Here’s a problem that doesn’t get discussed enough: when penetration testers pipe their recon output into ChatGPT or Claude.ai to ask “what does this mean?” or “what should I exploit next?”, they’re sending client data to a third-party API. That data – hostnames, IP addresses, service versions, vulnerability details – may belong to a client under NDA. The exposure risk is real.
METATRON is an open-source AI penetration testing assistant that solves this by running entirely locally. Your recon output never leaves your machine. It uses Ollama to serve a fine-tuned LLM locally, combines it with standard security tooling, and produces structured assessment output without any cloud API calls.
Why Local LLM Pentesting Matters
Three distinct reasons to prefer local LLMs for security work:
- Data privacy: Client hostnames, IPs, vulnerability details, and credentials should never touch a third-party API.
- Offline operation: Works behind strict egress firewalls, in air-gapped environments, or without internet access.
- Unrestricted responses: Cloud APIs have safety filters that can refuse legitimate professional security discussions. Local models are generally less restricted.
How METATRON Works
- Standard security tools (nmap, nikto, whatweb) run the reconnaissance
- Collected output is piped into a locally-running LLM via Ollama
- The LLM analyses findings, cross-references CVEs via DuckDuckGo, and produces structured analysis
- An agentic loop allows the model to request additional tool runs if it needs more data
Hardware Requirements
- Minimum: 16GB RAM (CPU-only inference, slow but functional)
- Recommended: 16GB RAM + dedicated GPU with 8GB+ VRAM
- Storage: ~7GB for model weights
Installation on Kali Linux
# Install Ollama
curl -fsSL https://ollama.com/install.sh | sh
sudo systemctl enable --now ollama
# Pull the METATRON model
ollama pull huihui_ai/qwen3.5-abliterated:9b
# Verify
ollama list
curl http://localhost:11434/api/tags
# Clone METATRON
git clone https://github.com/[metatron-repo]/metatron.git
cd metatron
# Install dependencies in virtualenv (recommended)
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
Running Against a Lab Target
# Basic scan (lab VM only)
python3 metatron.py --target 192.168.56.101
# Verbose mode
python3 metatron.py --target 192.168.56.101 --verbose
# Specify output directory
python3 metatron.py --target 192.168.56.101 --output /tmp/metatron_results/
# Web-focused profile
python3 metatron.py --target 192.168.56.101 --profile web
The Agentic Loop
METATRON’s most interesting feature is its agentic loop. After initial recon, the LLM can decide it needs more information and request additional tool runs:
- Nmap discovers port 8080 with an unidentified service
- LLM requests a whatweb or curl probe against port 8080
- Results show Apache Tomcat 9.0.12
- LLM cross-references CVEs for that version and adds them to the report
This iterative approach mimics how a human analyst works without requiring manual intervention.
Configuring the Ollama Backend
# Environment variables or config.yaml
OLLAMA_BASE_URL=http://localhost:11434
OLLAMA_MODEL=huihui_ai/qwen3.5-abliterated:9b
CONTEXT_WINDOW=16384
TEMPERATURE=0.7
# Test the model
ollama run huihui_ai/qwen3.5-abliterated:9b
>>> What is the CVE for the vsftpd 2.3.4 backdoor?
Interpreting the Output
METATRON produces a structured report covering: attack surface summary (open ports, services, OS fingerprint), vulnerability findings (CVEs with CVSS scores), recommended next steps in priority order, and exploitation guidance for each finding.
Comparing to Cloud-Based Alternatives
PentestGPT (cloud APIs) produces more sophisticated analysis when the cloud model is larger. The trade-off is data privacy and offline operation. For professional engagements, the privacy argument alone justifies accepting somewhat less capable analysis in exchange for keeping client data on your machine. As local models improve, this gap is closing rapidly.
Conclusion
METATRON represents the direction AI-assisted penetration testing is heading: powerful LLM analysis without the liability of sending client data to third-party APIs. The setup investment is real – you need compatible hardware and several gigabytes of model weights – but once running, the workflow is clean: point it at your target, let it run, review the structured output.
Only use METATRON against systems you own or have explicit written authorisation to test.

Leave a Reply
You must be logged in to post a comment.