DrowAI

Overview

AI-assisted red team work, organized from objective to report

DrowAI helps an operator run scoped security tasks with a guided agent, isolated Kali execution, structured evidence, and engagement-ready reporting in one workspace.

Workflow

How DrowAI organizes agentic security work

Engagement

One mission-level security workspace

An engagement represents a full authorized red-team or pentest effort, keeping scope, targets, tasks, evidence, and outcomes together.

Task

Focused work inside the engagement

Tasks break a larger engagement into specific objectives, so the operator and agent can work through separate lines of investigation without losing context.

Knowledge

Persistent security knowledge

As the agent works, DrowAI turns collected activity into durable records for assets, services, evidence, findings, relationships, and reporting.

Knowledge workspace

Every agent action becomes structured security knowledge

DrowAI keeps findings, assets, services, evidence, and network territory connected in one inspectable workspace, so an operator can move from raw activity to a defensible security picture.

Territory

DrowAI territory workspace showing a network topology map with selected asset details

Topology and relationship map

Network territory, selected asset context, and linked finding state.

01

Authorized Engagement

Scope, targets, and rules.

02

Operator Objective

A focused goal to pursue.

03

Red Team Agent

Plans, reasons, and guides.

04

Controlled Kali Container

Isolated tool execution.

05

Structured Knowledge

Linked assets and evidence.

06

Agentic Report

Report-ready findings.

Workflow From scoped engagement to report-ready output

Product workflow

A guided loop from objective to report

Human-in-the-loop control
Work runs inside a controlled Kali container
Evidence becomes report-ready knowledge

Agent capabilities

LLM-visible capabilities in the MVP

The runtime includes more than 100 Kali tools, but only the capabilities listed here are currently fully integrated and available to the LLM.

Filesystem

Workspace file operations

Read, search, create, edit, copy, move, and remove files and directories inside the task workspace.

Reconnaissance

Host discovery and network scanning

Use fping, Nmap, and bounded network checks to identify reachable hosts, open services, and network details.

Web testing

HTTP requests and content discovery

Make HTTP requests, download web content, and use FFUF to discover paths and web application content.

Exploitation

Metasploit module workflows

Search, inspect, and run supported Metasploit modules within the task's authorized scope.

Service access

FTP and SSH access checks

Log into supplied FTP and SSH services, list remote files, and download single files for review.

Traffic analysis

Packet capture inspection

Use TShark to inspect packet captures and identify relevant network traffic for task review.

Image preview