Skip to main content

Cyberstrike is now open source! AI-powered penetration testing for security professionals. Star on GitHub

Getting Started

Cyberstrike is an AI-powered penetration testing agent that automates security assessments. This guide covers installation, authentication, and running your first scan.

Cyberstrike installation and first run

System Requirements

Before installing Cyberstrike, verify your system meets these requirements:

RequirementMinimumRecommended
Operating SystemmacOS 12+, Ubuntu 20.04+, Windows 10+macOS 14+, Ubuntu 22.04+
RAM4 GB8 GB
Disk Space500 MB2 GB
Node.js18.0+20.0+

Installing Cyberstrike

Choose your preferred installation method based on your operating system and package manager.

  1. Open your terminal
  2. Run the installation command:
Terminal window
npm install -g @cyberstrike-io/cyberstrike@latest
  1. Verify the installation:
Terminal window
cyberstrike --version
Cyberstrike TUI after installation

Bun Coming Soon

Bun support is not yet available.

Homebrew (macOS) Coming Soon

Homebrew support is not yet available.

curl (Linux/macOS)

Run the installation script:

Terminal window
curl -fsSL https://cyberstrike.io/install | bash

iwr (Windows/Powershell)

Run the installation script:

Terminal window
iwr -useb https://cyberstrike.io/install.ps1 | iex

Caution

Review scripts before executing them. The installation script is available at github.com/CyberStrikeus/CyberStrike.

Docker

Caution

Docker image is coming soon. For now, use npm or curl.

Authenticating with an AI Provider

Cyberstrike auth login flow

Cyberstrike requires an AI provider to function. The following providers are supported:

ProviderFree TierAPI Key Required
OpenRouterYesYes
AnthropicNoYes
OpenAINoYes
Google GeminiYesYes
OllamaYes (Local)No

Setting Up Authentication

Cyberstrike model selection dialog
  1. Run the authentication command:
Terminal window
cyberstrike auth login
  1. Select your provider from the list:
? Select provider
❯ OpenRouter (free tier available)
Anthropic (API key from console.anthropic.com)
OpenAI (ChatGPT Plus/Pro or API key)
Google (API key from ai.google.dev)
Ollama (local models)
Other
  1. Enter your API key when prompted

  2. Verify your credentials:

Terminal window
cyberstrike auth list

Using Environment Variables

Set API keys as environment variables instead of storing them:

Terminal window
# Anthropic
export ANTHROPIC_API_KEY="sk-ant-..."
# OpenAI
export OPENAI_API_KEY="sk-..."
# Google
export GOOGLE_GENERATIVE_AI_API_KEY="AI..."
# OpenRouter
export OPENROUTER_API_KEY="sk-or-..."

Add these to your shell profile (~/.bashrc, ~/.zshrc) for persistence.

Running Your First Scan

Starting Interactive Mode

Launch Cyberstrike in your target directory:

Terminal window
cd /path/to/target
cyberstrike

The terminal user interface (TUI) appears with:

  • Input prompt at the bottom
  • Response area in the center
  • Status bar showing model and token usage
Cyberstrike TUI main interface

Executing a Quick Scan

Run a single command without entering interactive mode:

Terminal window
cyberstrike run "perform reconnaissance on example.com"

Specialized Agents

Cyberstrike runs one primary agent — cyberstrike — which automatically delegates to specialized subagents based on the task. You don’t select these by hand; the primary agent dispatches them through its task tool:

SubagentFocus
web-applicationWeb-app security (OWASP WSTG)
cloud-securityAWS / Azure / GCP / Kubernetes (CIS)
internal-networkNetwork & Active Directory
mobile-applicationMobile apps (MASTG / MASVS)
proxy-agentTesting proxy-captured web traffic

The --agent flag (and the default_agent config) selects the primary agent. Only cyberstrike ships built-in — you can define your own, see Custom Agents. Passing a subagent name falls back to the default with a warning.

Basic Configuration

Create a cyberstrike.json file in your project directory to set default options:

cyberstrike.json
{
"$schema": "https://cyberstrike.io/config.json",
"model": "anthropic/claude-sonnet-4-20250514"
}

When you run cyberstrike in this directory, it automatically loads these settings. The example above uses Claude Sonnet as the default AI model, so you don’t need to pass --model every time. The cyberstrike agent runs by default and delegates to specialized subagents as needed.

Configuration Hierarchy

Cyberstrike loads configuration from multiple sources in this order:

  1. Command line arguments (highest priority)
  2. Environment variables
  3. Project config (cyberstrike.json)
  4. User config (~/.config/cyberstrike/cyberstrike.json)
  5. Default values (lowest priority)

For detailed configuration options, see the Configuration Reference.

Keyboard Shortcuts

Learn these shortcuts for efficient navigation:

ShortcutAction
EnterSubmit message
Shift+EnterNew line
EscapeInterrupt the running session
Ctrl+PCommand list
TabNext agent
Ctrl+DExit Cyberstrike
/ Navigate input history

See Keyboard Shortcuts for the full reference.

Next Steps

Continue learning with these guides:

  1. Configuration Reference - Customize Cyberstrike settings
  2. AI Providers - Configure your preferred AI provider
  3. Security Agents - Learn about specialized agents
  4. CLI Commands - Complete command reference

Tip

Join the community at Discord for support and updates.