feat(ui): INKO branding + top-bar flyout chat
SquidC5
A SquidSec Open Source Project
SquidOffense.com ·
GitHub ·
Docs
Command · Control · Cognitive · Collaborative · Coordination
Security-first, AI-native C5 teamserver for authorized red team and penetration testing. Built by SquidSec.
Authorized use only. Unauthorized access is illegal.
What C5 means
| Pillar | Role |
|---|---|
| Command | Tasking shells, beacons, native implants |
| Control | Scoped tokens, policy, HITL, feature flags |
| Cognitive | INKO (Intelligent Neural Kinetic Operator) + sandboxed Admin AI + restricted MCP |
| Collaborative | Teams, handoff, per-operator audit |
| Coordination | Profiles, OAST, timeline, reports |
Features
-
Scoped API tokens + immutable audit hash chain (
sc5 audit-verify) -
Dual AI — MCP off by default; INKO neural operator chat + Admin AI (15 allow-listed capabilities); optional local Ollama
-
Native implant —
agents/sc5beacon(Go): AEAD, sleep/jitter/kill/hours, files, SOCKS reverse-dial -
Implant factory —
sc5 implants build/POST /api/v1/implants/build -
Malleable transforms — base64, prepend/append, xor, netbios + profile push
-
SOCKS5 pivot — operator proxy with implant reverse-dial duplex or direct mode
-
File ops —
file:list|read|write|delete(+ chunk offset/length) -
Engagement ROE — banned commands, end time, HITL file-write
-
Multi-op collab — session claim/lock, handoff packs, spectator, presence, team chat, per-op audit
-
Ops console — multi-page nav, mobile drawer, INKO top-bar flyout chat, resizable event/console dock
-
Secure defaults — TLS on, empty CORS (no null), no public OpenAPI, admin.js gated, MCP scoped+HITL, implant AEAD on all listeners
-
Binary CI — Linux/Windows server+CLI, native agents, SBOM
Quick start (Docker lab)
docker compose up --build -d
curl -sk https://127.0.0.1:8443/api/v1/health
docker compose exec squidc5 cat /data/admin_token.txt
# Ops UI: https://127.0.0.1:8443/ops
Quick start (local)
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements-dev.txt && pip install -e .
squidc5
# token: data/admin_token.txt
Binaries
Every push to master builds and releases:
https://github.com/SquidSec/SquidC5/releases/latest
| Asset | Role |
|---|---|
squidc5-linux-x64 |
Teamserver |
sc5-linux-x64 |
Operator CLI |
sc5beacon-* (CI artifact) |
Native implant |
SHA256SUMS.txt / sbom.cdx.json |
Integrity |
chmod +x squidc5-linux-x64 && ./squidc5-linux-x64
./sc5-linux-x64 login --url https://HOST:8443 --token sc5_... --insecure
Prod deploy: binary only from main CI. See docs/deployment.md.
Operator CLI
sc5 login --url https://HOST:8443 --token sc5_... --insecure
sc5 sessions list
sc5 implants build --os linux --arch amd64 C2_HOST 8443
sc5 policy hitl list
sc5 audit-verify
sc5 backup ./backup.db
sc5 ai opsec_review --data "listeners on 443"
Native beacon
cd agents/sc5beacon && go mod tidy && go build -o sc5beacon .
export SC5_URL="https://C2:8443/api/v1/implant/beacon"
export SC5_PSK="$(cat /path/to/data/implant_psk.txt)"
./sc5beacon # TLS verifies system CAs (use real cert or lab CA)
Docs: agents/sc5beacon/README.md
API (selected)
| Area | Path |
|---|---|
| Health | GET /api/v1/health · GET /api/v1/health/deep |
| Implant build | POST /api/v1/implants/build |
| File ops | POST /api/v1/files/op |
| SOCKS | POST /api/v1/pivot/socks |
| Profile push | POST /api/v1/profiles/{id}/push |
| Engagement | GET/PUT /api/v1/engagement |
| HITL | GET /api/v1/policy/hitl |
| Audit verify | GET /api/v1/audit/verify |
| INKO chat (ops) | POST /api/v1/ai/chat · GET /api/v1/ai/tools |
| Admin AI capabilities | POST /api/v1/ai/run · GET /api/v1/ai/status |
| LLM connections | GET/POST /api/v1/llm · POST /api/v1/llm/models |
Auth: Authorization: Bearer <token>. No public OpenAPI on the server.
Documentation
| Doc | Link |
|---|---|
| Docs index | docs/README.md |
| User guide | docs/user-guide.md |
| Operator runbook | docs/operator-runbook.md |
| Deployment | docs/deployment.md |
| Threat model | docs/threat-model.md |
| Five-star roadmap | docs/roadmap-five-star.md |
| Prod readiness | docs/prod-readiness-plan.md |
| Vision | docs/squidc5-vision.md |
| Changelog | CHANGELOG.md |
| Contributing | CONTRIBUTING.md |
| Security | SECURITY.md |
| Agents | AGENTS.md |
Configuration
See .env.example. Prefix SQUIDC5_.
| Variable | Default | Notes |
|---|---|---|
TLS_ENABLED |
true |
HTTPS |
MCP_ENABLED |
false |
External AI tools |
IMPLANT_REQUIRE_AUTH |
true |
AEAD beacons |
LOCAL_LLM_ENABLED |
false |
Opt-in Ollama path |
LOCAL_LLM_BASE_URL |
http://127.0.0.1:11434/v1 |
Ollama-compatible |
LOCAL_LLM_MODEL |
llama3.2 |
Model id when enabled |
RATE_LIMIT_PER_MINUTE |
60 |
Raise for ops UI (e.g. 600) |
PUBLIC_HOST |
empty | Stage-2 / SOCKS data host |
Security model
- Deny by default · scoped tokens · server-side HITL
- INKO / Admin AI: capability + chat-tool allow-lists,
sanitize_untrusted, audited tool calls - Implant AEAD · no skip-verify in native agent
- Audit chain + verify · engagement ROE
- SquidGate on PRs
Development
pytest -q
ruff check src tests
# optional: cd agents/sc5beacon && go build .
Git cycle: feature branch → tests → PR → green CI → merge master. Never push straight to master.
About SquidSec
SquidSec — U.S. veteran-owned security.
Sister project: SquidGate.
License
MIT — LICENSE.
Disclaimer
For authorized security testing and education only. Authors are not responsible for misuse.