416rehmanandClaude Opus 5 d83d1711e0 feat: run pipelines with your Claude Code subscription, no API key required
Pipelines can now use the Claude Code you already have installed and
signed in, so LLM analysis works without a third-party API key or
per-token billing:

    model: claude-code            # default model
    model: claude-code/sonnet     # or /opus, or a full model name

DeepZero never handles your credentials - it runs your own `claude`
binary in headless mode and inherits its existing sign-in. If the CLI is
missing or not signed in, validation says so before a run starts.

The pipeline feeds untrusted decompiled code to the model, so the
integration denies tools and external servers, sends the prompt over
stdin rather than the command line, and hides any ANTHROPIC_API_KEY from
the CLI so your subscription is used and not a metered API. Usage limits
retry with backoff; sign-in failures stop immediately with a clear
message.

Under the hood, LLM backends are selected from the model string by a
registry, so another agent CLI can be added later without touching the
engine, pipelines, or stages. Existing API-key models are unaffected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-24 21:07:34 -06:00
2026-04-27 22:31:51 -06:00
2026-04-27 18:24:19 +05:30
2026-04-27 22:31:51 -06:00
2026-04-27 22:31:51 -06:00
2026-04-27 22:31:51 -06:00
2026-04-27 22:31:51 -06:00
2026-04-16 01:22:54 -04:00


DeepZero

Automated vulnerability research pipeline engine

Define pipelines as YAML. DeepZero handles orchestration, parallelism, fault tolerance, and state.

CI License Docs Python Platform


DeepZero terminal dashboard

English | 简体中文 | Français

  • 🔗 Pipeline-as-YAML - chain ingest, filter, transform, and LLM-assess stages declaratively
  • ⚡ Parallel execution - ThreadPoolExecutor with configurable concurrency per stage
  • 💾 Resumable runs - atomic per-sample state on disk; Ctrl+C and re-run to pick up where you left off
  • 🤖 LLM integration - Jinja2 prompt templates with any LLM provider via LiteLLM
  • 🌐 REST API (WIP) - query run state and sample data over HTTP (currently experimental and incomplete)
  • 🧩 Extensible - write custom processors as Python classes, reference them by path in YAML

📚 Documentation

DeepZero features extensive, exhaustive documentation covering architecture, pipeline schemas, CLI references, and custom processor development.

👉 Read the Official Documentation here


⚡️ Quickstart

DeepZero requires a target corpus of files to analyze and a pipeline configuration detailing how to process them.

  1. Clone & Install (Python 3.11+)

    git clone https://github.com/416rehman/DeepZero.git
    cd DeepZero
    pip install -e .
    
  2. Configure Environment

    cp .env.example .env
    
  3. Run a Pipeline

    deepzero run C:\drivers -p .\pipelines\loldrivers\pipeline.yaml
    

For detailed setup instructions and example corpora, see the Quickstart Documentation.


📁 Repository Structure

src/deepzero/
├── api/                 # REST API (starlette)
├── engine/              # orchestration, state persistence, pipeline execution
└── stages/              # built-in processors (map, reduce, ingest)

processors/              # external processors (shipped as examples)
├── ghidra_decompile/    # ghidra headless decompiler (MapProcessor)
├── loldrivers_filter/   # loldrivers.io hash exclusion filter (MapProcessor)
├── pe_ingest/           # PE header parser and driver metadata extractor (IngestProcessor)
└── semgrep_scanner/     # semgrep batch scanner (BulkMapProcessor)

pipelines/
└── loldrivers/          # BYOVD kernel driver vulnerability research pipeline
    ├── pipeline.yaml
    ├── assessment.j2    # LLM prompt template
    └── rules/           # semgrep rules

docs/                    # Jekyll-based GitHub Pages documentation
tests/                   # pytest suite

🤝 Contributing

CI runs on Python 3.11 and 3.12 via GitHub Actions.

Run linting and security checks before submitting:

ruff check . && ruff format --check . && bandit -ll -ii -c pyproject.toml -r .

Please refer to the Contributing Guide and the Code of Conduct before submitting pull requests.


📄 License

DeepZero is released under the MIT License.

S
Description
Automated archival mirror of github.com/416rehman/DeepZero-Agentic-Vulnerability-Research-Pipeline
Readme MIT
6.6 MiB
Languages
Python 99%
Jinja 1%