0
Agents Online
0
Tests Running
0
Tests Passed
0
Tests Failed
0
Excalibur Scripts

Recent Tests

TCode Type Name Agent State Exit Started Duration
Loading...

Agent Status

Loading agents...
-
Online
-
Offline / Stale
-
Total
-
Windows
-
Linux
-
macOS
-
Tagged
-
Avg Beacon
Name Hostname / PAW Platform OS Status Last Seen Beacon Tags Version
Loading...
-
Services Available
-
Installed
-
Running
-
Lab Hosts
-
Active Labs
Loading Industrial Lab overview...
-
Devices
-
Running
-
Ready
-
Hosts
-
Apps
-
Instances
Loading Mobile Lab overview...
[*] Excalibur Script Packs — Certified adversary emulation packs from Camelot CDN
[INFO] Click Refresh catalog to load available packs.
-
Total Scripts
-
Unique TCodes
-
Tactics
-
Windows
-
Linux
-
macOS
-
Excalibur
-
Custom
-
Modified
-
PowerShell
-
CMD / Bash
TCode Name Tactic Executor Platform Source Tags Actions
Loading...
Success Rate-
Avg Duration-
Unique TCodes-
Agents-
Scripts Used-
Detection Fabric AI
- Reviewed
|
- In Review
|
- Pending
|
- Blocked
Detection Intelligence
-Validated Tests
-Confirmed
-Possible
-No Telemetry
-Not Detected
-Inconclusive
-Errors
Date TCode Type Name Script Agent State Status Detection Fabric Verdict Sync Detections Exit Code Duration Actions
Loading...
-
Total
-
With Scripts
-
Empty
-
Total Nodes
-
Avg Nodes
-
Updated Today
Name Description Nodes Updated
Loading chains...
Chain Agent State Started Finished
No executions yet
-
Total
-
With Chains
-
Empty
-
Total Chain Refs
-
Avg Chains
-
Updated Today
Name Description Chains Updated
Loading campaigns...
Campaign Agent State Started Finished
No executions yet

Snapshots

Assessment Organisation Area Created Baseline Tests Assurance Snapshot Report Actions
Loading...

Workspaces

Loading workspaces...

Tag Definitions

Label Key Value Namespace Type Flags (?) Usage
Loading...
NameEmailAliasRole ProviderEnabledWorkspacesTags
Loading...
-
Timestamp Level Source Message
Click "Last 30 min" or set filters and click Apply.

Engine Status

Loading...

Active Provider

Provider
-
Model
-
Auth
-

Morgana AI — Local

Powered by the Morgana Intelligence Engine (MIE)
LOCAL ONLY — No external AI data egress
Engine Status
Loading...
Check This Computer
Local AI Self-Test
Performance Benchmark
Morgana Specialist Models
Installed Intelligence Packs
How to use Morgana AI ▸
  1. Start the engine
  2. Install or verify a specialist model
  3. Assign that model to a compatible Agent
  4. Run the self-test
  5. Use Morgana normally

You can use Morgana AI for one Agent and a cloud/general provider for another. Starting Morgana AI does not change existing Agent provider selections.

AI Agents

Each agent can use a different AI provider
Apply same provider to ALL agents at once
S
Script Agent
script_agent
Analyses Red Team scripts. Explains techniques, lists requirements and risks. Called from the Scripts UI.
T
Test Result Agent
test_result_agent
Analyses test execution output. Determines BLOCKED / INTERCEPTED / ERROR / FAILED / FINISHED status.
D
Detection Agent
detection_agent
Determines ATTACK_DETECTED by cross-referencing test data with detection fabric evidence.
P
Intelligent Report
report_agent
Produces a staged AI Detection Assurance assessment with evidence-grounded findings, priorities, SOC actions and retest criteria.
R
Red Team
red_agent (Orchestrator + Attacker + Analyst)
3 AI agents working together: Orchestrator decides strategy, Attacker generates real attack code, Analyst judges results. Loops until BLOCKED or FINISHED.

Agent Prompts

All 21 AI agent prompts are shown here. Click "Edit" to customise any prompt — the next agent call will use your version. "Reset" restores the hardcoded default.

Status: - | Adapters: - | Total Detections: - | Ingestion Interval: - min

Vendor API Adapters

Adapter Status Last Sync Statistics
Empty

Tick the rows you want to ingest, then press Sync Selected for specific Vendor Adapters, or use Sync All Adapters to run all enabled Vendor Adapters and all enabled Universal folder adapters at once. Only adapters that are both Enabled and Configured will actually run; the others are skipped silently. Secrets (client secret / token) are stored encrypted on disk (Fernet) and never returned through the API.

Reads *.json files in Morgana JSON format from enabled folders. Successfully imported files are deleted.

Name Folder Status Last State Last Run Actions
Loading...

Universal Adapter Evidence

Evidence ingested through Universal Adapter sources such as folder-based Morgana JSON integrations.

TimeIntegrationHost / OSUser ProcessCommand lineSeverityThreat / TitleTechniques
Loading...

Global Detection & Telemetry Evidence

All evidence currently stored in Detection Fabric across vendor adapters, test-scoped telemetry retrieval and Universal Adapters.

Detection ID First Activity (UTC) Last Activity (UTC) Source Type Title Severity Status Techniques Events Entities Test Association Actions
Empty

Schedules

Name Target Trigger Mode Status Last Run Next Run Runs
Loading...
0
Approved Corpus
0
Pending Review
0
Hard Cases
0
Human Overrides
0
Datasets
0
Active Runs
None
Production Model
None
Latest Candidate
Fixtures / quick actions:

Server Information

-
IP Address
-
Machine Name
-
Platform
-
Server Port
-
Memory Used %
-
Memory Free GB
-
Disk Used %
-
Disk Free GB

The DNS name is used in one-liner installer commands. If empty, the server IP address is used. The IP address is read-only (detected from the host network interface).

API Keys

Keys authorize requests to this Morgana server. Create a named key with + New Key — the full value is shown once after creation. A Copy button appears in the table for keys created in this browser session.

Name Key (prefix) Created
Loading...

Global Agent Defaults

Default beacon interval applied to newly enrolled agents.
Per-agent overrides can be set by clicking the Beacon value in the Agents table.

Logging

Configure log retention and the minimum severity level to record.

Changes take effect immediately, reset on server restart

Database Backup

Last backup: -
Folder: -
Loading...
Evidence governance
Real execution is never automatic Gold. Every governed case must pass human review before entering the versioned calibration corpus. The original system label is preserved across any human override. Provider coverage gap (sensor lacks evidence) is kept distinct from Morgana ingestion gap (evidence exists but Morgana fails to normalize/persist it).
Cognitive vs Endpoint Agents
Cognitive Agents are internal Morgana AI specialists (Script / Test Result / Detection / Red / Report / Executive / Critic) that reason over evidence. Endpoint Agents are the Go/Windows/Linux services installed on targets that execute jobs. The Executive Brain never dispatches Endpoint Agent jobs in ANALYSIS_ONLY / PLAN_ONLY modes, and this kernel never dispatches them at all. Raw hidden chain-of-thought is never persisted — only structured decision evidence.
Cognitive Foundry
The Foundry discovers, acquires, benchmarks and specialises base models. Arena evidence outranks brand claims. No trust_remote_code=True. No repository code execution. Adapters are learned specialist capabilities. Cognitive Agents are runtime organs built from model + adapter + role.
Controlled self-development
Morgana observes its own cognitive performance, creates Growth Needs, decides the appropriate improvement (routing, Skill, model switch, adapter, Agent clone, new Agent, or more data), and builds/evals it inside the SANDBOX_AUTONOMOUS policy envelope. Normal growth happens through routing, memory, Skills, models, adapters and Cognitive Agent definitions — never arbitrary source-code self-rewriting. No Endpoint Agent jobs are dispatched, and dynamic Agents never exceed ANALYSIS_ONLY authority.
Intelligence Heritage
Morgana learning does NOT automatically leave the local installation. Validated knowledge is promoted by an operator through exactly one of three inheritance channels: the private Intelligence repository (Cognitive Agents + Skills manifests), the private Model Artifact Registry (adapters/models resolved by manifest + hash, never Git), and the public Camelot repository (sanitized generalized Variants via branch + PR, never a direct push to main). Every outbound action requires an explicit preview and approval.