Kali Linux published a new installment in its LLM-driven workflow series showing how to run LLM-assisted penetration testing fully offline/on-prem by hosting the model, context/tooling layer, and client locally. The walkthrough uses Ollama (a local model runner) plus 5ire as a desktop client, emphasizing operational security and privacy benefits versus cloud-hosted AI services, and noting the primary tradeoff is GPU hardware and power cost rather than SaaS subscriptions.
The guide demonstrates an NVIDIA CUDA-based setup on a GeForce GTX 1060 (6GB VRAM), including replacing the open-source nouveau driver with proprietary non-free NVIDIA drivers to enable CUDA acceleration and validating the environment with nvidia-smi after reboot. In parallel, SentinelOne published separate research on using LLMs for cyber threat intelligence (CTI) information extraction, describing how models can convert narrative reports into structured data (e.g., IOCs and relationships) and discussing evaluation tradeoffs; this is adjacent AI-in-security content but not part of the Kali local pentesting stack or its implementation details.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
As part of the published workflow, Kali demonstrated end-to-end natural-language control of Kali tools by having the local LLM stack invoke an nmap scan against scanme.nmap.org through the MCP-connected tool server. The example validated that model inference and tool execution could be performed fully locally.
The Kali Linux team published a guide showing how to run an AI-assisted penetration testing workflow entirely on local hardware using Ollama, mcp-kali-server, and the 5ire client. The guide emphasizes offline operation, NVIDIA GPU acceleration, and avoiding third-party cloud services for privacy and operational security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.