Suijin is a dual-mode autonomous security platform. The Red Team chains reconnaissance → vulnerability discovery → exploitation → escalation → flag capture → reporting over a LangGraph state machine, while the Blue Team monitors live HTTP traffic, detects attacks, and responds with deception, blocking, and source patching. Both modes share one toolkit, one knowledge base, and one knowledge graph. Intended for authorized security testing, education, and research only.
The Red Team
A LangGraph-driven pipeline runs recon, vuln discovery, exploit, escalation, flag capture, and report generation autonomously. It spawns parallel subagents (up to 3 concurrent) for multi-vector attacks, coordinated by a zero-cost LLM supervisor that watches for loops, missed flags, and stalled progress every 5 iterations — no API cost. A persistent knowledge graph is shared across all agents, and every engagement produces Markdown reports with Mermaid attack-chain diagrams. A live command box during runs supports /state, /note, /kb, /cost, /approvals, /scope, /audit, /sessions, /report, /pause, and /panic.
The Blue Team SOC
Live traffic flows through 18 regex-based attack pattern detectors — SQLi, XSS, SSRF, CMDi, XXE, JWT, SSTI, deserialization, LDAP, NoSQL, scanner user-agents, mass assignment, auth bypass, brute force, file inclusion, and GraphQL. Per-endpoint AI subagents analyze handler code in real time. When an attack is detected, the decision engine deploys layered responses: tarpit (real, measurable delays — 0.018s normal to 8.0s at threat score 10), network blocking via pfctl/iptables, source code patching directly on the filesystem, and honeypots (decoy admin users, canary API keys, phantom debug tokens). The first 25 requests build baseline profiles before the AI activates.
Built-in labs
Eight deliberately vulnerable Flask apps ship in the box, so nobody learns on real targets:
- cloud_iam_lab (:5900) — AWS IAM misconfigurations
- api_only_lab (:5901) — REST + GraphQL, BOLA, mass assignment
- oauth_lab (:5902) — OAuth 2.0 / OIDC misconfigurations
- log4shell_lab (:5903) — Log4j RCE
- wordpress_lab (:5904) — WordPress + vulnerable plugins
- ad_lab (:5905) — simulated AD DC, Kerberos, LDAP, SMB
- blue_target (:5906) — 25 endpoints, 15+ vuln classes
- devops_dashboard (:5700) — hard RCE, multi-step chain required
A modular security OS
Suijin is rebuilt as a modular operating system for security automation: a kernel of 12 stdlib-only subsystems (contracts, context, events, registry, controller, jobs, vfs, security, config, health, journal, errors), a Core tier that cannot be disabled, a Recommended tier of disableable modules, and an Installed tier of community modules discovered on every boot. Modules are one folder — plugin.json plus register(ctx), start(ctx), stop(ctx) — managed through a Textual TUI.
Extensibility in four rungs
- Skill — drop a markdown file, it boots into the agent's prompt. 30 seconds.
- Addon — plain functions, auto-registered as agent tools. 2 minutes.
- Pack — scaffolded tools + skill doc + kernel unit. 5 minutes.
- Module — full lifecycle with dependencies, versioning, overrides.
The offline knowledge base
suijin pull kb downloads and indexes HackTricks, GTFOBins, PayloadsAllTheThings, LOLBAS,
OWASP Cheat Sheets, and SecLists (~300 MB) into a local sqlite3 store with FTS5 and BM25-ranked search.
KB-powered tools — suggest_exploit, find_wordlist, extract_payloads, kb_stats, mine_failures,
anonymize_report — all work offline, with no API key.
Governance & ops
A policy engine blocks dangerous patterns before the agent hits enter, scope controls enforce Burp-style target boundaries, and HITL approvals gate destructive actions. Credentials live in a PBKDF2-HMAC-SHA256 encrypted vault, provider failover rolls to the next LLM provider on hard failure, and cost guardrails enforce alert, budget, and hard-cap limits in USD.
curl -fsSL https://raw.githubusercontent.com/0xwi11iam/Suijin/main/install.sh | bash