
Erebus is an AI-powered pentesting assessment agent that turns authorized targets—domains, URLs, repos, files, APIs, and LLM apps—into prioritized, report-ready security findings grounded in real tool evidence. Paste this into Long Description: Erebus is an AI-powered pentesting assessment platform built for the age where software ships faster than security teams can manually validate it. The agent takes an authorized target such as a domain, URL, repository, uploaded file, API endpoint, or LLM-powered web app, then gathers evidence through safe security tools and intelligence sources. Instead of simply chatting about cybersecurity, Erebus acts like an assessment layer. It connects scanner output, HTTP metadata, public web intelligence, dependency analysis, exposed service data, repository review, file inspection, and LLM application testing into a single normalized report. The system is designed to avoid hallucinated vulnerabilities: findings are only created when there is evidence from tools, user-provided artifacts, or controlled test results. Each finding is converted into a pentest-style format with severity, confidence, affected asset, evidence, business impact, remediation guidance, validation steps, and security mappings such as CWE or OWASP categories. This makes Erebus useful not only for auditing our own apps before production, but also for helping teams investigate suspicious repositories, files, phishing surfaces, exposed services, and AI application behavior. The project combines a fine-tuned cybersecurity model, retrieval over modular security datasets, and an extensible tool architecture. Today it can support web security assessment, OSINT enrichment, malware and file triage, dependency risk review, and LLM security checks. In the future, Erebus can grow into a full autonomous security assessment copilot that helps developers, startups, and security teams validate products faster without lowering the quality of the analysis.
31 May 2026