Raven is a complete pentest framework: recon, findings, evidence, and reporting in one place. Free to download and free to run your whole engagement, right on your machine. Agentic AI tools are built in, but optional to use.
Free to download and run Docker or standalone CLI Runs entirely on your machine
curl -fsSL https://chamberdoorsecurity.com/install.sh | sh
One-line install for Kali, Debian 12+, and Ubuntu 22.04+. View source · Docker, macOS, Windows below ↓
Run the whole engagement in one place: your data, your imports, your exports. Download it and go. The full pentest lifecycle, visible, transferable, and reportable in a single view, with AI integration only for when you need it.
Findings, evidence, hosts, services, credentials, scope, and notes, all tracked together from recon to report. It's your data, on your machine. Your project.
Pull in Nessus, Burp, and raw scanner output. Everything lands in one normalized, severity-ranked view instead of scattered files on disk. Consolidating your data and files lets you test more efficiently, with a more organized workflow.
Push findings and evidence out to PlexTrac, Burp, CSV, PDF, or Obsidian. Hand off to whatever you already use to write the report, and stay in control of what gets exported and how.
Scope, methodology, host inventory, and findings by severity render to markdown or PDF straight from your engagement data. No credits, no model call, no waiting on a prompt.
Nmap, Nuclei, SQLMap, Subfinder, Gowitness, Feroxbuster, and more, orchestrated from one UI with results auto-parsed into your findings.
Turn a sequence of scans into a repeatable workflow: passive recon to HTTP probing to a Nuclei sweep. Pick a template or build your own. Expand your capacity by operating as efficiently as possible, without giving up control.
LOLBAS, GTFOBins, LOOBins, WADComs, LOLDrivers, and HijackLibs, searchable with MITRE mapping, without leaving the tool.
One place for the whole engagement: your data, your imports, your findings, and your exports, all in one tool.
Hosts, ports, services, domains, credentials, and scope, tracked together and cross-linked. Click a host to see everything you've found on it.
Import Nessus scans, Burp issues, and raw scanner output. Everything normalizes into the same severity-ranked findings, with no scattered files and screenshots to chase. Raven sits on top of the process you're already doing.
Nmap, Nuclei, Nessus, and manual findings land in one severity-ranked list with CVEs, affected hosts, and source. Ports, emails, and exposures are tracked right alongside, so there is nothing to collate by hand. Create clean, standardized reporting.
Push findings and evidence out to PlexTrac, Burp, CSV, PDF, or Obsidian, straight into whatever you already use to write the report. Raven automates perhaps the most tedious task in your workflow.
Chain scanners into a single run: passive subdomain discovery to HTTP probing to a Nuclei scan. Pick a template or build your own. Optimize the process you're already doing.
Recon and web testing are only half the job. Drop an agent on your RTA, or pivot through a jumpbox, and run the internal Active Directory attack chain from the same place you track everything else. No AI required.
Drop a lightweight connect-back agent on your RTA, or a jumpbox in the DMZ, and it dials home over an encrypted tunnel. See each one's status and tooling at a glance, then launch the next tool without ever leaving the engagement. Time spent moving between tools feels trivial until you consolidate the views, and once every status is visible in one place it is obvious why a single platform matters.
Kick off LLMNR/NBT-NS poisoning and SMB relay in one move. Raven finds the signing-disabled targets, runs Responder and ntlmrelayx on your agent, and streams every captured hash and successful relay back live, with coercion available when you need to force authentication.
Every NetNTLMv2, Kerberos ticket, and relayed hash lands in one library, auto-parsed, deduped, and hashcat-ready. Crack them in place and the recovered passwords flow straight into your credential store for the next hop.
Feed in a BloodHound collection and Raven charts the graph: kerberoastable accounts, delegation, and the shortest path to DA with a risk score on every hop. The weaknesses it surfaces turn straight into findings, without adding another step.
Deploy a lightweight connect-back agent on your RTA, or pivot raw-socket tools through an SSH jumpbox. Either way you're running from inside the network.
Raven orchestrates the classic chain: Responder poisoning, ntlmrelayx (SMB dump or LDAP/RBCD), Coercer, netexec, Kerberoasting. Captured hashes are auto-parsed, deduped, and hashcat-ready.
Pin active testing to your rules-of-engagement window. Outside the agreed hours, Raven warns, or blocks and auto-defers the run until the window opens. Your SOW, enforced.
Recon hints, analysis, a chat assistant, report narratives. Optional, and metered by credits (or bring your own model for free).
Run it in Raven and the whole loop is tuned as one piece: our prompts, how your findings are fed in, and how the output comes back structured for your report. That's the combination we've refined on real engagements, not context pasted into a chatbot. Prefer your own AI account? You can still bring your own model: Raven hands you an anonymized copy-paste prompt, then de-anonymizes the answer when you paste it back. You can write your own prompts, of course, but that means testing them yourself, keeping every output anonymized, and catching hallucinations. Raven has already built that in, for when you need it.
And it never sees your client's real data. Every hostname, IP, domain, and user becomes a placeholder before the request leaves your machine. Here's the actual payload the model receives:
Same engagement, two views. Every value that identifies your client is swapped for a stable placeholder before the request leaves your machine. Tooling context (SMB, NTLM, Kerberos) is kept so the model can still reason, while passwords and hashes are stripped one-way and never sent at all.
Hover or tap any value to trace it across the boundary.
The model answers in placeholders too: host-1, DOMAIN\user-1. Raven swaps your real names back in on your machine, before you read a word, so your findings and report say DC01 and ACME\jsmith. The lookup table never leaves your box, and the redacted secrets stay gone.
Every AI action in Raven runs on prompts purpose-built for offensive security and refined across real engagements. The result? Analysis grounded in your findings, not generic chatbot filler or AI slop. Anonymized data goes out; how Raven turns it into sharp, report-ready work stays under the hood.
Constrained to your engagement's real findings, so recommendations map to what's actually on the wire, not a plausible-sounding hallucination.
Output comes back in a shape your findings list and report templates consume directly: less reformatting, faster to the deliverable.
Built around the methodology (recon, credentials, lateral movement) and hardened against prompt injection coming from raw tool output.
“I built this for me, to make my life as a pentester easier and keep my boss off my back. Then I sat back, looked at what it had become, and thought: every pentester should have this.”
Raven didn't start as a product. It started as my own engagement tooling: the scanners I run every week, the findings tracking I was doing by hand in spreadsheets, and an AI advisor that actually works with the engagement data instead of hallucinating over it. It was built to get the work done and the report out the door, not to be sold.
It got good enough that keeping it to myself started to feel selfish. So here it is: the same tool I use, packaged so you can too.
The framework is yours to run. AI is the only thing you pay for. Pay-as-you-go credits don't expire, and every credit unlocks the full methodology. Or subscribe for the best per-credit rate and the frontier model.
Credits are metered and managed in the app, so you pay only for what you use. Running a team or agency? Talk to sales.
Raven itself is free, on every platform. Pick yours and we'll show you what works. AI is the only thing that ever costs anything, and only if you use it.
I'm using:
Docker image with the full Kali toolchain bundled, so it works anywhere Docker runs. Download and run it; AI features draw from your credit balance once you pair.
~2.9 GB Docker image
The easiest install on any Debian-family system, including Kali. Add our apt repository once, then raven-server and raven-cli install and stay current with apt upgrade, like the rest of your machine.
Standalone terminal client. Connect to any Raven server from your terminal. Same REPL as the web UI, with AI chat. Download and connect; AI features draw from your credit balance.
~25-46 MB
For Kali / Mac-with-Homebrew pentesters who already have nmap, nuclei, etc. installed natively. Skip the 3 GB Docker image: download just the server binary, run raven-server start, web UI is up. Then pair with chamberdoor for AI features.
~70-80 MB
One command adds the signed repository and installs Raven, so it upgrades with apt like any other package.
1. Install
curl -fsSL https://chamberdoorsecurity.com/install.sh | sh
2. Start it and pair for AI
raven-server start # web UI on http://localhost:8080 (binds 127.0.0.1)
raven-server auth login # one-time: pair your Chamber Door account to enable AI
Optional: the operator CLI / REPL
sudo apt install raven-cli
View the installer source before running it, or add the repository by hand if you manage apt sources with configuration management. Heads up: don't apt install raven. Debian ships an unrelated tool by that name, so our packages are raven-server and raven-cli (the CLI installs as /usr/bin/raven-cli so it coexists).
1. Load the Docker image
docker load < raven-pro-amd64.tar.gz
2. Create the data folder
mkdir -p pentests auth config
3. Run it
docker run -d --name raven --network host --restart unless-stopped \
--cap-add=NET_RAW --cap-add=NET_ADMIN \
-v $(pwd)/pentests:/home/raven/pentests \
-v $(pwd)/auth:/home/raven/.raven \
-v $(pwd)/config:/home/raven/.config/raven \
raven:pro-amd64
4. Open in your browser
open http://localhost:8080
5. Pair with your chamberdoor account to unlock AI (one-time)
docker exec -it raven raven auth login
Raven runs fully without this: scans, engagement data, the whole workflow. Pairing signs you in to your chamberdoor account so the AI features (chat, methodology, analysis, reports) can draw from your credit balance. The CLI prints a URL; open it, sign in, confirm the device.
Optional standalone client. Connect to your Raven server from any terminal.
1. Make it executable (macOS: remove quarantine first)
xattr -d com.apple.quarantine raven-cli-pro-darwin-arm64
chmod +x raven-cli-pro-darwin-arm64
sudo mv raven-cli-pro-darwin-arm64 /usr/local/bin/raven-cli
2. Connect to your server
raven-cli -s localhost:8080
3. Or connect to a remote server
raven-cli -s your-server-ip:8080