AI-Based Intelligent Vulnerability Scoring System (AI-VSS) is an autonomous cybersecurity testing platform that combines AI-assisted attack generation, runtime observability, and intelligent vulnerability scoring.
The system automatically clones GitHub repositories, detects technology stacks, deploys isolated Docker environments, executes intelligent attack simulations, monitors application behavior, and generates professional security reports with CVSS v3.1 and Extended Behavior-Based Security Score (EBSS).
- Automated GitHub repository analysis
- Technology stack fingerprinting
- Dynamic Docker environment generation
- AI-assisted attack orchestration
- Playwright-based application crawling
- Runtime observability and monitoring
- CVSS v3.1 severity scoring
- Extended Behavior-Based Security Score (EBSS)
- Professional HTML security reports
- Safe containerized attack execution
User Repository URL
│
▼
Repository Cloner
│
▼
Stack Detection Engine
│
▼
Docker Environment Generator
│
▼
Target Application Deployment
│
▼
AI Attack Orchestrator
│
▼
Observability & Monitoring
│
▼
CVSS + EBSS Calculation
│
▼
Security Report Generator
- Python
- Docker
- Docker Compose
- Playwright
- PostgreSQL
- Git
- Large Language Models (LLMs)
- AI-based Payload Generation
- Adaptive Attack Suggestions
- Security Classification Engine
- Runtime Telemetry Collection
- Container Statistics Monitoring
- Database Performance Monitoring
- Log Correlation System
- User submits GitHub repository URL.
- Repository is cloned locally.
- Technology stack is detected.
- Docker Compose configuration is generated.
- Application is deployed inside isolated containers.
- Playwright crawler maps application endpoints.
- AI engine generates attack payloads.
- Attacks execute inside sandboxed attacker containers.
- Runtime metrics are continuously monitored.
- CVSS and EBSS scores are calculated.
- Professional HTML report is generated.
- SQL Injection
- Cross-Site Scripting (XSS)
- Authentication Bypass Testing
- API Abuse Detection
- Command Injection Testing
- CPU Utilization Monitoring
- Memory Consumption Analysis
- Response Latency Tracking
- Error Log Analysis
- Database Performance Monitoring
Industry-standard vulnerability severity scoring based on:
- Attack Vector
- Attack Complexity
- Privileges Required
- User Interaction
- Confidentiality Impact
- Integrity Impact
- Availability Impact
Custom scoring model based on runtime impact:
| Behavior Metric | Weight |
|---|---|
| CPU Spike | +4 |
| DB Error Rate Spike | +3 |
| Sensitive Data Exposure | +5 |
| Successful Data Exfiltration | +8 |
| Container Crash | +6 |
| Response Time > 3x Baseline | +2 |
The generated report includes:
- Attack Timeline
- Vulnerability Findings
- CVSS Scores
- EBSS Scores
- Runtime Metrics
- Observability Graphs
- Impact Analysis
- CWE References
- Remediation Recommendations
| Component | Requirement |
|---|---|
| Processor | Intel i5 / Ryzen 5+ |
| RAM | 8 GB Minimum |
| Storage | 20 GB Free Space |
| Internet | Required |
| OS | Windows / Linux |
| Software | Version |
|---|---|
| Python | 3.x |
| Docker | Latest |
| Docker Compose | Latest |
| Playwright | Latest |
| Git | Latest |
- Autonomous exploit chaining
- Machine learning vulnerability prediction
- Kubernetes security testing
- Cloud-native deployment analysis
- DevSecOps integration
- GitHub Actions support
- Real-time monitoring dashboards
- Framework-specific exploit modules
- Offline enterprise security mode
- Niraj Naphade
- Atharva Padwal
- Shruti Mogre
- Prof. Nikhil Sardar
- Mr. Uday Mithapelli
This project is developed for academic and research purposes.
This platform is intended solely for authorized security testing, cybersecurity education, and research. Users must obtain proper permission before testing any target system.

49897fb446bb2d3a3e2912af557f004ed88ab470