Corvus Technology · Architecture Reference
A target-agnostic, human-in-the-loop, multi-agent red-team framework driven by a local LLM, executing real offensive tooling under full operator control. Architecture reference.
The engagement is data (a playbook). Three local-LLM roles plan and adapt; a single deterministic gate enforces scope, risk tiers, approvals and audit on every action. Techniques run real offensive tooling through a config-driven toolpack, network and Active-Directory tooling, a web-application tier, pivoting/tunneling, and live HTTP against AI targets. The same engine drives a full Active-Directory forest compromise, a web-application foothold that pivots into the internal network, an AI-application breach, and an AI-model robustness assessment, switched by which playbook is loaded.
Loop: Planner chooses the next eligible technique (recon/discovery run exhaustively first; the kill chain is selective) → Operator fills its args from state → gate (scope → risk tier → human approval if Tier ≥ 2 → audit) → toolpack runs the real tool → its redacted output lands in the ledger → Analyst derives insights + a recommendation. Every LLM role reads the ledger, so choices adapt to what actually happened. Repeats until the success condition, a stop, or an abort.
| Component | Role |
|---|---|
| State machine | drives the supervisor → execute → analyst loop with a checkpointer; enforces exhaustive discovery before the selective kill chain |
| The gate | the single choke point every action passes through (scope → tier → human approval → audit → execute) |
| Scope / risk / audit guardrails | deterministic controls: a hard allowlist (per-host, multi-target aware), the risk-tier classifier, and an append-only audit sink with redacted output |
| Tool runner | config-driven executor: substitutes synthesized args into a declared command, runs it live (or replays a fixture), parses output into loot, and redacts secrets in stored output |
| Eligibility engine | findings-driven predicates, techniques become eligible only from what recon actually found |
| Engagement state | merges loot and maintains the ledger digest fed to every LLM role |
| Planner role | chooses the next eligible technique (local LLM, with deterministic fallback) |
| Operator role | synthesizes a technique's tool args from discovered state (including multi-host enumeration); the LLM cannot override a scope-pinned target |
| Analyst role | derives attack-path insights, ranks eligible techniques, and summarizes state |
| Playbook loader | loads and validates a playbook: authorization gate, phase ordering, tier resolution, and success/coverage criteria |
| Tool manifest | each tool declared once as a command template, a capture pattern, and a replay fixture (held internally, shared under NDA) |
| Least-privilege executors | per-call, sandboxed processes that dispatch the declared tools |
| Tier | Meaning | Gate |
|---|---|---|
| T0 | read-only recon / enumeration | auto |
| T1 | low-impact / contained mutation | notify |
| T2 | state-changing exploitation | approve |
| T3 | destructive / high blast radius | approve + typed confirm |
Tiers are set per tool and overridable per playbook; a human-only override forces a step to a confirm gate for the highest-impact actions (e.g. an agentic AI tool action, or a domain-dominance step).
| Mechanism | What it does |
|---|---|
| Findings-driven eligibility | each technique's eligibility rule gates it on live state (e.g. a domain controller was discovered, credentials are available, a vulnerable certificate template was found); only applicable branches fire. |
| Exhaustive discovery | every recon/discovery technique runs first, deterministically, no vector is skipped, before the LLM-selective kill chain, which may stop early once a foothold works. |
| The ledger | each action's redacted output + outcome accumulates in state; the planner/operator/analyst read it, so they adapt to real signals (e.g. an access-denied result → pivot to another enumeration route) instead of stalling. |
| Multi-host sweep | enumeration targets an explicit host list or CIDR; one step iterates every in-scope host. Authenticated steps stay pinned to a single discovered host. |
| Operator synthesis | tool args (targets, users, payloads) are synthesized from discovered state; a scope-pinned value cannot be overridden by a hallucinating LLM. |
| Playbook | Kind | Execution |
|---|---|---|
| full-ad | Active-Directory forest → domain/forest compromise: recon, poison/relay, credential access, certificate-services abuse, delegation, ACL abuse, database access, trusts, domain dominance | real tools (live / sim) |
| web-app | Web-application foothold: unauth recon → OWASP Top 10 → credential recovery → CMS/plugin RCE → local privesc → pivot into the internal network → hands off to the AD chain | real tools + HTTP (live / sim) |
| ai-surface-redteam | AI model/agent robustness, OWASP-LLM / MITRE ATLAS battery | real HTTP against the target agent (live / sim) |
| ai-dmz | AI-to-AD pivot: retrieval poisoning → web exploitation → internal lateral movement | real HTTP + tools (live / sim) |
Playbooks are loaded as data and keyed by name; adding or removing one is a configuration change, not a code change. Scope (the target network, hosts and endpoints) lives in each playbook's scope block, so the same technique set retargets to any authorized environment.