Kali Linux published documentation for an AI-assisted penetration testing workflow that uses Anthropic’s Claude Desktop as a natural-language interface and the open-source Model Context Protocol (MCP) to translate prompts into tool execution on a Kali host. The described architecture separates a GUI “UI layer” (Claude Desktop on macOS/Windows), an “execution layer” (a Kali system running an mcp-kali-server bridge that exposes tools), and an “intelligence layer” (Anthropic’s Claude Sonnet 4.5 in the cloud). The goal is to let operators request tasks like port scanning and web checks in plain language, with the LLM planning and iterating through tool calls while returning structured results.
This is not an incident report but a capability/workflow enablement that can materially change how offensive tooling is orchestrated, including by lowering the operational friction of chaining common recon and enumeration steps. Organizations evaluating similar agentic workflows should treat the MCP bridge and any AI agent runtime as a privileged automation surface (credentials, tokens, tool execution, and output handling), and consider isolation and least-privilege controls when experimenting with LLM-driven command execution in security tooling environments.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage described the integration as a native AI-assisted penetration testing workflow and emphasized risks such as prompt injection, excessive permissions, and weak audit logging when MCP-enabled tools can execute commands. The reporting also noted Kali's cautions about privacy and engagement-scope concerns when using a cloud LLM in offensive security workflows.
In the published workflow, Kali showed an example where a user request in Claude Desktop caused the system to run an nmap scan of scanme.nmap.org through the MCP bridge. The demonstration included tool checks and execution of the scan from the Kali host, with results returned to the LLM-driven interface.
Kali Linux documented a method for using Claude Desktop on macOS with Anthropic Sonnet 4.5 to translate natural-language requests into security tool commands executed on a Kali host via the Model Context Protocol. The guide described enabling SSH access, installing and running the mcp-kali-server on Kali, and configuring Claude Desktop to invoke it remotely.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.