HexStrike AI Red Team Integrates 127 Security Tools and BOAZ
Key Takeaways HexStrike AI v6.0, a new fork, has been released, integrating 127 security tools and the BOAZ evasion engine. The platform enables AI agents like Claude and GPT to autonomously conduct...
Key Takeaways
- HexStrike AI v6.0, a new fork, has been released, integrating 127 security tools and the BOAZ evasion engine.
- The platform enables AI agents like Claude and GPT to autonomously conduct red team operations, penetration testing, and vulnerability discovery.
- BOAZ provides advanced EDR/AV evasion capabilities, transforming HexStrike into a comprehensive payload generation pipeline.
- The framework targets authorized penetration testing, bug bounty programs, and red team exercises, explicitly prohibiting malicious use.
HexStrike AI v6.0 has been unveiled as a significant fork of the original HexStrike AI project, introducing a powerful Model Context Protocol (MCP)-based framework designed to automate advanced cybersecurity operations. This latest iteration consolidates 127 professional security tools with BOAZ, a sophisticated multi-layered EDR/AV payload evasion engine tailored for realistic red team scenarios.
Table Of Content
The platform empowers leading AI agents such as Claude, GPT, VS Code Copilot, and Cursor, along with any MCP-compatible AI, to independently manage penetration testing workflows, identify vulnerabilities, and craft enterprise-grade evasion payloads. This integration dramatically reduces the time spent on manual tooling, condensing days of work into mere minutes of AI-driven analysis.
Operating as a FastMCP server, HexStrike AI establishes a crucial bridge between large language models (LLMs) and a meticulously curated collection of offensive security tools. Its core architecture features an Intelligent Decision Engine that functions as the central orchestration unit. This engine is responsible for analyzing target environments, selecting the most effective tools, and executing complex multi-phase assessments without constant human intervention.
Out of the box, HexStrike AI supports six distinct AI client integrations: Claude Desktop, Cursor, VS Code Copilot, Roo Code, 5ire (partial), and any other MCP standards-compliant agent.
BOAZ Red Team Integration
The most impactful addition in this new fork, developed by Muhammad Osama, Yenn503, and Aoxley, is the full integration of BOAZ (Bypass, Obfuscate, Adapt, Zero-Trust). BOAZ, an open-source, multi-layered AV/EDR evasion framework developed by Thomasxm, is now seamlessly embedded within HexStrike.
This integration is facilitated through five dedicated MCP tools, fundamentally transforming HexStrike from a mere scanning engine into a complete red team payload generation pipeline. BOAZ provides an extensive array of capabilities:
- Process Injection Loaders: Over 77 loaders categorized into Syscall (11), Stealth (17), Memory Guard (6), Threadless (6), VEH/VCH (5), and Userland (4).
- Encoding Schemes: 12 schemes including AES, ChaCha20, DES, RC4, AES2, UUID, XOR, MAC, IPv4, Base45, Base64, and Base58.
- EDR Bypass Techniques: Features API unhooking, ETW (Event Tracing for Windows) patching, and LLVM obfuscation utilizing Akira and Pluto compilers.
- Anti-Analysis Controls: Incorporates anti-emulation checks, sleep obfuscation, entropy reduction, and sandbox detection mechanisms.
- Compiler Support: Includes MinGW cross-compiler, NASM assembler, and Wine for Windows binary testing on Linux.
- Output Formats: Generates EXE, DLL, and CPL files, with options for self-deletion and anti-forensic measures.
The BOAZ workflow within HexStrike follows a structured payload pipeline: MSFVenom generation, followed by entropy analysis, then the BOAZ evasion layer, culminating in an enterprise-grade stealth binary.
127-Security Tools Arsenal
HexStrike AI comes equipped with a formidable arsenal of 127 classified security tools. Of these, 53 are automatically installed via the install/install_all.sh script. The remaining 74 tools require manual installation, primarily due to licensing restrictions, specialized dependencies, or specific platform requirements.
Key categories of included tools are:
- Network & Reconnaissance: 10 tools, including nmap, masscan, rustscan, amass, subfinder, nuclei, autorecon, theharvester, responder, and netexec.
- Web Application Security: 19 tools, such as gobuster, feroxbuster, ffuf, nikto, sqlmap, wpscan, httpx, hakrawler, dalfox, commix, and nosqlmap.
- Password & Authentication: 5 tools, including hydra, john, hashcat, evil-winrm, and hashid.
- Binary Analysis & RE: 13 tools, like gdb, radare2, binwalk, ghidra (JDK), checksec, ropgadget, pwntools, and angr.
- Forensics & CTF: 16 tools, including foremost, testdisk, steghide, exiftool, volatility3, scalpel, zsteg, and sleuthkit.
Tools requiring manual installation often have broader enterprise applications, such as wireless tools (aircrack-ng, kismet), cloud auditing platforms (kube-hunter, scout-suite, checkov, terrascan, falco), web proxies (Burp Suite, ZAProxy), and OSINT platforms (Maltego, Censys-CLI).
A full installation of HexStrike AI demands approximately 24 GB of disk space and a compilation time of 60 to 90 minutes. A significant portion of this time, roughly 30 minutes for each, is dedicated to building the LLVM-based Akira and Pluto obfuscators from their source code. The project fork is available for cloning on GitHub.
HexStrike AI’s developers explicitly define its legitimate uses as authorized penetration testing engagements with documented permission, participation in bug bounty programs within specified scopes, CTF competitions, and red team exercises with organizational approval. The project documentation strictly forbids unauthorized testing, data exfiltration, and any malicious activities.
Check Point Research has previously highlighted the inherent dual-use risk associated with LLM orchestration frameworks like HexStrike. They noted that the very abstraction layer that makes these tools incredibly powerful for defensive purposes can also direct offensive capabilities at scale with minimal human supervision. This presents a critical risk vector that security teams must actively consider in their defensive strategies.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.