@cyanheads/pentest-mcp-server
Provides WAF bypass payload templates specific to Akamai WAF, referencing public research for each WAF product variant.
Provides WAF bypass payload templates specific to Cloudflare WAF, referencing public research for each WAF product variant.
Provides WAF bypass payload templates specific to Fortinet FortiWeb WAF, referencing public research for each WAF product variant.
Provides WAF bypass payload templates specific to NGINX with ModSecurity, referencing public research for each WAF product variant.
Provides methodology and test cases aligned with the OWASP Testing Guide, including test case IDs in playbooks and technique mapping.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@cyanheads/pentest-mcp-serverguide for SQL injection testing"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Public Hosted Server: https://pentest.caseyjhand.com/mcp
Authorized use only. This server is designed for penetration testers, red teamers, CTF players, security researchers, and students working on systems they own or have explicit written authorization to test. Users are solely responsible for ensuring their testing is lawful and appropriately scoped. Unauthorized access to computer systems is illegal — this server does not and cannot enforce authorization on your behalf.
Dual-audience design. Every offensive technique is paired with detection indicators and mitigations. Blue teamers, developers, and anyone building detection coverage will find the methodology and ATT&CK data as useful as the red team workflows.
Overview
Offline penetration-testing methodology engine: MITRE ATT&CK techniques and threat groups, OWASP Testing Guide methodology, and annotated payload templates for authorized penetration testing, CTF, and security research. Generate a phased testing playbook, map techniques to a target profile, analyze HTTP responses for leakage, and generate or encode payload templates from any MCP client. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
Tools
Tool | Description |
| Step-by-step authorized-testing methodology playbook for a chosen attack vector, phase-filterable, with detection and mitigation per technique. |
| Analyzes raw HTTP response headers/body from authorized probing for leakage, fingerprinting, and misconfiguration. |
| Looks up a MITRE ATT&CK technique by ID or keyword, with detection data, mitigations, and procedure examples. |
| Looks up a MITRE ATT&CK threat group or software entry by ID or name, with aliases and technique usage. |
| Ranks ATT&CK techniques and OWASP test cases against a target profile (stack, services, auth type, OS). |
| Generates annotated payload templates for a vulnerability category and injection context, with optional WAF bypass variants and encoding. |
| Applies an ordered encoding chain to a payload string with decode-path tracing. |
Related MCP server: oscp-companion
Capability reference
pentest_guide tool
15 attack vectors via
vectorenum:auth_bypass,idor,ssrf,xss,sqli,xxe,path_traversal,cors,csrf,open_redirect,deserialization,race_condition,ssti,command_injection,jwt_attackOptional
target_context(stack,waf,recon_notes) narrows the playbook to stack-specific techniques and WAF-bypass-aware variantsphasefilter:all(default),recon,enumeration,exploitation, orpost_exploitationEvery technique carries
detectionandmitigation; response also includesowasp_references(WSTG IDs) andattack_technique_idsfor cross-referencingauthorized_use_reminderrendered as the first line of every responsenextToolSuggestionspre-filled with payload-generator and ATT&CK-lookup calls derived from the methodology context
pentest_analyze_response tool
Accepts
response_headers(≤20,000 chars),response_body(≤10,000 chars),status_code(100–599), and freeformcontext(≤2,000 chars) — at least one of headers or body is requiredDetects 10 finding categories (version disclosure, stack traces, internal paths, debug headers, technology fingerprints, auth patterns, CORS misconfiguration, missing security headers, interesting fields, error messages), each with
severity(info/low/medium/high)Each finding carries
detectionandremediation; results are ordered by severity descendingfingerprintsblock (server_software,framework,language,database,cloud_provider,other) ready for use as target context inpentest_guideorpentest_map_techniquesTyped
no_inputerror when neitherresponse_headersnorresponse_bodyis suppliednextToolSuggestionspre-filled from detected fingerprints and findings
pentest_lookup_technique tool
Accepts an exact ATT&CK ID (
T1190,T1059.001) or a keyword; ID lookup is exact, keyword falls back to best-match searchReturns tactics, platforms, description, detection (
summary,data_sources,indicators), mitigations, and procedure examples from public ATT&CK reportinginclude_subtechniques(defaulttrue) toggles sub-technique inclusionattack_versionechoes the embedded ATT&CK dataset version (e.g. "Enterprise v19.1") on every responseTyped
no_matcherror when the ID or keyword resolves to nothing
pentest_lookup_group tool
Accepts an exact ATT&CK group ID (
G0007) or software ID (S0002), or a name/keyword (APT28,Mimikatz)typediscriminatesgroup(intrusion set) fromsoftware(malware/tool);aliaseslists known alternate namestechniques_usedreturns up to 20 techniques with procedure-level context, each linking topentest_lookup_techniquebytechnique_iddescriptiontruncated to 800 charactersTyped
no_matcherror when the ID or name resolves to nothing
pentest_map_techniques tool
Profile inputs:
stack(array),services(array),auth_type(jwt/session_cookie/api_key/oauth2/basic_auth/ntlm/kerberos/none/unknown),os(linux/windows/macos/unknown) — at least one requiredRelevance scoring adds points for platform, stack, service, and auth-type matches; each result's
relevance_rationalelists exactly which criteria matchedlimitcapsranked_techniquesat 1–50 (default 15); enrichment (truncated,shown,cap) discloses when results were cappedEach ranked technique carries
detection_opportunity,mitigation_summary, and an optionalpentest_guide_vectorfor follow-upowasp_test_casesreturns up to 10 relevant OWASP Testing Guide test casesTyped
no_profileerror when no profile field is supplied
pentest_generate_payloads tool
14 payload categories (
xss,sqli,ssrf,xxe,path_traversal,ssti,command_injection,open_redirect,csrf,deserialization,jwt,ldap_injection,nosql_injection,http_header) × 16 injection contexts (html_attribute,html_body,js_string,js_template,js_script_block,url_parameter,url_path,sql_where,sql_integer,xml_element,xml_attribute,http_header,json_value,cookie_value,file_name,generic)waf_profile(cloudflare,aws_waf,modsecurity_crs,imperva,akamai,f5_bigip_asm,nginx_modsecurity,fortinet_fortiwaf,nonedefault,unknown) adds bypass variants referencing public research when setOptional
encodingchain applied to each returned template;countcaps results at 1–20 (default 5)Each payload carries
detection_signatureandmitigation;waf_bypass_notepresent only whenwaf_profileisn'tnoneTemplates are annotated placeholders, not live weaponized strings —
authorized_use_reminderrendered first in every response
pentest_encode tool
payloadstring up to 10,000 characters;chainis an ordered list of 1–6 encoding steps applied left to right10 encoding types:
url,double_url,html_entity,unicode,hex,base64,js_escape,null_byte,mixed_case,comment_breakintermediate_stepstraces the value after each chain step;explain(defaulttrue) addsdecode_pathandbypass_rationaledetection_noteon every response — how defenders detect encoded variantsPure deterministic transforms, no live probing; typed
encoding_errorwhen a step produces invalid output
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
Methodology-specific:
Fully offline at runtime — no external API calls, no credentials required; all data loaded at startup, zero I/O during request handling
MITRE ATT&CK Enterprise embedded at build time via
scripts/refresh-attack.tsand indexed in memory by ID/keyword; fails fast with an actionable error if the data file is missingOWASP Testing Guide methodology and payload template library curated as structured TypeScript modules, one per vector/category
WAF bypass variants keyed by WAF product and attack vector, referencing public research
All tools annotated
readOnlyHint: true,openWorldHint: false— deterministic output from a bounded embedded dataset
Agent-friendly output:
authorized_use_reminderrendered as the first line ofcontent[]on every guide/payload/encoding response — consistent framing regardless of which surface a client forwardsdetectionandmitigationfields required (non-optional) on every technique, finding, and payload — defenders always get usable context alongside offense techniqueattack_versionechoed on every ATT&CK-backed response so callers can reason about data vintagenextToolSuggestionspre-filled with arguments derived from the current context, reducing agent planning overhead
Build-time data step
The server embeds MITRE ATT&CK Enterprise data (~20 MB JSON) fetched by a one-time script into a gitignored path. Self-hosters and Docker builders must run this step before the server will start:
bun run scripts/refresh-attack.tsThis downloads the latest ATT&CK Enterprise JSON from the MITRE GitHub release endpoint, writes it to src/data/attack/enterprise.json (gitignored), and updates src/data/attack/version.ts with a version string such as Enterprise v16.1. The version file is committed; the JSON is not (too large for git history).
The Dockerfile handles this automatically — the build stage runs scripts/refresh-attack.ts before the TypeScript compile, so docker build produces a self-contained image.
If you clone the repo and skip this step, attack-service will fail fast at startup with an actionable error message pointing to scripts/refresh-attack.ts.
Run the script quarterly (or before each release) to pull the latest ATT&CK version.
Getting started
Public Hosted Instance
A public instance is available at https://pentest.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"pentest-mcp-server": {
"type": "streamable-http",
"url": "https://pentest.caseyjhand.com/mcp"
}
}
}Self-Hosted / Local
Add the following to your MCP client configuration file.
{
"mcpServers": {
"pentest-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/pentest-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"pentest-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/pentest-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"pentest-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/pentest-mcp-server:latest"
]
}
}
}For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpPrerequisites
Bun v1.4.0 or higher (or Node.js v24+).
ATT&CK data seeded — run
bun run scripts/refresh-attack.tsonce after cloning (Docker builds handle this automatically).
Installation
Clone the repository:
git clone https://github.com/cyanheads/pentest-mcp-server.gitNavigate into the directory:
cd pentest-mcp-serverInstall dependencies:
bun installSeed the ATT&CK data:
bun run scripts/refresh-attack.tsConfigure environment:
cp .env.example .env
# edit .env if needed — no required vars beyond transport defaultsConfiguration
No API keys required. The server is fully offline at runtime.
Variable | Description | Default |
| Transport: |
|
| Port for HTTP server. |
|
| Auth mode: |
|
| Log level: |
|
| Directory for log files (Node.js only). |
|
| Enable OpenTelemetry instrumentation (spans, metrics, completion logs). |
|
See .env.example for the full list of optional overrides.
Running the server
Local development
Build and run:
# Seed ATT&CK data (first time, or to update) bun run scripts/refresh-attack.ts # Build bun run rebuild # Run bun run start:stdio # or bun run start:httpRun checks and tests:
bun run devcheck # Lint, format, typecheck, security audit bun run test # Vitest test suite bun run lint:mcp # Validate MCP definitions
Docker
# Build — ATT&CK data is fetched during the build stage
docker build -t pentest-mcp-server .
docker run --rm -p 3010:3010 pentest-mcp-serverThe Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/pentest-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them. The ATT&CK data refresh runs automatically in the build stage.
Project structure
Directory / File | Purpose |
|
|
| MITRE ATT&CK service — loads and indexes the embedded enterprise JSON at startup. |
| OWASP Testing Guide methodology service — vector branches for |
| Payload template service — keyed by category and injection context. |
| Encoding chain executor — pure TypeScript transforms. |
| Pattern library for information leakage and fingerprinting detection. |
| Tool definitions ( |
|
|
| Curated OWASP TG v4.2 methodology content as TypeScript modules. |
| Annotated payload templates by vulnerability category. |
| WAF bypass variants keyed by product and attack vector. |
| Encoding transform functions. |
| Regex patterns and metadata for response leakage detection. |
| Downloads ATT&CK Enterprise JSON and updates the version string. Run once after cloning, then quarterly. |
| Unit and integration tests mirroring |
| Design document — tool surface, data strategy, and architectural decisions. |
Development guide
See CLAUDE.md for development guidelines and architectural rules. The short version:
Handlers throw and the framework catches; catch only to translate an owned operational failure into a declared
ctx.failcontractUse
ctx.logfor request-scoped logging and keep request handling stateless and deterministicRegister new tools via the barrel in
src/mcp-server/tools/index.tsExternal source boundary: validate raw data, normalize to a domain type, then return the output schema; never fabricate missing fields
authorized_use_reminderis a required output field on every tool that produces methodology or payload content — render it as the first line of everycontent[]response informat()Every technique, finding, and payload object has required (non-optional)
detectionandmitigationfields — this is a schema contract, not documentation guidance
Contributing
Issues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testLicense
Apache-2.0 — see LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceAutonomous pentests from one command: real security tools, working PoCs, and audit-ready reports, all driven via MCP.219 PyPI1,692MIT
- FlicenseNot gradedqualityDmaintenanceProvides structured pentesting methodology knowledge base with 7 read-only tools for searching techniques, services, and attack paths via MCP.3-
- AlicenseNot gradedqualityCmaintenanceEnables automated bug bounty hunting and security research with tools for reconnaissance, web vulnerability scanning, API testing, binary analysis, and mobile app analysis through an MCP interface.MIT
- FlicenseNot gradedqualityCmaintenanceMCP server for security analysis, reverse engineering, and penetration testing, providing 70+ tools (nmap, sqlmap, hydra, frida, etc.) with configurable backends (Docker Kali, WSL, SSH).-