# FunnyWolf/Viper: a free red team platform with an LLM agent and Python modules

> Viper bundles over 100 post-exploitation modules, multi-platform implants and a built-in LLM agent behind a web UI. The README sells the feature list; the repository itself exposes only a documentation site, so the install path is the first thing to check.

**FunnyWolf/Viper** — Adversary simulation and Red teaming platform with AI

- Repository: https://github.com/FunnyWolf/Viper
- Website: https://www.viperrtp.com
- Stars: 5,319 · Forks: 705
- Language: Unknown
- License: not declared
- Published: 2026-09-09 · Updated: 2026-09-09 · Language: en
- Canonical page: https://hysenlabs.com/projects/funnywolf-viper

## What Viper is for, and who ends up using it

Viper is an adversary simulation and red teaming platform. The README describes it as integrating "the core tools and functionalities required for adversary simulation and red team operations", with the stated goal of completing cybersecurity assessment tasks efficiently. That places it in the same category as commercial command-and-control frameworks rather than in the scanner or vulnerability-management category.

The intended user is a red team operator running an assessment across mixed operating systems. The README claims implants for Windows, Linux and macOS, a pivot graph, team collaboration, and built-in evasion. The product comparison table in the README positions Viper against Cobalt Strike, NightHawk and BruteRatel on exactly those axes, and lists Viper's price as Free while listing the others at per-user annual figures.

A second audience is the automation-minded operator. The README advertises orchestration and notification mechanisms for continuous monitoring of target environments, plus a built-in LLM agent for "automated processing capabilities and intelligent decision-making support". Those two claims are the parts that distinguish Viper from older free C2 projects, and they are also the parts the README explains least.

## The moving parts: web console, modules, implants, agent

The repository layout is thin. The top level contains .github/, docs/, package.json, tsconfig.json, vercel.json, README.md and README_ZH.md. The package.json scripts are docs:dev, docs:build and docs:preview, all invoking Vitepress against the docs directory, and the devDependencies are documentation tooling: vitepress, markdown-it-mathjax3, medium-zoom and similar. In other words, this repository is the documentation and website source, not the platform source. The platform itself is distributed elsewhere, which the README points to through its Getting-Started and Documentation links on viperrtp.com and a Docker Hub organisation named viperplatform.

From the README's feature list, the architecture reads as four layers. A visual web interface sits on top. Below it is a module layer of "over 100 post-exploitation modules covering all stages of the MITRE ATT&CK framework". Below that are the implants for Windows, Linux and macOS. Alongside all of it runs the LLM agent, which the README says enhances automated processing and decision support. The README also lists anti-tracing, a handler firewall, defense evasion, a pivot graph and automated notification as further built-in features.

Extensibility is Python. The comparison table states the custom plugin language as Python, against CNA for Cobalt Strike and nothing for NightHawk and BruteRatel. The README repeats that Python-based custom module development is supported for specialised requirements. That is a real design commitment: anyone who can write Python can add a module without learning a proprietary scripting dialect.

## Installing Viper and running a first session

The README does not contain install commands, and this repository contains no code to build the platform from. What it does contain is documentation tooling. The package.json scripts are the only runnable commands in the tree:

```json
{
  "scripts": {
    "docs:dev": "vitepress dev docs",
    "docs:build": "vitepress build docs",
    "docs:preview": "vitepress preview docs"
  }
}
```

Running those builds the docs site you are reading, not a Viper server. For the platform itself, the README links a Getting-Started page at www.viperrtp.com/guide/getting_start, a Documentation page at www.viperrtp.com/guide/welcome_to_viper, and a Docker Hub organisation at hub.docker.com/u/viperplatform. Those are the sources the project names for installation.

The README does not print an image name, a tag, a published port or a default account, so none of that can be quoted from here. Read the Getting-Started page and the Hub organisation page for the exact pull target and the port the console listens on.

For the first real use, the sequence the README implies is: open the web interface, confirm the console is reachable, then look for the module list and the agent panel. The README claims over 100 post-exploitation modules, so the module list is the fastest way to confirm you are running the real thing and not a stub. If you plan to write a module, the README's statement that custom modules are Python is the relevant fact; it does not publish an API reference or a module template in this repository, so the guide is where the entry point has to come from.

One practical note on the agent: the README says an LLM agent is built in but does not say which model provider it calls, whether an API key is required, or whether inference happens locally. Budget time for that configuration step before an engagement, not during one.

## Where Viper will disappoint you

The largest limitation is distribution opacity. The repository you are reading when you land on github.com/funnywolf/viper is a Vitepress site. The scripts build docs, not a server. Anyone who clones it expecting to compile the platform will find no source tree for the platform, and the README never says this outright. It is discoverable only by reading package.json or by noticing that every link points off-repository.

The licence is not stated in the README. For a tool that runs implants on target hosts and handles engagement data, the licence determines whether you can use it commercially, whether you can redistribute a modified build, and what happens if something goes wrong during an authorised test. That information has to come from the project's own pages, and it is the first thing a legal or procurement reviewer will ask for.

The README's own feature claims are also unquantified. "Over 100 post-exploitation modules" has no breakdown by platform or by ATT&CK tactic. "Built-in evasion" has no description of what is evaded or against which detection stack. "Anti-tracing" and "handler firewall" are named but not defined. None of these are reasons to avoid the tool; they are reasons to test it against your own detection baseline before you rely on the claim in a report.

Finally, the LLM agent is a double-edged feature. Sending engagement context to a model provider is an operational security decision, and the README does not describe the data flow. If your rules of engagement forbid target data leaving your infrastructure, confirm the agent's inference path before enabling it.

## Viper against Cobalt Strike, on approach rather than price

The README's comparison table makes Cobalt Strike the obvious reference point, and the difference is not only the price line. Cobalt Strike ships Windows implants; Viper claims Windows, Linux and macOS. Cobalt Strike's custom plugin language is CNA; Viper's is Python. The README marks built-in evasion, automation and the LLM agent as absent in Cobalt Strike and present in Viper, and marks team collaboration as present in both.

That framing is the vendor's own, and it should be read as such. Cobalt Strike is a commercial product with a vendor behind it, a paid support relationship, and a long history of third-party tooling, training material and detection research built around it. Viper's README lists no company, no support tier and no training programme. The trade is straightforward: you give up a contract and an ecosystem, and in exchange you get a free platform with a Python extension model and broader implant coverage.

If your team already has CNA scripts, Aggressor scripts and years of muscle memory in another console, porting that investment to Python modules is real work that the README does not acknowledge. If your team has no existing investment, the Python model is the easier starting point. NightHawk and BruteRatel appear in the same table as Windows-only, closed to custom plugins, which makes the comparison sharper: Viper's differentiator is breadth of platforms plus an open extension language.

## Maintenance cadence, releases and what upgrading costs

The last push to the repository was on 2026-05-31, and the repository is not archived. Recent releases are v3.1.9 (2025-11-09), v3.1.10 (2026-01-18) and v3.1.11 (2026-03-31), the last carrying the tagline "Skill is all you need". The gap between the most recent release and the most recent push is roughly two months, which is consistent with documentation and site work continuing between tagged platform releases.

Because this repository only builds documentation, upgrading here means updating docs, not the platform. The platform upgrade path runs through the Docker image or whatever distribution the Getting-Started guide describes. That has a consequence worth stating plainly: the release notes in this repository describe platform versions, but the artefacts you deploy are published outside it, so you should pin an explicit image tag rather than tracking a floating one. A red team platform that changes under you mid-engagement is a problem you cannot debug afterwards.

The upgrade cost that is easy to miss is module compatibility. The README states that custom modules are written in Python, and it does not state a module API stability policy. If you maintain private modules, assume you will need to re-test them after each minor version bump, and read the release notes for v3.1.x before pulling a new image.

On licence implications: the README does not name a licence, so there is nothing here to reason about. Do not assume a permissive licence because the price is listed as Free. Free of charge and free to modify are different claims, and only the project's own licence file settles which applies to you.

## Conclusion

Viper suits red teams that want a free, self-hosted console covering Windows, Linux and macOS with Python-based module development, and that are prepared to read the official guide before touching a target. It is the wrong choice if you need a vendor contract, indemnification or a support line, since the README lists no commercial backing and the repository holds only documentation sources. Verify first that the Docker image tag you intend to run is the one the guide names, and confirm the licence terms and the LLM provider configuration before any engagement, because neither is stated in the README.

## FAQ

### What is FunnyWolf/Viper?

It is an adversary simulation and red teaming platform. The README describes it as integrating the core tools for red team operations, with Windows, Linux and macOS implants, over 100 post-exploitation modules, a pivot graph and a built-in LLM agent.

### How do I install FunnyWolf/Viper?

The README does not give install commands. It links a Getting-Started page at www.viperrtp.com/guide/getting_start and a Docker Hub organisation at hub.docker.com/u/viperplatform, which are the sources the project names for installation.

### How do I use FunnyWolf/Viper?

The README points to the guide at www.viperrtp.com/guide/welcome_to_viper for usage. It describes a visual interface for launching assessments, a module list covering MITRE ATT&CK stages, and Python-based custom module development, but publishes no usage walkthrough in the repository.

### What is another name for FunnyWolf/Viper?

The README does not give the project an alternative name. It refers to the platform as VIPER throughout and links the website www.viperrtp.com, which is the only other name the repository attaches to it.

## Sources

- [FunnyWolf/Viper on GitHub](https://github.com/FunnyWolf/Viper)
- [Issues](https://github.com/FunnyWolf/Viper/issues)
- [Project website](https://www.viperrtp.com)
- [README](https://github.com/FunnyWolf/Viper/blob/master/README.md)
- [Releases](https://github.com/FunnyWolf/Viper/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/funnywolf-viper
