pexels tima miroshnichenko 5380589

Nebula: AI-Assisted Recon and Vulnerability Analysis in Your Terminal

Most AI pentesting tools fall into one of two camps: fully autonomous (run it and hope), or just a chatbot with a security-themed system prompt. Nebula sits deliberately in between – it’s an AI-assisted CLI tool that provides analysis and command suggestions while keeping a human in control of every actual action. That’s not a limitation; it’s a design choice that makes it appropriate for professional engagements where you need to document and justify every step.

What Nebula Is

Nebula is a command-line tool for penetration testers that provides AI-powered guidance during recon, note-taking, and vulnerability analysis. You run your tools as normal; Nebula helps you interpret the output, suggests next steps, and maintains structured notes throughout the engagement. It supports multiple LLM backends including local Ollama models.

The key distinction from fully autonomous tools like METATRON: Nebula doesn’t execute tools itself. It analyses output you provide and suggests what to run next. You stay in the loop on every action.

Installation

git clone https://github.com/berylliumsec/nebula
cd nebula

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

cp .env.example .env
nano .env

Connecting to a Local Ollama Backend

# In .env or config:
LLM_PROVIDER=ollama
OLLAMA_BASE_URL=http://localhost:11434
OLLAMA_MODEL=llama3.1:8b     # Fast for basic analysis
# or
OLLAMA_MODEL=qwen2.5:14b     # Better reasoning

# Verify Ollama is running
ollama list

# Start Nebula
python nebula.py

The Basic Workflow

# 1. Start a new engagement
nebula new-engagement --target "192.168.56.101" --name "Lab Assessment 2026-06"

# 2. Run Nmap as normal
nmap -sV -sC -oA /tmp/scan 192.168.56.101

# 3. Feed output to Nebula for analysis
nebula analyse --file /tmp/scan.nmap

# 4. Run a suggested command, paste output back
nebula analyse --input "$(nikto -h 192.168.56.101)"

# 5. Add manual notes
nebula note "FTP allows anonymous login - confirmed"

Recon Analysis in Practice

# Analyse Nmap XML (richer data)
nebula analyse --file /tmp/scan.xml --format nmap-xml

# Example Nebula output:
# == Analysis of 192.168.56.101 ==
#
# Open Services:
# - FTP (21): vsftpd 2.3.4 - HIGH RISK: backdoored version
#   Suggested: use exploit/unix/ftp/vsftpd_234_backdoor in Metasploit
#
# - HTTP (80): Apache 2.2.8 - MEDIUM RISK: outdated Apache
#   CVE: CVE-2011-3192
#   Suggested: run Nikto, check for web application vulnerabilities
#
# == Recommended Next Steps ==
# 1. Exploit vsftpd backdoor (highest confidence)
# 2. Run Nikto against port 80
# 3. Check for anonymous FTP access

Vulnerability Analysis

# Ask context-aware questions
nebula ask "Given this nmap output, what post-exploitation steps should I take after getting root via vsftpd?"

# Analyse a CVE in context
nebula cve CVE-2021-4034

Note-Taking Integration

# Add timestamped findings
nebula finding --severity high --title "vsftpd 2.3.4 backdoor" 
               --evidence "Connected to port 6200 after triggering backdoor" 
               --recommendation "Upgrade vsftpd to current version"

# Export notes for report writing
nebula export --format markdown > /tmp/engagement_notes.md
nebula export --format json > /tmp/engagement_data.json

How Nebula Compares

  • vs METATRON: METATRON is more autonomous – runs tools and analyses results automatically. Nebula keeps you in control. Use METATRON for fast initial assessment, Nebula for methodical engagements requiring documentation.
  • vs PentestGPT: PentestGPT uses cloud APIs. Nebula runs fully locally and has better note/report integration.
  • vs plain Claude/ChatGPT: General AI assistants lack engagement context, don’t maintain state, and have no security tooling integration. Nebula wraps those capabilities in an engagement-aware interface.

Model Recommendations

# Fast mode (quick analysis during active testing)
OLLAMA_MODEL=llama3.2:8b

# Quality mode (thorough analysis, planning)
OLLAMA_MODEL=qwen2.5:14b
OLLAMA_MODEL=deepseek-r1:14b  # Best for reasoning through attack chains

Conclusion

Nebula is the right tool when you need AI assistance but also need a defensible audit trail. Its human-in-the-loop design makes it appropriate for professional engagements, and the local LLM support means you don’t have to choose between AI assistance and client data privacy. Think of it as an AI-powered sidekick that analyses what you show it and suggests what to do next – the decisions, and the actions, stay with you.


Leave a Reply