Morgana M
    • [D] Dashboard
    • [I] AI
    • [A] Agents
    • [TI] Test Intelligence
    • [X] Intelligence Lab
    • [G] Calibration
    • [B] Morgana Brain
    • [F] Cognitive Foundry
    • [E] Self Development
    • [H] Intelligence Heritage
    • [A] Assessments
    • [R] Assessment Snapshots
    • [VP] Validation Packages
    • [EN] Environments
    • [PP] Parameter Packs
    • [P] Campaigns
    • [T] Tests
    • [S] Scripts
    • [C] Chains
    • [L] Industrial Lab
    • [M] Mobile Lab
    • [I] Adapters
    • [Z] Automation Center
    • [G] Tags
    • [U] Users
    • [L] Logs
    • [*] Admin
  • [?] Help
Connecting...
[UPDATE AVAILABLE] Download Installer
How to update:  1. Stop the Morgana NT Service  sc stop Morgana   2. Download and run the installer above   3. Restart the machine  shutdown /r /t 0   4. After restart, the Morgana service will start automatically
Active Workspace:
[DEMO] Public demo · Read-only · Simulated data
MORGANA HELP CENTER

Morgana Documentation

User guidance, administration procedures, community resources, and product information.

Free and Open Source GNU AGPL v3
Morgana
Created and authored by
in Nino Crudele View LinkedIn profile ↗
X3M.AI Ltd, United Kingdom
COMPLETE REFERENCE Morgana User and Administrator Manual Installation, Agents, Scripts, Excalibur Packs, Chains, Tests, Campaigns, Detection Fabric, AI, settings, security, backup, API, and troubleshooting. Open manual ↗ TEST INTELLIGENCE Test Intelligence Operator Guide Technique, Behavior Class, Test Family, Test Variant, Execution Strategy, Execution Plan, Plan Run, Test Instance, Coverage, Detection Gaps, Family Review, and the Semantic Chain Composer. Open guide ↗ OFFICIAL COMMUNITY Camelot Community Camelot is the official community repository for Merlino and Morgana: documentation, installers, templates, laboratories, Excalibur content, Stockpile and Atomic Red Team packs, and shared resources. Open Camelot ↗ ASSURANCE Assessment Snapshots & Executive Report Immutable assurance snapshots joining Merlino strategic context with Morgana test and detection evidence, and the 14-slide native PowerPoint Executive Report. Open guide ↗
Free software, responsible use.

Morgana is free and open-source software licensed under GNU AGPL v3. It can execute adversary-emulation commands with Agent service privileges. Use it only on systems covered by explicit written authorization and approved rules of engagement.

Dashboard

0
Agents Online
0
Tests Running
0
Tests Passed
0
Tests Failed
0
Excalibur Scripts

Recent Tests

TCode Type Name Agent State Exit Started Duration
Loading...

Agent Status

Loading agents...

Agents

-
Online
-
Offline / Stale
-
Total
-
Windows
-
Linux
-
macOS
-
Tagged
-
Avg Beacon
Name Hostname / PAW Platform OS Status Last Seen Beacon Tags Version
Loading...

Industrial Lab

-
Services Available
-
Installed
-
Running
-
Lab Hosts
-
Active Labs
Loading Industrial Lab overview...
Service Provider Protocol Runtime Default Port Fidelity
Loading services...
No deployed Labs. Click "Deploy Lab" to create one.
Agent Platform Status Lab Host Python uv Container Raw Network
Loading hosts...

Mobile Lab

Provision and manage Android and iOS security test environments

-
Devices
-
Running
-
Ready
-
Hosts
-
Apps
-
Instances
Loading Mobile Lab overview...
Name Platform Provider Model OS Host State Health Frida Drozer Apps
Loading devices...
Name Platform Version Package / Bundle Source License Installed On
No app assets registered.
No templates available.
Agent Platform Status Mobile Lab Host SDK ADB Emulator Xcode simctl Frida Virtualization
Loading hosts...

Scripts

[*] Excalibur Script Packs — Certified adversary emulation packs from Camelot CDN
[INFO] Click Refresh catalog to load available packs.
-
Total Scripts
-
Unique TCodes
-
Tactics
-
Windows
-
Linux
-
macOS
-
Excalibur
-
Custom
-
Modified
-
PowerShell
-
CMD / Bash
TCode Name Tactic Executor Platform Source Tags Actions
Loading...

Tests

Success Rate-
Avg Duration-
Unique TCodes-
Agents-
Scripts Used-
Detection Fabric AI
- Reviewed
|
- In Review
|
- Pending
|
- Blocked
Detection Intelligence
-Validated Tests
-Confirmed
-Possible
-No Telemetry
-Not Detected
-Inconclusive
-Errors
Date TCode Type Name Script Agent State Status Detection Fabric Verdict Sync Detections Exit Code Duration Actions
Loading...

Detection Scoring Settings

Signal Points

Test Detail

ID
TCode
State
State Reason
Exit Code
Agent
Duration
Created
Finished
STDOUT

            
STDERR

            
STRUCTURED RESULT

            
AI REVIEW
Detection Fabric Verdict
Ranked candidates (score = correlation score; higher = stronger match)
Evidence Bundle
Detection AI

Chains

-
Total
-
With Scripts
-
Empty
-
Total Nodes
-
Avg Nodes
-
Updated Today
Name Description Nodes Updated
Loading chains...

Recent Executions

Chain Agent State Started Finished
No executions yet

New Chain

Campaigns

-
Total
-
With Chains
-
Empty
-
Total Chain Refs
-
Avg Chains
-
Updated Today
Name Description Chains Updated
Loading campaigns...

Recent Executions

Campaign Agent State Started Finished
No executions yet

New Campaign

Save campaign first to assign tags.

Assessment Snapshots

Snapshots

Assessment Organisation Area Created Baseline Tests Assurance Snapshot Report Actions
Loading...

Snapshot

Tags

Workspaces

Loading workspaces...

Tag Definitions

Editing tag:
Label Key Value Namespace Type Flags (?) Usage
Loading...

Users

[WARNING] Break glass account admin@admin.com is using the default password. Change it now.

Create User

NameEmailAliasRole ProviderEnabledWorkspacesTags
Loading...

Change Break Glass Password

Change Break Glass Password

Server Logs

-
Timestamp Level Source Message
Click "Last 30 min" or set filters and click Apply.

AI Mission Engine

Engine Status

Loading...

Active Provider

Provider
-
Model
-
Auth
-

Change Provider

Step 1 — Select provider

Step 2 — Configure credentials

These providers use your gh CLI token. If already signed in (gh auth status), no extra step is needed. Otherwise sign in once:

Open https://github.com/login/device and enter the code:

----
Recommended models
LM Studio Setup Guide
How to find the model name
  1. Open LM Studio and load your model (click Load on the model card).
  2. Go to Developer tab → Local Server. The loaded model identifier is shown next to “Model” (e.g. gemma-4-26b-a4b-instruct-ud).
  3. Alternatively, with the server running, open: http://localhost:1234/v1/models — the id field in the JSON response is the exact model name to use here.
  4. Copy that identifier and paste it into the Model field above.
Performance optimization — Gemma 4 27B (recommended settings)
In LM Studio, select your model → click Settings (the gear icon on the model card) and apply the following:
Setting Value Why
Context Length Just below your GPU VRAM limit Larger context = more VRAM used. Set as high as your GPU allows without offloading to RAM.
GPU Offload (GPU Layers) MAX (100% / all layers) Loads the entire model on GPU. Avoids slow CPU/RAM fallback. Fastest inference.
K Cache Quantization Type Q8_0 Reduces KV cache VRAM usage with minimal quality loss. Allows longer context on the same GPU.
V Cache Quantization Type Q8_0 Same as K cache — reduces VRAM for value cache with near-lossless quality.
Tip: after changing GPU Offload or Context Length you must reload the model in LM Studio for the settings to take effect.
Step 3 — Test & apply

Morgana AI — Local

Powered by the Morgana Intelligence Engine (MIE)
LOCAL ONLY — No external AI data egress
Set Up Morgana AI
  1. Check this computer
  2. Start the engine
  3. Verify or install an Intelligence Pack
  4. Assign a model to a compatible Agent
  5. Run the local AI self-test
Engine Status
Loading...
Check This Computer
Local AI Self-Test
Performance Benchmark
One-click Agent assignment
Morgana Specialist Models
Installed Intelligence Packs
How to use Morgana AI ▸
  1. Start the engine
  2. Install or verify a specialist model
  3. Assign that model to a compatible Agent
  4. Run the self-test
  5. Use Morgana normally

You can use Morgana AI for one Agent and a cloud/general provider for another. Starting Morgana AI does not change existing Agent provider selections.

AI Agents

Each agent can use a different AI provider
Apply same provider to ALL agents at once
S
Script Agent
script_agent
Analyses Red Team scripts. Explains techniques, lists requirements and risks. Called from the Scripts UI.
T
Test Result Agent
test_result_agent
Analyses test execution output. Determines BLOCKED / INTERCEPTED / ERROR / FAILED / FINISHED status.
D
Detection Agent
detection_agent
Determines ATTACK_DETECTED by cross-referencing test data with detection fabric evidence.
P
Intelligent Report
report_agent
Produces a staged AI Detection Assurance assessment with evidence-grounded findings, priorities, SOC actions and retest criteria.
R
Red Team
red_agent (Orchestrator + Attacker + Analyst)
3 AI agents working together: Orchestrator decides strategy, Attacker generates real attack code, Analyst judges results. Loops until BLOCKED or FINISHED.

Agent Prompts

All 21 AI agent prompts are shown here. Click "Edit" to customise any prompt — the next agent call will use your version. "Reset" restores the hardcoded default.

Edit Prompt

Adapters

Status: - | Adapters: - | Total Detections: - | Ingestion Interval: - min

Vendor API Adapters

Adapter Status Last Sync Statistics
Empty

Tick the rows you want to ingest, then press Sync Selected for specific Vendor Adapters, or use Sync All Adapters to run all enabled Vendor Adapters and all enabled Universal folder adapters at once. Only adapters that are both Enabled and Configured will actually run; the others are skipped silently. Secrets (client secret / token) are stored encrypted on disk (Fernet) and never returned through the API.

Universal Adapter (Morgana JSON)

Reads *.json files in Morgana JSON format from enabled folders. Successfully imported files are deleted.

Name Folder Status Last State Last Run Actions
Loading...

Universal Adapter Evidence

Evidence ingested through Universal Adapter sources such as folder-based Morgana JSON integrations.

TimeIntegrationHost / OSUser ProcessCommand lineSeverityThreat / TitleTechniques
Loading...
Detection Detail

New Universal Adapter

Enabling starts folder ingestion immediately.

Required Morgana JSON format

Each .json file may contain one event object or an array of event objects.

{
  "schema": { "name": "morgana.normalized_event", "version": "1.0" },
  "event": {
    "id": "event-001", "time": "2026-08-25T10:30:00Z",
    "category": "process_activity", "class": "process",
    "type": "process_start", "severity": "high", "status": "open"
  },
  "source": { "vendor": "Vendor Name", "product": "Product Name", "integration": "integration_name" },
  "device": { "hostname": "HOST01", "id": "device-001", "ip": "10.0.0.10", "os": "Windows" },
  "actor": { "user": { "name": "alice", "upn": "alice@example.com", "id": "user-001" } },
  "process": { "name": "powershell.exe", "pid": 1234, "command_line": "powershell.exe -File test.ps1" },
  "network": { "src_ip": "10.0.0.10", "dst_ip": "10.0.0.20", "dst_port": 443, "protocol": "tcp" },
  "threat": {
    "name": "Suspicious PowerShell",
    "techniques": [{ "framework": "MITRE ATT&CK", "technique_id": "T1059.001", "technique_name": "PowerShell" }],
    "confidence": 80
  },
  "raw": { "format": "vendor_json", "original_event": { "id": "source-event-001" } }
}

Run History

Ingestion Runs

Started Status Format Source Received Accepted Rejected Dupes Error Summary
Loading...

Parse / Validation Errors

TimeLineTypeMessageFragment
Loading...

Test Parser / Normalizer

Paste a sample log payload to see format detection, parsed events, and the Morgana Normalized Event (MNE) output. Nothing is stored.

Run a test to see output.

Global Detection & Telemetry Evidence

All evidence currently stored in Detection Fabric across vendor adapters, test-scoped telemetry retrieval and Universal Adapters.

Detection ID First Activity (UTC) Last Activity (UTC) Source Type Title Severity Status Techniques Events Entities Test Association Actions
Empty

Automation Center

Schedules

Name Target Trigger Mode Status Last Run Next Run Runs
Loading...

Execution History —

Started Duration Mode Trigger Status Detection
Select a schedule above to see its history.

New Schedule

Target
Trigger
5-field cron (UTC): minute hour day month weekday
Execution Mode
[WARN] Red Team Mode is enabled. This schedule will be routed through the Red Teamer engine instead of the standard executor. Only scripts are fully supported; chains/campaigns will run each script node individually via the Red Teamer.
Advanced options

Execution Detail

Morgana Intelligence Lab

0
Approved Corpus
0
Pending Review
0
Hard Cases
0
Human Overrides
0
Datasets
0
Active Runs
None
Production Model
None
Latest Candidate
Fixtures / quick actions:

Admin

Server Information

-
IP Address
-
Machine Name
-
Platform
-
Server Port
-
Memory Used %
-
Memory Free GB
-
Disk Used %
-
Disk Free GB
[SAVED]

The DNS name is used in one-liner installer commands. If empty, the server IP address is used. The IP address is read-only (detected from the host network interface).

API Keys

Keys authorize requests to this Morgana server. Create a named key with + New Key — the full value is shown once after creation. A Copy button appears in the table for keys created in this browser session.

Name Key (prefix) Created
Loading...

Global Agent Defaults

Default beacon interval applied to newly enrolled agents.
Per-agent overrides can be set by clicking the Beacon value in the Agents table.

[SAVED]

Logging

Configure log retention and the minimum severity level to record.

[SAVED]
[APPLIED] Changes take effect immediately, reset on server restart

Database Backup

Last backup: -
Folder: -
[SAVED]
Loading...

Calibration Governance

Evidence governance
Real execution is never automatic Gold. Every governed case must pass human review before entering the versioned calibration corpus. The original system label is preserved across any human override. Provider coverage gap (sensor lacks evidence) is kept distinct from Morgana ingestion gap (evidence exists but Morgana fails to normalize/persist it).

Morgana Brain

Cognitive vs Endpoint Agents
Cognitive Agents are internal Morgana AI specialists (Script / Test Result / Detection / Red / Report / Executive / Critic) that reason over evidence. Endpoint Agents are the Go/Windows/Linux services installed on targets that execute jobs. The Executive Brain never dispatches Endpoint Agent jobs in ANALYSIS_ONLY / PLAN_ONLY modes, and this kernel never dispatches them at all. Raw hidden chain-of-thought is never persisted — only structured decision evidence.

Cognitive Foundry

Cognitive Foundry
The Foundry discovers, acquires, benchmarks and specialises base models. Arena evidence outranks brand claims. No trust_remote_code=True. No repository code execution. Adapters are learned specialist capabilities. Cognitive Agents are runtime organs built from model + adapter + role.

Self Development

Controlled self-development
Morgana observes its own cognitive performance, creates Growth Needs, decides the appropriate improvement (routing, Skill, model switch, adapter, Agent clone, new Agent, or more data), and builds/evals it inside the SANDBOX_AUTONOMOUS policy envelope. Normal growth happens through routing, memory, Skills, models, adapters and Cognitive Agent definitions — never arbitrary source-code self-rewriting. No Endpoint Agent jobs are dispatched, and dynamic Agents never exceed ANALYSIS_ONLY authority.

Intelligence Heritage

Intelligence Heritage
Morgana learning does NOT automatically leave the local installation. Validated knowledge is promoted by an operator through exactly one of three inheritance channels: the private Intelligence repository (Cognitive Agents + Skills manifests), the private Model Artifact Registry (adapters/models resolved by manifest + hash, never Git), and the public Camelot repository (sanitized generalized Variants via branch + PR, never a direct push to main). Every outbound action requires an explicit preview and approval.

Execution Strategy

Chain Composer

Review Case

Create New API Key

[SUCCESS] New key created

[WARNING] Copy this key now — it will NOT be shown again.

Deploy Agent - One-liner Installer

Paste the command below on the target machine (one line). It downloads the agent binary directly from this server and installs the service. No files to transfer manually.

[WINDOWS] - PowerShell 5.1+ (run as Administrator)
[LINUX] - bash (run as root)
[INFO] Agent binaries must be compiled before deployment. Run .\build\build-agents.ps1 from the Morgana root to build both Windows & Linux binaries (requires Go).

Uninstall Agent -

Run these commands on the target machine to stop and remove the Morgana agent service. After running them, click the x button in the agent row to remove the record from this server.

[WINDOWS] - PowerShell (run as Administrator)
Stop-Service MorganaAgent -Force sc.exe delete MorganaAgent Remove-Item "$env:ProgramData\Morgana\agent" -Recurse -Force Remove-Item "$env:ProgramData\Morgana\work" -Recurse -Force
[LINUX] - bash (run as root)
systemctl stop morgana-agent systemctl disable morgana-agent rm -f /etc/systemd/system/morgana-agent.service systemctl daemon-reload rm -f /usr/local/bin/morgana-agent rm -rf /etc/morgana /var/lib/morgana /var/log/morgana
[INFO] These commands only remove the agent from the target machine. To also remove the agent record from this server, click the x button in the agents table row.

Script

ⓘ Save Changes to persist edits and update the AI Review and Tags — both use the saved command. Use #{tag_key} format in the command for runtime values (e.g. #{listener_ip}).
Frida Mobile Target
Manual procedure - not executable by Morgana
Open pinned CTID source procedure
Complete this action outside Morgana in the authorized lab. A Chain stops at this checkpoint; after completion, run the next applicable phase or customized Chain.
Review Script with AI

The agent will review the current command, explain what the technique does, list requirements and risks, and suggest improvements. Press Apply to apply the suggested improvements to the Command and Cleanup Command fields.

Execute on Agent


            
            
Output Analysis

The agent found an issue and suggests a fix. Press Fix Script to update the Command fields.

Loading...

▶ Chain Execution

Chain: Agent:

⚡ Red Team Attack

Script

⚠ Red Team

Script: Agent: Max iterations: Timeout (s):
Context for Red Team (env info: IPs, hostnames, tenant IDs...)
Current Command:
(waiting for output...)

Tags

Click ⚡ Ask AI to get suggested values for each tag. Click a suggestion chip to apply it.

Console - Agent

Select Script

TCodeNameTacticExecutorPlatform
Loading...

Execution Log

Select Chain

NameDescriptionNodes
Loading...

Chain

Loading...

Compose

Campaign Execution Log

Execute

Execute Selected

Items without an assigned agent:

    Report Style

    COLOURS
    TYPOGRAPHY
    BRANDING

    Configure Adapter

    Secrets
    Values are encrypted with a local Fernet key and stored on disk separately from the config. They are never returned by the API. Leave blank to keep the current stored value.

    Detection Details

    Morgana Detection Assurance Intelligence Report

    Generate an AI-only, evidence-grounded assessment of detection assurance, root causes, priorities, SOC actions and retest criteria. Use Export Report ZIP for detailed evidence.

    Related Detections

    Related Tests