Threat reportThreat IntelligenceTL-2026-1109

Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No CVE/Active Exploitation

TRACKING

Nebula — AI-Integrated Open-Source Penetration Testing Tool (TL-2026-1109), also tracked as Nebula AI, is a info-severity tracked intrusion set, first published 2026-07-05. It has no confirmed attribution, affects BerylliumSec Nebula (nebula-ai), maps to 18 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
INFOAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1109

Threat ID
TL-2026-1109
Also known as
Nebula AI, nebula-ai, BerylliumSec Nebula
Severity
INFO
Status
TRACKING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
23

Malware and tooling in Nebula — AI-Integrated Open-Source Penetration Testing Tool

Malware and tooling: CrackMapExec - S0488, Deep Application Profiler (DAP), DeepSeek-R1-Distill-Llama-8B, Llama-3.1-8B-Instruct, Mistral-7B-Instruct-v0.2, Nebula, Nebula Pro, Nmap, OWASP ZAP, Ollama, metasploit

How Nebula — AI-Integrated Open-Source Penetration Testing Tool works

Nebula is an open-source, LLM-integrated penetration testing CLI tool from BerylliumSec that wraps OpenAI, Llama-3.1-8B-Instruct, Mistral-7B-Instruct, and DeepSeek-R1-Distill-Llama-8B models around Nmap, Metasploit, CrackMapExec, and OWASP ZAP to automate recon, exploit suggestion, and engagement documentation. This record tracks Nebula as a dual-use offensive-automation tool for defender awareness — it is not a vulnerability, exploit, or confirmed malicious campaign, and carries no CVE/CVSS.

Nebula is an open-source, AI-integrated penetration testing CLI tool developed by BerylliumSec (github.com/berylliumsec/nebula), distributed via PyPI as the 'nebula-ai' package. Dated PyPI release history shows the 1.0.9 beta line already active by 2024-01-18 (version 1.0.9b37) and continuing through 2024-03-20 (version 1.0.9b39), with the tool later rewritten onto the 2.0 beta line by 2025-02-04 (version 2.0.0b4). It wraps large language models — OpenAI's API-accessible models, Meta's Llama-3.1-8B-Instruct, Mistral AI's Mistral-7B-Instruct-v0.2, and DeepSeek-R1-Distill-Llama-8B — around a pentester's terminal workflow, running local inference through Ollama (CPU/GPU capable) or cloud inference via an OPENAI_API_KEY environment variable. Minimum system requirements are 16GB RAM and Python 3.10-3.13.9, with Docker deployment available using X11 forwarding for GUI features.

Nebula does not replace existing offensive tooling; it 'works alongside any CLI-invokable security utility,' with documented integrations for Nmap, Metasploit, CrackMapExec, and OWASP ZAP. Users toggle between AI and Terminal modes (or prefix commands with '!') to get AI-powered internet-search-augmented context, real-time exploitation suggestions derived from parsing terminal tool output, automated note-taking and finding categorization (independently observed by Ostorlab to map findings to CWE and NIST standards), built-in screenshot capture/annotation, and a status feed panel refreshing every five minutes. Nebula Pro, a commercial tier built on the open-source Nebula 2.0 codebase, adds an 'Autonomous Mode' that charts and chains multi-tool attack paths with human oversight, plus a code-analysis capability and multi-analyst collaboration with audit trails. BerylliumSec separately publishes the Deep Application Profiler (DAP), a neural-network- and vector-database-backed malware analysis web service/API (listed on Microsoft AppSource) aimed at zero-day detection in unmanaged-code executables up to roughly 0.5 MB, and a related terminal assistant called 'neutron' (github.com/berylliumsec/neutron).

This is a TOOL-RELEASE TRACKING record, not a vulnerability, exploit, or active campaign: there is no associated CVE, CVSS score, confirmed malicious deployment, or threat-actor attribution. It is documented here because Nebula is explicitly dual-use — the same LLM-driven reconnaissance, vulnerability-scanning, exploit-suggestion, credential-attack (via CrackMapExec), and lateral-movement (via CrackMapExec/Metasploit) automation that benefits authorized pentesters could, in principle, be adopted by an intrusion actor to accelerate equivalent stages of an unauthorized attack. Independent reviews (Darknet.org.uk, Ostorlab, Starlog, Spark42.tech) consistently describe Nebula as an AI-assisted terminal assistant that keeps a human in the loop by default (autonomous multi-step chaining is opt-in and Pro-only) and caution that LLM-generated exploit suggestions can be confidently wrong — citing non-existent CVEs, syntactically broken payloads, or OS-mismatched privilege-escalation techniques — so any AI-suggested exploit should be treated as an unverified hypothesis requiring validation.

Defensive relevance: SOC/blue teams should be able to recognize Nebula's footprint — the 'nebula-ai' PyPI package, its default '~/.local/share/nebula/logs' log path, Ollama model-pull commands (e.g., 'ollama pull mistral'), and OPENAI_API_KEY usage — to distinguish authorized red-team/pentest engagement activity from potential unauthorized use of the same tool, and to correlate Nebula-driven Nmap/CrackMapExec/Metasploit/ZAP activity with existing detections built for those underlying utilities.

MITRE ATT&CK techniques used in TL-2026-1109

Credential Access

T1003 OS Credential Dumping; T1110 Brute Force

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1049 System Network Connections Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Execution

T1059.006 Python

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Collection

T1113 Screen Capture

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1587.001 Malware; T1588.002 Tool; T1588.006 Vulnerabilities

Reconnaissance

T1592 Gather Victim Host Information; T1595.002 Vulnerability Scanning; T1596 Search Open Technical Databases

Affected products and versions in Nebula — AI-Integrated Open-Source Penetration Testing Tool

  • BerylliumSec — Nebula (nebula-ai)
    Vulnerable versions: 2.0.0b4 (2025-02-04 PyPI release); 2.0 open-source line
  • BerylliumSec — Nebula Pro
    Vulnerable versions: Preview/commercial tier adding Autonomous Mode and Code Analysis
  • BerylliumSec — Deep Application Profiler (DAP)
    Vulnerable versions: Web service / API, Microsoft AppSource listing

Remediation for Nebula — AI-Integrated Open-Source Penetration Testing Tool

Immediate actions

  • Inventory hosts for the 'nebula-ai' PyPI package, Ollama model pulls, and the default '~/.local/share/nebula/logs' log directory to identify unsanctioned Nebula installations
  • Restrict and monitor outbound calls authenticated via OPENAI_API_KEY from non-approved pentest jump hosts

Longer-term hardening

  • Maintain an approved-tool allowlist for internal red-team/purple-team engagements and require sign-off before AI-assisted offensive tooling (Nebula, Nebula Pro, or similar) is used against production systems
  • Extend existing detections for Nmap, Metasploit, CrackMapExec, and OWASP ZAP to correlate with AI-assistant wrapper activity, since Nebula automates invocation of these tools rather than replacing them
  • Treat AI-generated exploit or privilege-escalation suggestions from any LLM-assisted tool as an unverified hypothesis requiring manual validation before execution, given documented hallucination risk

Timeline of Nebula — AI-Integrated Open-Source Penetration Testing Tool

  • Earliest confirmed dated PyPI release of the 'nebula-ai' package, version 1.0.9b37, showing the 1.0.9 beta line of Nebula was already under active development in early 2024.
  • Nebula version 1.0.9b39 is published to PyPI, continuing the 1.0.9 beta release line prior to the later 2.0 rewrite.
  • Nebula version 2.0.0b4 is published to PyPI as the 'nebula-ai' package, reflecting the jump to the 2.0 beta line and active continued beta-stage development.
  • Darknet.org.uk publishes 'Nebula – Autonomous AI Pentesting Tool,' describing Nebula's integrations with Nmap, CrackMapExec, and OWASP ZAP and noting it is an AI-assisted terminal tool rather than a fully autonomous pentester (exact publish day approximate, sourced to April 2025).
  • Spark42.tech publishes 'Top 10 Open-Source AI Agent Penetration Testing Projects,' listing Nebula among leading open-source AI pentesting agent projects.
  • Ostorlab publishes '8 Open-Source AI Pentest Tools for Security Teams in 2026,' benchmarking Nebula and peer tools against a banking web application and noting Nebula's AI-assisted findings map to CWE and NIST standards.
  • Starlog publishes 'Nebula: The AI-Powered Pentesting Assistant That Learns Your Workflow,' profiling Nebula's workflow-adaptive AI assistant features.
  • Cyber Security News publishes 'New Nebula AI-Integrated Penetration Testing Tool Empowers Attackers to Uncover Weaknesses' by Guru Baran, the article that triggered this tool-tracking record; it confirms LLM backends and capabilities with no associated CVE or exploitation activity.
  • BerylliumSec publishes its own comparison blog post, 'AI-Powered Penetration Testing: Nebula in Focus and How It Stacks Up Against the Rest,' positioning Nebula against competing open-source AI pentesting agents.

Sources cited for Nebula — AI-Integrated Open-Source Penetration Testing Tool

Detection coverage for TL-2026-1109

As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1109 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats