Team Ai
Apppublic

0xPhantom/AppSec-Hunter-70B

sourceHugging Faceupdated 5mo agoView on Hugging Face
0likes
App README

πŸ›‘οΈ AppSec Hunter: Llama 3.1 70B Automated Vulnerability Scanner

AMD Developer Hackathon Submission

AppSec Hunter is an automated zero-day vulnerability hunting pipeline. It intercepts raw HTTP traffic, pipes it to an enterprise AMD MI300X GPU, and forces Llama 3.1 70B to act as a programmatic security engine to identify critical threats (IDOR, SSRF, Path Traversal) and output strict, actionable JSON.

πŸš€ The Architecture & "The Ghost Backend"

This project was designed with extreme cost-efficiency and enterprise cloud economics in mind. Running massive 70B parameter models continuously is expensive. We solved this using the Ghost Backend strategy:

  1. 1.Intercept: Network traffic is captured locally via tools like mitmproxy.
  2. 2.Deploy & Hunt: An AMD MI300X cloud instance is spun up. The traffic is securely transferred (scp) and scanned by Llama 3.1 70B in seconds using a custom API bridge (mass_hunter.py).
  3. 3.Exfiltrate & Destroy: The resulting JSON threat intelligence is extracted, and the AMD cloud instance is immediately destroyed to freeze the billing timer.
  4. 4.Zero-Cost Analysis: The intelligence is visualized locally using a dark-themed Streamlit dashboard (app.py), resulting in a 100% free, permanent analysis environment.

πŸ› οΈ Technology Stack

  • β€”Hardware: AMD Instinctβ„’ MI300X Accelerators
  • β€”AI Engine: Llama 3.1 70B (Served via Ollama)
  • β€”Backend Bridge: Python 3 & Requests
  • β€”Frontend UI: Streamlit & Pandas

πŸ“ Repository Structure

  • β€”mass_hunter.py - The AI execution engine designed to run on the AMD droplet.
  • β€”app.py - The local Streamlit dashboard for threat visualization.
  • β€”captured_traffic.json - Sample raw HTTP traffic payload.
  • β€”hackathon_intel.json - The finalized AI-generated threat intelligence report.

πŸ’» Running the Local Dashboard

Because the cloud backend is ephemeral, this repository is designed to visualize pre-computed intelligence.

bash
# 1. Install requirements
pip install streamlit pandas

# 2. Launch the Ghost UI
streamlit run app.py