« All posts

Agenthound: Offensive Security Framework for AI Agent Infrastructure

Agenthound is an open-source offensive security framework mapping attack paths across MCP, A2A, and AI model infrastructure via a Neo4j graph.

Agenthound is an open-source offensive security framework that targets every layer of the modern agentic stack - MCP, A2A, model gateways, inference servers, vector stores, MLOps, and notebooks. It unifies recon, fingerprinting, credential looting, modelfile/system-prompt inventory, model inversion for training-data residue, tool/instruction poisoning, and config-implant persistence under a single CLI, merging findings into a Neo4j graph to surface real attack paths.

Positioned as 'BloodHound for the agentic stack,' the framework uses 23 node labels, 32 edge kinds, and 15 post-processors to compute cross-protocol pivots and credential chains that raw data alone can't reveal. It ships 35 detection rules and 19 prebuilt attack-path queries mapped to OWASP MCP/Agentic Top 10 and MITRE ATLAS.

For engineers running AI infrastructure and red teams alike, Agenthound offers a single point to map and validate the attack surface of agent-based systems. Released under Apache-2.0, it deploys via Docker Compose for the analysis server and a static binary for the collector, and is explicitly scoped for use only against authorized infrastructure.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work