How to update:
1. Stop the Morgana NT Service sc stop Morgana
2. Download and run the installer above
3. Restart the machine shutdown /r /t 0
4. After restart, the Morgana service will start automatically
Active Workspace:
[DEMO]Public demo · Read-only · Simulated data
MORGANA HELP CENTER
Morgana Documentation
User guidance, administration procedures, community resources, and product information.
Morgana is free and open-source software licensed under GNU AGPL v3. It can execute adversary-emulation commands with Agent service privileges. Use it only on systems covered by explicit written authorization and approved rules of engagement.
Dashboard
0
Agents Online
0
Tests Running
0
Tests Passed
0
Tests Failed
0
Excalibur Scripts
Recent Tests
TCode
Type
Name
Agent
State
Exit
Started
Duration
Loading...
Agent Status
Loading agents...
Agents
-
Online
-
Offline / Stale
-
Total
-
Windows
-
Linux
-
macOS
-
Tagged
-
Avg Beacon
Name
Hostname / PAW
Platform
OS
Status
Last Seen
Beacon
Tags
Version
Loading...
Industrial Lab
-
Services Available
-
Installed
-
Running
-
Lab Hosts
-
Active Labs
Loading Industrial Lab overview...
Service
Provider
Protocol
Runtime
Default Port
Fidelity
Loading services...
No deployed Labs. Click "Deploy Lab" to create one.
Agent
Platform
Status
Lab Host
Python
uv
Container
Raw Network
Loading hosts...
Mobile Lab
Provision and manage Android and iOS security test environments
Determines ATTACK_DETECTED by cross-referencing test data with detection fabric evidence.
P
Intelligent Report
report_agent
Produces a staged AI Detection Assurance assessment with evidence-grounded findings, priorities, SOC actions and retest criteria.
R
Red Team
red_agent (Orchestrator + Attacker + Analyst)
3 AI agents working together: Orchestrator decides strategy, Attacker generates real attack code, Analyst judges results. Loops until BLOCKED or FINISHED.
Agent Prompts
All 21 AI agent prompts are shown here. Click "Edit" to customise any prompt — the next agent call will use your version. "Reset" restores the hardcoded default.
Edit Prompt
Adapters
Status:-|Adapters:-|Total Detections:-|Ingestion Interval:- min
Vendor API Adapters
Adapter
Status
Last Sync
Statistics
Empty
Tick the rows you want to ingest, then press Sync Selected for specific Vendor Adapters, or use
Sync All Adapters to run all enabled Vendor Adapters and all enabled Universal folder adapters at once.
Only adapters that are both Enabled and Configured will actually run; the others are skipped silently.
Secrets (client secret / token) are stored encrypted on disk (Fernet) and never returned through the API.
Universal Adapter (Morgana JSON)
Reads *.json files in Morgana JSON format from enabled folders. Successfully imported files are deleted.
Name
Folder
Status
Last State
Last Run
Actions
Loading...
Universal Adapter Evidence
Evidence ingested through Universal Adapter sources such as folder-based Morgana JSON integrations.
Time
Integration
Host / OS
User
Process
Command line
Severity
Threat / Title
Techniques
Loading...
Detection Detail
New Universal Adapter
Enabling starts folder ingestion immediately.
Required Morgana JSON format
Each .json file may contain one event object or an array of event objects.
Paste a sample log payload to see format detection, parsed events, and the Morgana Normalized Event (MNE) output. Nothing is stored.
Run a test to see output.
Global Detection & Telemetry Evidence
All evidence currently stored in Detection Fabric across vendor adapters, test-scoped telemetry retrieval and Universal Adapters.
Detection ID
First Activity (UTC)
Last Activity (UTC)
Source
Type
Title
Severity
Status
Techniques
Events
Entities
Test Association
Actions
Empty
Automation Center
Schedules
Name
Target
Trigger
Mode
Status
Last Run
Next Run
Runs
Loading...
Execution History —
Started
Duration
Mode
Trigger
Status
Detection
Select a schedule above to see its history.
New Schedule
Advanced options
Execution Detail
Morgana Intelligence Lab
0
Approved Corpus
0
Pending Review
0
Hard Cases
0
Human Overrides
0
Datasets
0
Active Runs
None
Production Model
None
Latest Candidate
Fixtures / quick actions:
Admin
Server Information
-
IP Address
-
Machine Name
-
Platform
-
Server Port
-
Memory Used %
-
Memory Free GB
-
Disk Used %
-
Disk Free GB
[SAVED]
The DNS name is used in one-liner installer commands. If empty, the server IP address is used.
The IP address is read-only (detected from the host network interface).
API Keys
Keys authorize requests to this Morgana server. Create a named key with + New Key — the full value is shown once after creation.
A Copy button appears in the table for keys created in this browser session.
Name
Key (prefix)
Created
Loading...
Global Agent Defaults
Default beacon interval applied to newly enrolled agents. Per-agent overrides can be set by clicking the Beacon value in the Agents table.
[SAVED]
Logging
Configure log retention and the minimum severity level to record.
[SAVED]
[APPLIED]Changes take effect immediately, reset on server restart
Database Backup
Last backup:-
Folder:-
[SAVED]
Loading...
Calibration Governance
Evidence governance
Real execution is never automatic Gold. Every governed case must pass human review before entering the
versioned calibration corpus. The original system label is preserved across any human override.
Provider coverage gap (sensor lacks evidence) is kept distinct from Morgana ingestion gap
(evidence exists but Morgana fails to normalize/persist it).
Morgana Brain
Cognitive vs Endpoint Agents Cognitive Agents are internal Morgana AI specialists (Script / Test Result / Detection /
Red / Report / Executive / Critic) that reason over evidence. Endpoint Agents are the
Go/Windows/Linux services installed on targets that execute jobs. The Executive Brain never dispatches
Endpoint Agent jobs in ANALYSIS_ONLY / PLAN_ONLY modes, and this kernel never dispatches them at all.
Raw hidden chain-of-thought is never persisted — only structured decision evidence.
Cognitive Foundry
Cognitive Foundry
The Foundry discovers, acquires, benchmarks and specialises base models. Arena evidence outranks brand claims.
No trust_remote_code=True. No repository code execution. Adapters are learned specialist capabilities.
Cognitive Agents are runtime organs built from model + adapter + role.
Self Development
Controlled self-development
Morgana observes its own cognitive performance, creates Growth Needs, decides the appropriate improvement
(routing, Skill, model switch, adapter, Agent clone, new Agent, or more data), and builds/evals it inside the
SANDBOX_AUTONOMOUS policy envelope. Normal growth happens through routing, memory, Skills, models,
adapters and Cognitive Agent definitions — never arbitrary source-code self-rewriting. No Endpoint Agent jobs
are dispatched, and dynamic Agents never exceed ANALYSIS_ONLY authority.
Intelligence Heritage
Intelligence Heritage
Morgana learning does NOT automatically leave the local installation. Validated knowledge is promoted by an
operator through exactly one of three inheritance channels: the private Intelligence repository (Cognitive
Agents + Skills manifests), the private Model Artifact Registry (adapters/models resolved by manifest + hash,
never Git), and the public Camelot repository (sanitized generalized Variants via branch + PR, never a direct
push to main). Every outbound action requires an explicit preview and approval.
Execution Strategy
Chain Composer
Review Case
Create New API Key
[SUCCESS] New key created
[WARNING] Copy this key now — it will NOT be shown again.
Deploy Agent - One-liner Installer
Paste the command below on the target machine (one line).
It downloads the agent binary directly from this server and installs the service.
No files to transfer manually.
[WINDOWS] - PowerShell 5.1+ (run as Administrator)
[LINUX] - bash (run as root)
[INFO] Agent binaries must be compiled before deployment.
Run .\build\build-agents.ps1 from the Morgana root to build both Windows & Linux binaries (requires Go).
Uninstall Agent -
Run these commands on the target machine to stop and remove the Morgana agent service.
After running them, click the x button in the agent row to remove the record from this server.
[INFO] These commands only remove the agent from the target machine.
To also remove the agent record from this server, click the x button in the agents table row.
Script
ⓘSave Changes to persist edits and update the AI Review and Tags — both use the saved command. Use #{tag_key} format in the command for runtime values (e.g. #{listener_ip}).
Complete this action outside Morgana in the authorized lab. A Chain stops at this checkpoint; after completion, run the next applicable phase or customized Chain.
Review Script with AI
The agent will review the current command, explain what the technique does, list requirements and risks, and suggest improvements.
Press Apply to apply the suggested improvements to the Command and Cleanup Command fields.
Execute on Agent
Output Analysis
The agent found an issue and suggests a fix. Press Fix Script to update the Command fields.
Loading...
▶ Chain Execution
Chain:Agent:
⚡ Red Team Attack
Script
⚠ Red Team
Script:Agent:Max iterations:Timeout (s):
Context for Red Team (env info: IPs, hostnames, tenant IDs...)
Current Command:
(waiting for output...)
Tags
Click ⚡ Ask AI to get suggested values for each tag. Click a suggestion chip to apply it.
Console - Agent
Select Script
TCode
Name
Tactic
Executor
Platform
Loading...
Execution Log
Select Chain
Name
Description
Nodes
Loading...
Chain
Loading...
Compose
Campaign Execution Log
Execute
Execute Selected
Items without an assigned agent:
Report Style
COLOURS
TYPOGRAPHY
BRANDING
Configure Adapter
Secrets
Values are encrypted with a local Fernet key and stored on disk separately from the config. They are never returned by the API. Leave blank to keep the current stored value.
Detection Details
Morgana Detection Assurance Intelligence Report
Generate an AI-only, evidence-grounded assessment of detection assurance, root causes, priorities, SOC actions and retest criteria. Use Export Report ZIP for detailed evidence.