arXiv:2510.03610cs.CRcs.AI2025-10被引 1

用AI代理自动化渗透测试,灵活组合多任务流程。

PentestMCP: A Toolkit for Agentic Penetration Testing

  • 基于MCP架构构建可远程调用的渗透测试代理
  • 支持扫描、指纹识别、漏洞利用等完整渗透流程
  • 适合安全研究员快速搭建定制化自动化测试系统

代理式AI正重塑安全领域,通过自动化人工执行的多项任务。早期的代理方法采用单一架构,而现在的模型-上下文-协议(Model-Context-Protocol)已实现远程过程调用(RPC)范式,使多功能代理的灵活构建与组合成为可能。本文介绍PentestMCP,一个支持代理式渗透测试的MCP服务器组件库。该工具涵盖网络扫描、资源枚举、服务指纹识别、漏洞扫描、漏洞利用及后渗透等常见渗透测试任务,使开发者能够自定义多代理工作流,完成自动化渗透测试。

原文摘要 · Abstract (English)

Agentic AI is transforming security by automating many tasks being performed manually. While initial agentic approaches employed a monolithic architecture, the Model-Context-Protocol has now enabled a remote-procedure call (RPC) paradigm to agentic applications, allowing for the flexible construction and composition of multi-function agents. This paper describes PentestMCP, a library of MCP server implementations that support agentic penetration testing. By supporting common penetration testing tasks such as network scanning, resource enumeration, service fingerprinting, vulnerability scanning, exploitation, and post-exploitation, PentestMCP allows a developer to customize multi-agent workflows for performing penetration tests.

渗透测试AI代理自动化安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。