Autonomous offensive/defensive security research framework, built on Claude Code but works with many
2.4K
An autonomous offensive/defensive security research framework built on top of Claude Code (though it isn't tied to it — you can plug in your own analysis layer too). It chains together static analysis, binary analysis, LLM-powered vulnerability validation, exploit generation, and patch writing into a single workflow you can run against a codebase or binary.
RAPTOR stands for Recursive Autonomous Penetration Testing and Observation Robot. We really wanted to call it RAPTOR.
It is not polished software. It was built in spare time, held together with enthusiasm and duct tape, and it works well enough that we can't stop using it. If you want to make it better, open a PR.
This image is the RAPTOR devcontainer: a ready-built Debian Bookworm
environment with the tooling RAPTOR needs already installed — CodeQL,
Semgrep, AFL++, GDB, the rr debugger, Playwright/Chromium, Node.js, and
Claude Code. It does not bundle the RAPTOR source itself; mount your
checkout into /workspaces/raptor when you run it.
git clone https://github.com/gadievron/raptor.git
cd raptor
docker pull danielcuthbert/raptor:latest
docker run --privileged -it -v "$(pwd):/workspaces/raptor" danielcuthbert/raptor:latest
The --privileged flag is required for the rr deterministic debugger.
Links
- Source: https://github.com/gadievron/raptor
- Licence: MIT (note: CodeQL carries its own licence and does not permit
commercial use)
- Authors: Gadi Evron, Daniel Cuthbert, Thomas Dullien (Halvar Flake),
Michael Bargury, John Cartwright
Content type
Image
Digest
sha256:26685262d…
Size
2 GB
Last updated
about 12 hours ago
docker pull danielcuthbert/raptor