0xPhantom/AppSec-Hunter-70B
0
π‘οΈ AppSec Hunter: Llama 3.1 70B Automated Vulnerability Scanner
AMD Developer Hackathon Submission
AppSec Hunter is an automated zero-day vulnerability hunting pipeline. It intercepts raw HTTP traffic, pipes it to an enterprise AMD MI300X GPU, and forces Llama 3.1 70B to act as a programmatic security engine to identify critical threats (IDOR, SSRF, Path Traversal) and output strict, actionable JSON.
π The Architecture & "The Ghost Backend"
This project was designed with extreme cost-efficiency and enterprise cloud economics in mind. Running massive 70B parameter models continuously is expensive. We solved this using the Ghost Backend strategy:
- Intercept: Network traffic is captured locally via tools like
mitmproxy. - Deploy & Hunt: An AMD MI300X cloud instance is spun up. The traffic is securely transferred (
scp) and scanned by Llama 3.1 70B in seconds using a custom API bridge (mass_hunter.py). - Exfiltrate & Destroy: The resulting JSON threat intelligence is extracted, and the AMD cloud instance is immediately destroyed to freeze the billing timer.
- Zero-Cost Analysis: The intelligence is visualized locally using a dark-themed Streamlit dashboard (
app.py), resulting in a 100% free, permanent analysis environment.
π οΈ Technology Stack
- Hardware: AMD Instinctβ’ MI300X Accelerators
- AI Engine: Llama 3.1 70B (Served via Ollama)
- Backend Bridge: Python 3 & Requests
- Frontend UI: Streamlit & Pandas
π Repository Structure
mass_hunter.py- The AI execution engine designed to run on the AMD droplet.app.py- The local Streamlit dashboard for threat visualization.captured_traffic.json- Sample raw HTTP traffic payload.hackathon_intel.json- The finalized AI-generated threat intelligence report.
π» Running the Local Dashboard
Because the cloud backend is ephemeral, this repository is designed to visualize pre-computed intelligence.
# 1. Install requirements
pip install streamlit pandas
# 2. Launch the Ghost UI
streamlit run app.py
