# Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No CVE/Active Exploitation

> Nebula is an open-source, LLM-integrated penetration testing CLI tool from BerylliumSec that wraps OpenAI, Llama-3.1-8B-Instruct, Mistral-7B-Instruct, and DeepSeek-R1-Distill-Llama-8B models around Nmap, Metasploit, CrackMapExec, and OWASP ZAP to automate recon, exploit suggestion, and engagement documentation. This record tracks Nebula as a dual-use offensive-automation tool for defender awareness — it is not a vulnerability, exploit, or confirmed malicious campaign, and carries no CVE/CVSS.

- **Published:** 2026-07-05T00:00:00Z
- **Last reviewed:** 2026-07-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1109
- **ID:** TL-2026-1109
- **Severity:** INFO
- **Category:** THREAT_INTEL
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Nebula is an open-source, AI-integrated penetration testing CLI tool developed by BerylliumSec (github.com/berylliumsec/nebula), distributed via PyPI as the 'nebula-ai' package. Dated PyPI release history shows the 1.0.9 beta line already active by 2024-01-18 (version 1.0.9b37) and continuing through 2024-03-20 (version 1.0.9b39), with the tool later rewritten onto the 2.0 beta line by 2025-02-04 (version 2.0.0b4). It wraps large language models — OpenAI's API-accessible models, Meta's Llama-3.1-8B-Instruct, Mistral AI's Mistral-7B-Instruct-v0.2, and DeepSeek-R1-Distill-Llama-8B — around a pentester's terminal workflow, running local inference through Ollama (CPU/GPU capable) or cloud inference via an OPENAI_API_KEY environment variable. Minimum system requirements are 16GB RAM and Python 3.10-3.13.9, with Docker deployment available using X11 forwarding for GUI features.

Nebula does not replace existing offensive tooling; it 'works alongside any CLI-invokable security utility,' with documented integrations for Nmap, Metasploit, CrackMapExec, and OWASP ZAP. Users toggle between AI and Terminal modes (or prefix commands with '!') to get AI-powered internet-search-augmented context, real-time exploitation suggestions derived from parsing terminal tool output, automated note-taking and finding categorization (independently observed by Ostorlab to map findings to CWE and NIST standards), built-in screenshot capture/annotation, and a status feed panel refreshing every five minutes. Nebula Pro, a commercial tier built on the open-source Nebula 2.0 codebase, adds an 'Autonomous Mode' that charts and chains multi-tool attack paths with human oversight, plus a code-analysis capability and multi-analyst collaboration with audit trails. BerylliumSec separately publishes the Deep Application Profiler (DAP), a neural-network- and vector-database-backed malware analysis web service/API (listed on Microsoft AppSource) aimed at zero-day detection in unmanaged-code executables up to roughly 0.5 MB, and a related terminal assistant called 'neutron' (github.com/berylliumsec/neutron).

This is a TOOL-RELEASE TRACKING record, not a vulnerability, exploit, or active campaign: there is no associated CVE, CVSS score, confirmed malicious deployment, or threat-actor attribution. It is documented here because Nebula is explicitly dual-use — the same LLM-driven reconnaissance, vulnerability-scanning, exploit-suggestion, credential-attack (via CrackMapExec), and lateral-movement (via CrackMapExec/Metasploit) automation that benefits authorized pentesters could, in principle, be adopted by an intrusion actor to accelerate equivalent stages of an unauthorized attack. Independent reviews (Darknet.org.uk, Ostorlab, Starlog, Spark42.tech) consistently describe Nebula as an AI-assisted terminal assistant that keeps a human in the loop by default (autonomous multi-step chaining is opt-in and Pro-only) and caution that LLM-generated exploit suggestions can be confidently wrong — citing non-existent CVEs, syntactically broken payloads, or OS-mismatched privilege-escalation techniques — so any AI-suggested exploit should be treated as an unverified hypothesis requiring validation.

Defensive relevance: SOC/blue teams should be able to recognize Nebula's footprint — the 'nebula-ai' PyPI package, its default '~/.local/share/nebula/logs' log path, Ollama model-pull commands (e.g., 'ollama pull mistral'), and OPENAI_API_KEY usage — to distinguish authorized red-team/pentest engagement activity from potential unauthorized use of the same tool, and to correlate Nebula-driven Nmap/CrackMapExec/Metasploit/ZAP activity with existing detections built for those underlying utilities.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1592 Gather Victim Host Information
- T1596 Search Open Technical Databases
- T1588.002 Tool
- T1588.006 Vulnerabilities
- T1587.001 Malware
- T1190 Exploit Public-Facing Application
- T1059.006 Python
- T1068 Exploitation for Privilege Escalation
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1049 System Network Connections Discovery
- T1087 Account Discovery
- T1110 Brute Force
- T1003 OS Credential Dumping
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1113 Screen Capture

## Sources

- [New Nebula AI-Integrated Penetration Testing Tool Empowers Attackers to Uncover Weaknesses](https://cybersecuritynews.com/nebula-ai-penetration-testing/)
- [berylliumsec/nebula (GitHub repository)](https://github.com/berylliumsec/nebula)
- [berylliumsec/nebula_watcher (GitHub repository)](https://github.com/berylliumsec/nebula_watcher)
- [berylliumsec/neutron (GitHub repository)](https://github.com/berylliumsec/neutron)
- [Nebula – AI-Powered Penetration Testing Assistant (PyPI project page)](https://pypi.org/project/nebula-ai/)
- [Nebula – Autonomous AI Pentesting Tool](https://www.darknet.org.uk/2025/04/nebula-autonomous-ai-pentesting-tool/)
- [Top 10 Open-Source AI Agent Penetration Testing Projects](https://blog.spark42.tech/top-10-open-source-ai-agent-penetration-testing-projects/)
- [8 Open-Source AI Pentest Tools for Security Teams in 2026](https://blog.ostorlab.co/8-open-source-ai-pentest-tools-2026.html)
- [Nebula: The AI-Powered Pentesting Assistant That Learns Your Workflow](https://starlog.is/articles/cybersecurity/berylliumsec-nebula/)
- [AI-Powered Penetration Testing: Nebula in Focus and How It Stacks Up Against the Rest](https://www.berylliumsec.com/blog/ai-powered-penetration-testing)
- [Deep Application Profiler (DAP) — Microsoft AppSource listing](https://appsource.microsoft.com/en-gb/product/web-apps/beryllium_security.berylliumsec-dap)
- [nebula-ai 1.0.9b37 (PyPI release history)](https://pypi.org/project/nebula-ai/1.0.9b37/)
- [nebula-ai 1.0.9b39 (PyPI release history)](https://pypi.org/project/nebula-ai/1.0.9b39/)
- [nebula-ai — PyPI Package Security Analysis (Socket.dev)](https://socket.dev/pypi/package/nebula-ai)
- [neutron-ai — PyPI Package Security Analysis (Socket.dev)](https://socket.dev/pypi/package/neutron-ai)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1109
