About This Architecture
CyraFlow AI Pentest Lab Topology demonstrates an isolated, air-gapped penetration testing environment where an AI framework orchestrates reconnaissance and exploitation against intentionally vulnerable targets. The operator controls a Kali Linux attacker VM (192.168.56.101) running CyraFlow, which integrates a ReAct engine, classifiers, and MCP manager to coordinate nmap reconnaissance, Metasploit RPC calls, and credential scanning against Metasploitable 2 (192.168.56.102). CyraFlow leverages either local Ollama inference or cloud LLM APIs (Gemini, Groq, OpenRouter) to generate attack strategies while maintaining operational security through host-only network isolation. This architecture enables red teamers to automate pentest workflows with AI reasoning without exposing sensitive data to external services when using local inference. Fork and customize this lab topology on Diagrams.so to adapt the MCP server configuration, add additional victim VMs, or integrate alternative LLM providers for your security research.