Threat reportThreat IntelligenceTL-2026-1109
Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No CVE/Active Exploitation
Nebula — AI-Integrated Open-Source Penetration Testing Tool (TL-2026-1109), also tracked as Nebula AI, is a info-severity tracked intrusion set, first published 2026-07-05. It has no confirmed attribution, affects BerylliumSec Nebula (nebula-ai), maps to 18 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- INFOAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-1109
- Threat ID
- TL-2026-1109
- Also known as
- Nebula AI, nebula-ai, BerylliumSec Nebula
- Severity
- INFO
- Status
- TRACKING
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Nebula — AI-Integrated Open-Source Penetration Testing Tool
Malware and tooling: CrackMapExec - S0488, Deep Application Profiler (DAP), DeepSeek-R1-Distill-Llama-8B, Llama-3.1-8B-Instruct, Mistral-7B-Instruct-v0.2, Nebula, Nebula Pro, Nmap, OWASP ZAP, Ollama, metasploit
How Nebula — AI-Integrated Open-Source Penetration Testing Tool works
Nebula is an open-source, LLM-integrated penetration testing CLI tool from BerylliumSec that wraps OpenAI, Llama-3.1-8B-Instruct, Mistral-7B-Instruct, and DeepSeek-R1-Distill-Llama-8B models around Nmap, Metasploit, CrackMapExec, and OWASP ZAP to automate recon, exploit suggestion, and engagement documentation. This record tracks Nebula as a dual-use offensive-automation tool for defender awareness — it is not a vulnerability, exploit, or confirmed malicious campaign, and carries no CVE/CVSS.
Nebula is an open-source, AI-integrated penetration testing CLI tool developed by BerylliumSec (github.com/berylliumsec/nebula), distributed via PyPI as the 'nebula-ai' package. Dated PyPI release history shows the 1.0.9 beta line already active by 2024-01-18 (version 1.0.9b37) and continuing through 2024-03-20 (version 1.0.9b39), with the tool later rewritten onto the 2.0 beta line by 2025-02-04 (version 2.0.0b4). It wraps large language models — OpenAI's API-accessible models, Meta's Llama-3.1-8B-Instruct, Mistral AI's Mistral-7B-Instruct-v0.2, and DeepSeek-R1-Distill-Llama-8B — around a pentester's terminal workflow, running local inference through Ollama (CPU/GPU capable) or cloud inference via an OPENAI_API_KEY environment variable. Minimum system requirements are 16GB RAM and Python 3.10-3.13.9, with Docker deployment available using X11 forwarding for GUI features.
Nebula does not replace existing offensive tooling; it 'works alongside any CLI-invokable security utility,' with documented integrations for Nmap, Metasploit, CrackMapExec, and OWASP ZAP. Users toggle between AI and Terminal modes (or prefix commands with '!') to get AI-powered internet-search-augmented context, real-time exploitation suggestions derived from parsing terminal tool output, automated note-taking and finding categorization (independently observed by Ostorlab to map findings to CWE and NIST standards), built-in screenshot capture/annotation, and a status feed panel refreshing every five minutes. Nebula Pro, a commercial tier built on the open-source Nebula 2.0 codebase, adds an 'Autonomous Mode' that charts and chains multi-tool attack paths with human oversight, plus a code-analysis capability and multi-analyst collaboration with audit trails. BerylliumSec separately publishes the Deep Application Profiler (DAP), a neural-network- and vector-database-backed malware analysis web service/API (listed on Microsoft AppSource) aimed at zero-day detection in unmanaged-code executables up to roughly 0.5 MB, and a related terminal assistant called 'neutron' (github.com/berylliumsec/neutron).
This is a TOOL-RELEASE TRACKING record, not a vulnerability, exploit, or active campaign: there is no associated CVE, CVSS score, confirmed malicious deployment, or threat-actor attribution. It is documented here because Nebula is explicitly dual-use — the same LLM-driven reconnaissance, vulnerability-scanning, exploit-suggestion, credential-attack (via CrackMapExec), and lateral-movement (via CrackMapExec/Metasploit) automation that benefits authorized pentesters could, in principle, be adopted by an intrusion actor to accelerate equivalent stages of an unauthorized attack. Independent reviews (Darknet.org.uk, Ostorlab, Starlog, Spark42.tech) consistently describe Nebula as an AI-assisted terminal assistant that keeps a human in the loop by default (autonomous multi-step chaining is opt-in and Pro-only) and caution that LLM-generated exploit suggestions can be confidently wrong — citing non-existent CVEs, syntactically broken payloads, or OS-mismatched privilege-escalation techniques — so any AI-suggested exploit should be treated as an unverified hypothesis requiring validation.
Defensive relevance: SOC/blue teams should be able to recognize Nebula's footprint — the 'nebula-ai' PyPI package, its default '~/.local/share/nebula/logs' log path, Ollama model-pull commands (e.g., 'ollama pull mistral'), and OPENAI_API_KEY usage — to distinguish authorized red-team/pentest engagement activity from potential unauthorized use of the same tool, and to correlate Nebula-driven Nmap/CrackMapExec/Metasploit/ZAP activity with existing detections built for those underlying utilities.
MITRE ATT&CK techniques used in TL-2026-1109
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1049 System Network Connections Discovery; T1087 Account Discovery
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Collection
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
T1587.001 Malware; T1588.002 Tool; T1588.006 Vulnerabilities
Reconnaissance
T1592 Gather Victim Host Information; T1595.002 Vulnerability Scanning; T1596 Search Open Technical Databases
Affected products and versions in Nebula — AI-Integrated Open-Source Penetration Testing Tool
- BerylliumSec — Nebula (nebula-ai)
Vulnerable versions: 2.0.0b4 (2025-02-04 PyPI release); 2.0 open-source line - BerylliumSec — Nebula Pro
Vulnerable versions: Preview/commercial tier adding Autonomous Mode and Code Analysis - BerylliumSec — Deep Application Profiler (DAP)
Vulnerable versions: Web service / API, Microsoft AppSource listing
Remediation for Nebula — AI-Integrated Open-Source Penetration Testing Tool
Immediate actions
- Inventory hosts for the 'nebula-ai' PyPI package, Ollama model pulls, and the default '~/.local/share/nebula/logs' log directory to identify unsanctioned Nebula installations
- Restrict and monitor outbound calls authenticated via OPENAI_API_KEY from non-approved pentest jump hosts
Longer-term hardening
- Maintain an approved-tool allowlist for internal red-team/purple-team engagements and require sign-off before AI-assisted offensive tooling (Nebula, Nebula Pro, or similar) is used against production systems
- Extend existing detections for Nmap, Metasploit, CrackMapExec, and OWASP ZAP to correlate with AI-assistant wrapper activity, since Nebula automates invocation of these tools rather than replacing them
- Treat AI-generated exploit or privilege-escalation suggestions from any LLM-assisted tool as an unverified hypothesis requiring manual validation before execution, given documented hallucination risk
Timeline of Nebula — AI-Integrated Open-Source Penetration Testing Tool
- Earliest confirmed dated PyPI release of the 'nebula-ai' package, version 1.0.9b37, showing the 1.0.9 beta line of Nebula was already under active development in early 2024.
- Nebula version 1.0.9b39 is published to PyPI, continuing the 1.0.9 beta release line prior to the later 2.0 rewrite.
- Nebula version 2.0.0b4 is published to PyPI as the 'nebula-ai' package, reflecting the jump to the 2.0 beta line and active continued beta-stage development.
- Darknet.org.uk publishes 'Nebula – Autonomous AI Pentesting Tool,' describing Nebula's integrations with Nmap, CrackMapExec, and OWASP ZAP and noting it is an AI-assisted terminal tool rather than a fully autonomous pentester (exact publish day approximate, sourced to April 2025).
- Spark42.tech publishes 'Top 10 Open-Source AI Agent Penetration Testing Projects,' listing Nebula among leading open-source AI pentesting agent projects.
- Ostorlab publishes '8 Open-Source AI Pentest Tools for Security Teams in 2026,' benchmarking Nebula and peer tools against a banking web application and noting Nebula's AI-assisted findings map to CWE and NIST standards.
- Starlog publishes 'Nebula: The AI-Powered Pentesting Assistant That Learns Your Workflow,' profiling Nebula's workflow-adaptive AI assistant features.
- Cyber Security News publishes 'New Nebula AI-Integrated Penetration Testing Tool Empowers Attackers to Uncover Weaknesses' by Guru Baran, the article that triggered this tool-tracking record; it confirms LLM backends and capabilities with no associated CVE or exploitation activity.
- BerylliumSec publishes its own comparison blog post, 'AI-Powered Penetration Testing: Nebula in Focus and How It Stacks Up Against the Rest,' positioning Nebula against competing open-source AI pentesting agents.
Sources cited for Nebula — AI-Integrated Open-Source Penetration Testing Tool
- New Nebula AI-Integrated Penetration Testing Tool Empowers Attackers to Uncover Weaknesses
- berylliumsec/nebula (GitHub repository)
- berylliumsec/nebula_watcher (GitHub repository)
- berylliumsec/neutron (GitHub repository)
- Nebula – AI-Powered Penetration Testing Assistant (PyPI project page)
- Nebula – Autonomous AI Pentesting Tool
- Top 10 Open-Source AI Agent Penetration Testing Projects
- 8 Open-Source AI Pentest Tools for Security Teams in 2026
- Nebula: The AI-Powered Pentesting Assistant That Learns Your Workflow
- AI-Powered Penetration Testing: Nebula in Focus and How It Stacks Up Against the Rest
- Deep Application Profiler (DAP) — Microsoft AppSource listing
- nebula-ai 1.0.9b37 (PyPI release history)
- nebula-ai 1.0.9b39 (PyPI release history)
- nebula-ai — PyPI Package Security Analysis (Socket.dev)
- neutron-ai — PyPI Package Security Analysis (Socket.dev)
Detection coverage for TL-2026-1109
As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1109 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.