NERF Open Source AI Security Engineering Platform Enters Public Beta

✍️ OpenClawRadar📅 Published: April 4, 2026🔗 Source
NERF Open Source AI Security Engineering Platform Enters Public Beta
Ad

What NERF Does

NERF is an AI security engineering platform and autonomous coding agent that covers offensive, defensive, and everything in between. The platform includes 1,563 security techniques across 117 domains, organized into 9 auto-detected operating modes:

  • 🔴 RED - Attack paths, exploitation, C2, lateral movement
  • 🔵 BLUE - Detection engineering, Sigma/KQL/SPL rules, hardening, threat hunting
  • 🟣 PURPLE - ATT&CK mapping, adversary emulation, detection coverage, gap analysis
  • 🔍 RECON - OSINT, passive/active recon, asset discovery
  • 🚨 INCIDENT - Triage, digital forensics, containment, timeline reconstruction
  • 🏗️ ARCHITECT - Zero trust, threat modeling (STRIDE/DREAD/PASTA)
  • 🔧 BUILD - Security tooling, automation, CI/CD security, IaC
  • 🟢 PRIVACY - GDPR, CCPA, HIPAA, DPIAs, OpSec
  • 🔬 RESEARCHER - Vulnerability research, CVE analysis, threat intel

BUILD mode layers on top of any other mode. RED+BUILD produces offensive tools, BLUE+BUILD produces defensive automation.

Ad

Technical Architecture

Under the hood, NERF includes:

  • 26 LLM providers (Claude, OpenAI, Ollama, OpenRouter, etc.) via unified routing layer with per-phase model selection (cheap models for research, expensive for planning)
  • RAG pipeline over 96 knowledge docs (17,800+ chunks, FTS5 indexed)
  • Cross-session memory that persists across engagements
  • Compliance automation for 39 frameworks (NIST 800-53, SOC 2, PCI DSS 4.0, HIPAA, GDPR, ISO 27001, FedRAMP, EU AI Act, and more)
  • Full engagement engine: work decomposition, auto mode, budget enforcement, crash recovery, git worktree isolation
  • REST API (16 endpoints), MCP server, Signal bot, full CLI
  • ~6,900 tests passing

Getting Started

Quick start commands:

npm install -g @defconxt/nerf
nerf setup
nerf doctor
nerf (in your project directory)

Example usage:

nerf scan https://example.com
nerf compliance SOC2
nerf how do I detect Kerberoasting
nerf red --auto pentest the target

Additional Resources

The main site also includes threat actor profiles and comprehensive dossiers, privacy protection tools, and automated IT/Cybersecurity News aggregated into one spot. This is a public beta - not accepting contributions yet, but feedback is welcome via GitHub issues.

📖 Read the full source: r/ClaudeAI

Ad

👀 See Also

read-once: A Claude Code Hook That Prevents Redundant File Reads
Tools

read-once: A Claude Code Hook That Prevents Redundant File Reads

A developer built a PreToolUse hook called read-once that tracks files Claude Code has already read in a session, blocking re-reads of unchanged files and using diffs for changed files. The tool saves thousands of tokens per session by preventing Claude from repeatedly reading the same file content.

OpenClawRadar
Open-source MCP server adds built-in session memory for Claude Desktop
Tools

Open-source MCP server adds built-in session memory for Claude Desktop

A developer built a TypeScript MCP server with integrated session memory to preserve context between Claude Desktop coding sessions, eliminating the need for separate memory infrastructure. The server includes session save/load functions and additional tools like Brave Search and Google Gemini integration.

OpenClawRadar
Claude-voice: Local TTS with Word Highlighting for Claude Code
Tools

Claude-voice: Local TTS with Word Highlighting for Claude Code

Claude-voice is a Python tool that adds local text-to-speech with real-time word highlighting to Claude Code's voice mode. It uses Kokoro TTS (82M parameters) running fully locally without API keys.

OpenClawRadar
Team Brain: A Shared Memory Plugin for Claude Code That Stores Team Knowledge in Git
Tools

Team Brain: A Shared Memory Plugin for Claude Code That Stores Team Knowledge in Git

Team Brain is a Claude Code plugin that stores team knowledge in a .team-brain/ folder within your repository. It automatically generates a BRAIN.md file capped at 180 lines for optimal Claude instruction accuracy and works across tools by creating .cursorrules and AGENTS.md files.

OpenClawRadar