_lead or reporter running offensive modules).Security console provides a transparent inventory of all registered identities and active sessions for engagement accountability.ARES provides a production-grade Model Context Protocol (MCP) Gateway that enables modern AI coding assistants (Cursor IDE, Claude Desktop, Windsurf, VS Code Cline, Zed, Open-WebUI, LibreChat) to interact with the ARES purple-team offensive platform safely and under strict governance.

ARES MCP Two-Pane Split Terminal Monitor (OpenClaw style) with real-time tool telemetry, live scope inspection, and 1-key token authorization.
Unlike basic MCP servers that expose raw endpoints to LLMs without guardrails, ARES enforces strict Pre-Flight Scope Invariance (ScopeGuard), Anti-Prompt-Injection Taint Isolation, and Single-Use 60-second HMAC Confirmation Tokens before any live offensive action can execute.
For operators or developers connecting Cursor, Claude Desktop, or Windsurf to ARES:
Verify Subsystem Readiness (doctor):
Ensure all core subsystems (Protocol Engine, 9 Tools, 3 Resources, 3 Prompts, 62 Descriptors, Security Gates) report PASS:
.\mcp.bat doctor
1-Click AI Client Setup (No Manual JSON Editing): Automatically configure your preferred IDE with a single command:
# For Cursor IDE:
.\mcp.bat setup --client cursor
# For Claude Desktop:
.\mcp.bat setup --client claude
# For Windsurf:
.\mcp.bat setup --client windsurf
# For VS Code (Cline):
.\mcp.bat setup --client cline
This writes your active Python virtual environment path directly into the client config file (e.g. .cursor/mcp.json).
Reload Window in Cursor IDE:
Ctrl + Shift + P.Developer: Reload Window.Ctrl + ,) → Features → MCP Servers. The ares server will show a green dot (Connected).Launch the Live Two-Pane Monitor (Optional Companion Window): In a dedicated terminal window, run the OpenClaw-style two-pane monitor to watch real-time AI tool invocations, scope checks, and approve tokens:
.\mcp.bat monitor
ares_scope_check, ares_dry_run_module, ares_run_tool).A to approve a pending execution token, R to reject, C to clear stream, Q to quit.Issue Your First Command to the AI Agent:
Open Cursor Composer / Chat (Ctrl + I or Ctrl + L), and try this prompt:
"Check active campaign status, verify scope for target 10.0.1.50, and stage a dry-run of module ad.kerberoast."
For in-depth architecture, the 7 security invariants, CLI scriptability (--json), POSIX exit codes, and operational tool schemas, see ARES MCP Gateway & Product-Grade CLI Specification.
ARES provides a first-class, type-safe Python SDK (ares.sdk) to build custom adversary modules, simulate techniques in isolated test harnesses, and automate engagements programmatically:
BaseModule[P, R] & @ares_module)Declare validated parameter schemas with Pydantic v2 and write modules with full IDE autocomplete:
from ares.sdk import (
BaseModule, ExecutionContext, ModuleResult,
ModuleParams, param, SecretParam,
OpsecLevel, Severity, ares_module,
)
class KerberoastParams(ModuleParams):
dc: str = param("Target Domain Controller IP or FQDN", min_length=3)
domain: str = param("AD DNS domain name, e.g. CORP.LOCAL", min_length=3)
password: SecretParam = param("Domain user password", secret=True, required=False)
class CustomKerberoastModule(BaseModule[KerberoastParams, ModuleResult]):
MODULE_ID = "custom.ad.kerberoast"
MODULE_NAME = "Custom Kerberoasting"
MODULE_CATEGORY = "ad"
OPSEC_LEVEL = OpsecLevel.LOW
MITRE_TECHNIQUES = ["T1558.003"]
PARAMS_MODEL = KerberoastParams
async def execute(self, ctx: ExecutionContext[KerberoastParams]) -> ModuleResult:
# ctx.params provides full static typing and runtime validation
await self.before_request(ctx.params.dc)
# Emit findings using fluent context helpers
finding = ctx.emit_finding(
title=f"Kerberoastable SPN Captured on {ctx.params.dc}",
severity=Severity.HIGH,
mitre_technique="T1558.003",
)
return ModuleResult(status="success", findings=[finding], module_id=self.MODULE_ID)
ModuleTestHarness)Unit test custom techniques locally with mock scope guards, synthetic credential vaults, and fluent assertion matchers:
from ares.sdk import ModuleTestHarness, Severity
async def test_module():
harness = ModuleTestHarness(CustomKerberoastModule)
result = await harness.simulate(params={"dc": "10.0.0.10", "domain": "LAB.LOCAL"})
result.assert_success()
result.assert_finding(severity=Severity.HIGH, mitre="T1558.003")
AresClient)Automate engagements, dispatch modules, and stream real-time WebSocket telemetry via Python scripts or CI/CD pipelines:
from ares.sdk import AresClient
async with AresClient(base_url="http://127.0.0.1:8080", api_key="ares_key_...") as ares:
campaign = await ares.campaigns.create(name="Op-Titan", scope=["10.0.0.0/24"])
job = await ares.modules.run("ad.kerberoast", target="dc01.corp.local", campaign_id=campaign["id"])
findings = await ares.campaigns.findings(campaign["id"])
See docs/module_sdk.md and docs/module-development.md for full developer documentation, architecture specifications, and examples.
Comprehensive documentation is available in the docs/ directory:
If ARES has accelerated your security assessments, helped protect your enterprise infrastructure, or advanced your offensive security research, consider sponsoring the project to fund continuous feature development, threat research, and lab infrastructure:
Your support helps keep ARES open-source, robust, and continuously updated against the latest adversary tradecraft.
[!IMPORTANT] ARES is a dual-use software framework designed exclusively for authorized cybersecurity research, internal enterprise resilience validation, and professional red-team engagements with explicit written permission.
To report security vulnerabilities in ARES, please follow our Security Policy.
ARES is distributed under the open-source MIT License.
ARES - Modern Red Team Engagement & Continuous Security Validation System.
Continuous Security Validation. Zero Collateral Risk.
121 followers · starred Sep 2026
Python
92.7%
TypeScript
6.5%
ARES - authorized red-team engagement automation with dashboard, campaign scope, module orchestration, OPSEC controls, encrypted vault, and reporting.
Python
553
435 commits
updated Sep 30, 2026
The open-core platform empowering enterprise red teams, MSSPs, and security operations centers to execute targeted offensive engagements, discover deterministic attack paths, and continuously validate defensive posture with zero collateral risk.
Platform Showcase • Why ARES? • Competitive Matrix • Architecture • MITRE Matrix • Quickstart • Sponsorship • Credits • Zero-Trust Security • Documentation
Traditional penetration testing is fundamentally flawed: it is expensive, episodic, point-in-time, and leaves organizations blind to newly introduced misconfigurations and emerging adversary tradecraft. Meanwhile, automated vulnerability scanners overwhelm SOC teams with thousands of hypothetical CVEs without demonstrating exploitability or multi-stage lateral attack paths.
ARES bridges this gap. Built from the ground up for modern enterprise infrastructure, ARES delivers an operator-directed red team engagement platform that models real-world threat actors. By combining deterministic application-layer ScopeGuard fail-closed enforcement, adaptive OPSEC noise profiling, an interactive directed acyclic graph (DAG) attack solver, and 66 active production execution modules (70 total catalogued) covering 60+ mapped adversary techniques across MITRE ATT&CK, ARES allows security teams to prove vulnerability exploitability, locate shortest compromise paths to Active Directory Crown Jewels, and generate executive-ready deliverables with zero operational downtime.
THE ARES ADVANTAGE
┌─────────────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ STRICT SCOPE ENCLAVE │ │ DIRECTED ATTACK ENGINE │ │ ZERO-TRUST ARCHITECTURE │
│ Fail-closed ScopeGuard │ │ Computes shortest paths │ │ Memory-only JWT tokens, │
│ & Egress Scope Wall │───│ to Domain Admins & Crown│───│ AES-256-GCM AEAD vault, │
│ prevents out-of-scope. │ │ Jewels deterministically│ │ strict HMAC-CSRF checks.│
└─────────────────────────┘ └─────────────────────────┘ └─────────────────────────┘
│
▼
┌─────────────────────────┐
│ INSTANT EXECUTIVE SUITE │
│ Branded PDF, HTML, JSON │
│ deliverables with zero │
│ native GTK dependencies │
└─────────────────────────┘
socket.connect, socket.sendto, asyncio.create_connection) in Python user space. Guarantees fail-closed enforcement so zero offensive packets reach unapproved IP addresses or subnets.domain_admin, full_compromise, cloud_audit), and the ARES decision engine synthesizes multi-stage execution paths using graph heuristics and optional LLM agents (Claude / OpenAI / local Ollama) under explicit operator authorization.| Operational Capability | Traditional Manual Pentest | Legacy Vulnerability Scanners | ARES Orchestration Platform |
|---|---|---|---|
| Testing Frequency | Annual / Semi-Annual | Scheduled Daily / Weekly | Continuous / On-Demand |
| Exploitability Validation | Manual & Labor Intensive | Theoretical CVE Matching (No Validation) | Deterministic Multi-Stage Proof |
| Multi-Hop Attack Paths | Manual Drawing | None | Real-Time Interactive DAG |
| Scope Enclave & Egress Guard | Operator Discipline Only | Network Firewalls Only | Fail-Closed Dual-Layer ScopeGuard & OS/Transport Firewall |
| Active Directory Lateral Paths | Slow Script Execution | No Active Paths | Native BloodHound, Kerberos Suite & Linux AD RFC Track |
| Credential Security & Storage | Loose Flat Files / Cleartext | Vulnerability Logs | AES-256-GCM Authenticated Vault |
| OPSEC & Telemetry Throttling | Manual Jitter Scripts | High Network Noise | Adaptive Noise Profiles & Governor |
| Delivery Time for Reports | 1-2 Weeks Post-Engagement | Raw Data Dumps | Instant Multi-Format Artifacts |
| Deployment Footprint | External Consultants | Bulky Cloud Agents | Air-Gapped Local / Self-Hosted |
The ARES Platform features a high-performance, responsive operator dashboard engineered with dark-tech aesthetics, low cognitive load, and audited operational control.
# Launch local development environment
.\.venv\Scripts\ares.exe dashboard dev --no-reload
Access barrier designed specifically for authorized offensive operators and security personnel.

ARES Operator Enclave - Sign In button erupts with crimson plasma fire on hover, click, and Enter key. Minimalist Rive-style showcase featuring the animated ARES Ruby Dragon mascot on the right panel.
requestAnimationFrame.InResponseTo/nonce), JIT role mapping, and strict local password lockout for federated identities. (See SSO Setup Guide).X-ARES-CSRF).Real-time operational command console providing instant posture visibility across active campaigns.

Executive Command Center displaying real-time telemetry, validated findings, attack surface metrics, and activity pulse.
Active Engagements, Validated Findings, Attack Surface, and Engine Health (P95 latency, worker pool, and queue depth). Engineered with crisp typography (Plus Jakarta Sans & JetBrains Mono), eliminating redundant counts and distracting indicator dots.Operational / Offline) with on-demand subsystem health inspection from any view.Zero-collateral target governance enforcing hard CIDR whitelist boundaries, dual-layer Scope Firewall egress interception, and encrypted evidence isolation.

Campaign Management interface showing target scopes, CIDR boundaries, noise controls, and encrypted credential vault.
OSFirewallController via Windows Defender Firewall / Linux Netfilter when elevated) with transport-level socket interception (socket.connect, socket.sendto, asyncio.create_connection) enforcing strict fail-closed CIDR boundaries. Features async ContextVar task isolation (zero bleed to database pools or web dashboard handlers), anti-re-entrancy DNS protection, loopback/Windows Proactor pipe safeguards, cloud provider allowlists, and recursive parameter scanning.<label> definitions across all campaign pickers and parameter inputs, preventing operator ambiguity during rapid engagements.Stealth, Normal, Aggressive) with randomized delay distributions.Extensive catalog of weaponized adversary techniques aligned with the MITRE ATT&CK enterprise matrix.

Module Catalog with MITRE ATT&CK categorization, dynamic parameter generation, and dry-run safety modes.
ad.kerberoast, ad.adcs, ad.enum_users), Windows (windows.uac_bypass, windows.lsass_dump), Linux, Cloud (AWS, Azure, GCP), and Network infrastructure.Interactive hierarchical lateral pivot topology graph with perimeter firewall flame effects, slide-over Tactical Inspector Drawer, and a real-time docked Beacon session terminal console.

ARES Tactical Pivot Graph & Interactive Beacon Terminal Console - Live enterprise campaign topology (Kali test), perimeter ingress firewall with animated flames, Linux/Windows compromised footholds, slide-over Tactical Inspector Drawer, and real-time interactive beacon terminal.
PERIMETER INGRESS 0.0.0.0/0), initial foothold workstations and services, internal servers, and high-value Active Directory Domain Controllers (DC01).COMPROMISED (ACTIVE) vs RECON TARGET), OS detection, and perimeter access ports (e.g. 22/TCP).T1548.001, T1552.001), and pattern summaries.×4, ×3) to preserve a clean, high-signal view.SYSTEM * for Tier-0 Domain Controllers and root access, Amber ADMIN for internal servers, Cyan BEACON for compromised user workstations, and Red Brick Firewall nodes for perimeter ingress.• PATHWAY LOCKED: [HOST] | N NODES | N HOPS). Freely zoom and pan across complex topologies without losing situational focus.CobaltSessionDock):
[HOST] root or [DC01] SYSTEM *) and heartbeat interval (last: 2s).beacon>):
whoami: Resolves integrity level and active user context (TARGET\SYSTEM * or root).hashdump / creds: Harvests and displays cached NTLM SAM/LSA hashes.ps / process: Enumerates active process trees and resolves parent PIDs.ppid <pid>: Tasks beacon to spoof parent process IDs for EDR evasion.ssh <host> <user> <pass>: Tasks interactive lateral SSH traversal.net view / hosts / recon: Lists discovered network scope and adjacent nodes.clear: Clears current session terminal scrollback buffer.help: Quick reference of supported beacon tasking commands.Mode: LIVE CAMPAIGN: Renders live scoped engagement targets and findings discovered during reconnaissance. Use the [Active Pivots Only] filter to focus exclusively on confirmed lateral compromise routes.Mode: DEMO SAMPLE: Instant reference 9-node interconnected lateral pivot topology demonstrating enterprise multi-hop infiltration chains.Instant deliverable generation producing branded, audit-ready compliance reports across multiple enterprise formats (Executive PDF, Technical Markdown, Defect CSV).

Report Engine and Artifact Library supporting multi-format exports with synchronized real-time lifecycle management.
<label> elements (Target Campaign, Export Format) and clean inline validation error feedback.Goal-directed engine that plans, prioritizes, and stages complex attack chains with operator oversight while respecting OPSEC limits.

Strategy Console for goal-based campaign planning and adaptive containment governance.
GET /api/tags) with sub-second timeouts and TTL caching, paired with dynamic server-side cloud key verification (Claude, OpenAI).Target Campaign, Strategic Objective, AI Planning Engine, Explicit Authorizations), human-readable goal descriptions, and complete elimination of server environment variable leakage in UI labels.Deterministic, multi-step kill chains orchestrating reconnaissance, credential harvesting, and lateral movement in sequence.

Automated execution chains including AD Kerberos Exposure Chain and AD Domain Enumeration Chain.
asreproast -> kerberoast -> hashcat), domain enumeration, and cloud privilege escalation.Empirical tracking of evasion efficacy across enterprise endpoint detection and response (EDR) platforms.

Bypass Knowledge Base tracking technique success rates across CrowdStrike Falcon, SentinelOne, and Microsoft Defender.
Audited multi-role access control, cryptographic API key lifecycle, and continuous platform integrity verification.

Operator profile management, scoped API key provisioning, and automated system security audits.
Team Lead, Operator, Recon, Reporter) governing module execution and evidence viewing.High-frequency WebSocket event bus streaming operational telemetry, module output, and pipeline status.

Live operational event console with buffered telemetry and high-throughput WebSocket streaming.
Standardized engagement architectures for recurring red team exercises, compliance audits, and purple team drills.

Built-in engagement templates including Internal Pentest, AD Full Compromise, Cloud Assessment, and Assumed Breach.
Fully documented, interactive REST API surface for custom tooling, SOC orchestration, and CI/CD pipeline integration.

Interactive Swagger UI documentation exposing 70+ operational endpoints for enterprise automation.
| Surface | Core Responsibility | Available Sub-Tabs | Primary Operators |
|---|---|---|---|
| Overview | Executive health, telemetry counters, finding severity metrics. | Single Pane | All Stakeholders |
| Campaigns | Scope whitelisting, noise profiles, encrypted credential vault. | List, Scope, Findings | Team Lead, Operator |
| Modules | 66 active module catalog (70 total, 60+ techniques), parameter input forms, execution console. | Catalog, Run Panel, Results | Operator |
| Reports | Deliverable builder, evidence packages, Report Library lifecycle. | Generate, Library | Operator, Reporter |
| Graph | Cobalt Strike pivot topology, lateral movement tracking, Beacon session dock. | Live Campaign, Demo Sample, Beacon Console | Operator, Recon |
| Templates | Repeatable engagement playbooks and multi-stage workflow plans. | Templates, Plan Builder | Team Lead, Operator |
| Strategy | Goal-directed attack engine, automated planner integration. | Objective, Active, Result | Team Lead, Operator |
| Security | Operator credentials, API key lifecycle, dependency audit checks. | Account, API Keys, Audit | Team Lead |
| EDR/OPSEC | Defensive telemetry, bypass tracking, detection evasion rules. | Knowledge Base, Report Outcome | Operator |
| Live | Real-time WebSocket event streams and buffered telemetry logs. | Stream, Buffer | Operator |
ARES follows a strict defense-in-depth architecture separating presentation, execution orchestration, security governance, and persistent cryptographic storage:
flowchart TB
subgraph Client["Presentation Layer (Operator Enclave)"]
UI["React 18 Dashboard<br>(Vite + TypeScript)"]
Mesh["Dynamic Architectural Grid<br>(Canvas 2D Engine)"]
WSClient["WebSocket Client<br>(Real-Time Telemetry Stream)"]
end
subgraph Gateway["Zero-Trust Security Gateway"]
FastAPI["FastAPI Async Engine<br>(Uvicorn Backend)"]
AuthGuard["Auth & Session Guard<br>(Memory-Only JWT + HttpOnly Refresh)"]
CSRF["HMAC Double-Submit CSRF<br>(X-ARES-CSRF Validation)"]
RateLimit["Rate Limiting & Brute-Force Shield"]
end
subgraph Core["ARES Core Engine & Governance"]
ScopeFirewall["Scope Firewall & Transport Egress Hook<br>(In-Process Transport & OS Packet Filtering)"]
Governor["OPSEC Noise Governor<br>(Adaptive Jitter & Throttling)"]
Orchestrator["Module Execution Orchestrator<br>(Worker Thread Pool)"]
AutoPlanner["Goal-Directed Strategy Engine<br>(DAG Heuristics / Planner)"]
end
subgraph Storage["Cryptographic Persistence Layer"]
DB[(SQLite / PostgreSQL<br>Alembic Versioned)]
Vault[(AES-256-GCM Encrypted Vault<br>Encrypted Credentials & Hashes)]
GraphEngine["Attack Graph DAG Engine<br>(BloodHound Ingest & Shortest Path)"]
end
subgraph Deliverables["Reporting Pipeline"]
PDFGen["Headless Chromium / Edge Engine<br>(Automated PDF Generation)"]
Artifacts["Evidence Library<br>(HTML, Markdown, JSON)"]
end
UI -->|HTTPS / REST| AuthGuard
WSClient -->|WSS / Ticket Barrier| AuthGuard
AuthGuard --> CSRF --> RateLimit --> FastAPI
FastAPI --> ScopeFirewall
ScopeFirewall --> Orchestrator
Orchestrator --> Governor
Orchestrator --> AutoPlanner
Orchestrator --> Storage
Storage --> GraphEngine
FastAPI --> Deliverables
ARES implements 66 active production execution modules (70 total catalogued) mapping to 60+ adversary techniques across the MITRE ATT&CK Enterprise Framework:
┌──────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│ MITRE ATT&CK MATRIX COVERAGE │
├─────────────────────┬─────────────────────┬─────────────────────┬─────────────────────┬──────────────────────────┤
│ DISCOVERY │ CREDENTIAL ACCESS │ LATERAL MOVEMENT │ PRIVILEGE ESCALATION│ DEFENSE EVASION / CLOUD │
├─────────────────────┼─────────────────────┼─────────────────────┼─────────────────────┼──────────────────────────┤
│ • T1087 User Enum │ • T1558.003 Kerberoast│ • T1021.002 SMB/RPC │ • T1548.002 UAC Byps│ • T1070 Indicator Removal│
│ • T1069 Group Enum │ • T1558.004 AS-REP │ • T1021.006 WinRM │ • T1068 Token Privs │ • T1562 Impair Defenses │
│ • T1046 Port/Net │ • T1003 LSASS Dump │ • T1550 Use Ticket │ • T1053 Scheduled │ • T1078 Cloud IAM Enum │
│ • T1018 Host Disc │ • T1649 ADCS ESC1-8 │ • T1071 App Layer │ • T1055 Injection │ • T1580 Cloud Discovery │
│ • T1082 System Info │ • T1110 Pass Spray │ • T1021.001 RDP │ • T1134 Access Token│ • T1526 Cloud Hierarchy │
└─────────────────────┴─────────────────────┴─────────────────────┴─────────────────────┴──────────────────────────┘
ad.kerberoast), AS-REP Roasting, ADCS Certificate Template abuse and enrollment checks (ad.adcs; ad.ghost_forge retained as disabled audit stub), DCSync account replication, and BloodHound data generation.linux.sssd_harvest), pure-Python Kerberos ccache ticket hunting (linux.ccache_hunt), keytab parsing & Silver Ticket generation (linux.keytab_abuse), Samba machine secrets extraction (linux.samba_secrets), and bidirectional ccache <-> kirbi ticket transcoding (credential.ticket_converter).cloud.phantom_token retained as disabled audit stub).# 1. Clone the repository
git clone https://github.com/Mafifrizi/ARES.git
Set-Location .\ARES
# 2. Setup isolated Python virtual environment
py -3.12 -m venv .venv
.\.venv\Scripts\python.exe -m pip install -U pip
.\.venv\Scripts\python.exe -m pip install -e ".[dev,pdf]"
# 3. Install frontend dependencies
Set-Location frontend
& "C:\Program Files\nodejs\npm.cmd" ci
Set-Location ..
# 4. Configure local Edge PDF rendering engine & verify doctor status
$env:ARES_PDF_BROWSER = "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"
.\.venv\Scripts\ares.exe doctor --pdf-smoke
# 5. Launch development server (Frontend + Backend proxy)
.\.venv\Scripts\ares.exe dashboard dev --no-reload
Open your browser to http://127.0.0.1:5173/dashboard/.
adminARES_DEFAULT_ADMIN_PASSWORD in .env (default: Admin123456!)ares update & ares upgrade)ARES includes a built-in Nuclei-style update engine. Operators do not need to git clone or manually recompile the frontend when new capabilities or visual improvements are released:
ares update # Scan GitHub and install newly released modules
ares update --module <id> # Install a specific new module
ares update --dry-run # Preview new modules without modifying disk
ares upgrade # Full-system upgrade (Core platform + DB migrations + Modules + UI)
ares upgrade --system # Upgrade core framework engine and apply database schema migrations
ares upgrade --check # Check commit delta and available updates without modifying disk
ares upgrade --ui # Upgrade Frontend Web UI dashboard bundle
ares upgrade --modules # Upgrade installed modules to latest revisions
ares upgrade --dry-run # Preview upgrades without modifying disk
[!NOTE] Zero Data Loss Guarantee: User databases (
~/.ares/ares.dbor PostgreSQL), credentials, configuration files (config.yaml), audit reports, and custom user plugins (~/.ares/plugins/) are mathematically blacklisted from modification. Pre-flight Python AST verification and atomic file writes ensure zero risk of corruption.
ARES was designed for environments with the most stringent compliance and confidentiality requirements:
localStorage or sessionStorage.ares_refresh) with one-time rotation and automatic reuse revocation.X-ARES-CSRF headers matched against cryptographically secure cookie tokens.ARES enforces strict RBAC permissions across all API endpoints, background jobs, and UI surfaces:
| Role | API Value | Operational Scope | Administrative Authority |
|---|---|---|---|
| Team Lead | team_lead | Complete platform authority: campaign creation/deletion, user provisioning, security audits, high-noise module overrides. | Full System Admin |
| Operator | operator | Day-to-day operations: execute authorized modules, review findings, explore attack graph, generate reports. Cannot register users. | Operational Tier |
| Recon | recon | Read-heavy reconnaissance: execute safe discovery and network fingerprinting modules. Execution of disruptive modules is blocked. | Read-Heavy |
| Reporter | reporter | Stakeholder review: read-only access to campaign analytics, findings, attack graphs, and generated deliverables. No execution rights. | Read-Only Audit |
row = await db.resolve_access_token_principal(...)). Tampered JWT claims are mathematically discarded.team_lead via POST /auth/register (guarded by require_team_lead()) or automatically mapped from enterprise Identity Providers during SP-initiated SAML/OIDC SSO.PUT /users/{id} does not exist), eliminating horizontal and vertical privilege escalation vectors (e.g., recon escalating to team_lead or reporter running offensive modules).Security console provides a transparent inventory of all registered identities and active sessions for engagement accountability.ARES provides a production-grade Model Context Protocol (MCP) Gateway that enables modern AI coding assistants (Cursor IDE, Claude Desktop, Windsurf, VS Code Cline, Zed, Open-WebUI, LibreChat) to interact with the ARES purple-team offensive platform safely and under strict governance.

ARES MCP Two-Pane Split Terminal Monitor (OpenClaw style) with real-time tool telemetry, live scope inspection, and 1-key token authorization.
Unlike basic MCP servers that expose raw endpoints to LLMs without guardrails, ARES enforces strict Pre-Flight Scope Invariance (ScopeGuard), Anti-Prompt-Injection Taint Isolation, and Single-Use 60-second HMAC Confirmation Tokens before any live offensive action can execute.
For operators or developers connecting Cursor, Claude Desktop, or Windsurf to ARES:
Verify Subsystem Readiness (doctor):
Ensure all core subsystems (Protocol Engine, 9 Tools, 3 Resources, 3 Prompts, 62 Descriptors, Security Gates) report PASS:
.\mcp.bat doctor
1-Click AI Client Setup (No Manual JSON Editing): Automatically configure your preferred IDE with a single command:
# For Cursor IDE:
.\mcp.bat setup --client cursor
# For Claude Desktop:
.\mcp.bat setup --client claude
# For Windsurf:
.\mcp.bat setup --client windsurf
# For VS Code (Cline):
.\mcp.bat setup --client cline
This writes your active Python virtual environment path directly into the client config file (e.g. .cursor/mcp.json).
Reload Window in Cursor IDE:
Ctrl + Shift + P.Developer: Reload Window.Ctrl + ,) → Features → MCP Servers. The ares server will show a green dot (Connected).Launch the Live Two-Pane Monitor (Optional Companion Window): In a dedicated terminal window, run the OpenClaw-style two-pane monitor to watch real-time AI tool invocations, scope checks, and approve tokens:
.\mcp.bat monitor
ares_scope_check, ares_dry_run_module, ares_run_tool).A to approve a pending execution token, R to reject, C to clear stream, Q to quit.Issue Your First Command to the AI Agent:
Open Cursor Composer / Chat (Ctrl + I or Ctrl + L), and try this prompt:
"Check active campaign status, verify scope for target 10.0.1.50, and stage a dry-run of module ad.kerberoast."
For in-depth architecture, the 7 security invariants, CLI scriptability (--json), POSIX exit codes, and operational tool schemas, see ARES MCP Gateway & Product-Grade CLI Specification.
ARES provides a first-class, type-safe Python SDK (ares.sdk) to build custom adversary modules, simulate techniques in isolated test harnesses, and automate engagements programmatically:
BaseModule[P, R] & @ares_module)Declare validated parameter schemas with Pydantic v2 and write modules with full IDE autocomplete:
from ares.sdk import (
BaseModule, ExecutionContext, ModuleResult,
ModuleParams, param, SecretParam,
OpsecLevel, Severity, ares_module,
)
class KerberoastParams(ModuleParams):
dc: str = param("Target Domain Controller IP or FQDN", min_length=3)
domain: str = param("AD DNS domain name, e.g. CORP.LOCAL", min_length=3)
password: SecretParam = param("Domain user password", secret=True, required=False)
class CustomKerberoastModule(BaseModule[KerberoastParams, ModuleResult]):
MODULE_ID = "custom.ad.kerberoast"
MODULE_NAME = "Custom Kerberoasting"
MODULE_CATEGORY = "ad"
OPSEC_LEVEL = OpsecLevel.LOW
MITRE_TECHNIQUES = ["T1558.003"]
PARAMS_MODEL = KerberoastParams
async def execute(self, ctx: ExecutionContext[KerberoastParams]) -> ModuleResult:
# ctx.params provides full static typing and runtime validation
await self.before_request(ctx.params.dc)
# Emit findings using fluent context helpers
finding = ctx.emit_finding(
title=f"Kerberoastable SPN Captured on {ctx.params.dc}",
severity=Severity.HIGH,
mitre_technique="T1558.003",
)
return ModuleResult(status="success", findings=[finding], module_id=self.MODULE_ID)
ModuleTestHarness)Unit test custom techniques locally with mock scope guards, synthetic credential vaults, and fluent assertion matchers:
from ares.sdk import ModuleTestHarness, Severity
async def test_module():
harness = ModuleTestHarness(CustomKerberoastModule)
result = await harness.simulate(params={"dc": "10.0.0.10", "domain": "LAB.LOCAL"})
result.assert_success()
result.assert_finding(severity=Severity.HIGH, mitre="T1558.003")
AresClient)Automate engagements, dispatch modules, and stream real-time WebSocket telemetry via Python scripts or CI/CD pipelines:
from ares.sdk import AresClient
async with AresClient(base_url="http://127.0.0.1:8080", api_key="ares_key_...") as ares:
campaign = await ares.campaigns.create(name="Op-Titan", scope=["10.0.0.0/24"])
job = await ares.modules.run("ad.kerberoast", target="dc01.corp.local", campaign_id=campaign["id"])
findings = await ares.campaigns.findings(campaign["id"])
See docs/module_sdk.md and docs/module-development.md for full developer documentation, architecture specifications, and examples.
Comprehensive documentation is available in the docs/ directory:
If ARES has accelerated your security assessments, helped protect your enterprise infrastructure, or advanced your offensive security research, consider sponsoring the project to fund continuous feature development, threat research, and lab infrastructure:
Your support helps keep ARES open-source, robust, and continuously updated against the latest adversary tradecraft.
[!IMPORTANT] ARES is a dual-use software framework designed exclusively for authorized cybersecurity research, internal enterprise resilience validation, and professional red-team engagements with explicit written permission.
To report security vulnerabilities in ARES, please follow our Security Policy.
ARES is distributed under the open-source MIT License.
ARES - Modern Red Team Engagement & Continuous Security Validation System.
Continuous Security Validation. Zero Collateral Risk.
121 followers · starred Sep 2026
Python
92.7%
TypeScript
6.5%