Morgana Documentation
User guidance, administration procedures, community resources, and product information.
Morgana is free and open-source software licensed under GNU AGPL v3. It can execute adversary-emulation commands with Agent service privileges. Use it only on systems covered by explicit written authorization and approved rules of engagement.
Dashboard
Recent Tests
| TCode | Type | Name | Agent | State | Exit | Started | Duration |
|---|---|---|---|---|---|---|---|
| Loading... | |||||||
Agent Status
Agents
| Name | Hostname / PAW | Platform | OS | Status | Last Seen | Beacon | Tags | Version | ||
|---|---|---|---|---|---|---|---|---|---|---|
| Loading... | ||||||||||
Industrial Lab
Mobile Lab
Provision and manage Android and iOS security test environments
Scripts
| TCode | Name | Tactic | Executor | Platform | Source | Tags | Actions | |
|---|---|---|---|---|---|---|---|---|
| Loading... | ||||||||
Tests
| Date | TCode | Type | Name | Script | Agent | State | Status | Detection Fabric Verdict | Sync | Detections | Exit Code | Duration | Actions | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Loading... | ||||||||||||||
Chains
| Name | Description | Nodes | Updated | ||
|---|---|---|---|---|---|
| Loading chains... | |||||
Recent Executions
| Chain | Agent | State | Started | Finished | |
|---|---|---|---|---|---|
| No executions yet | |||||
Campaigns
| Name | Description | Chains | Updated | ||
|---|---|---|---|---|---|
| Loading campaigns... | |||||
Recent Executions
| Campaign | Agent | State | Started | Finished | |
|---|---|---|---|---|---|
| No executions yet | |||||
Assessment Snapshots
Snapshots
| Assessment | Organisation | Area | Created | Baseline | Tests | Assurance | Snapshot | Report | Actions |
|---|---|---|---|---|---|---|---|---|---|
| Loading... | |||||||||
Users
| Name | Alias | Role | Provider | Enabled | Workspaces | Tags | ||
|---|---|---|---|---|---|---|---|---|
| Loading... | ||||||||
Server Logs
| Timestamp | Level | Source | Message |
|---|---|---|---|
| Click "Last 30 min" or set filters and click Apply. | |||
AI Mission Engine
Engine Status
Active Provider
Morgana AI — Local
How to use Morgana AI ▸
- Start the engine
- Install or verify a specialist model
- Assign that model to a compatible Agent
- Run the self-test
- Use Morgana normally
You can use Morgana AI for one Agent and a cloud/general provider for another. Starting Morgana AI does not change existing Agent provider selections.
AI Agents
Each agent can use a different AI providerAgent Prompts
All 21 AI agent prompts are shown here. Click "Edit" to customise any prompt — the next agent call will use your version. "Reset" restores the hardcoded default.
Adapters
Vendor API Adapters
| Adapter | Status | Last Sync | Statistics | ||
|---|---|---|---|---|---|
| Empty | |||||
Tick the rows you want to ingest, then press Sync Selected for specific Vendor Adapters, or use Sync All Adapters to run all enabled Vendor Adapters and all enabled Universal folder adapters at once. Only adapters that are both Enabled and Configured will actually run; the others are skipped silently. Secrets (client secret / token) are stored encrypted on disk (Fernet) and never returned through the API.
Universal Adapter (Morgana JSON)
Reads *.json files in Morgana JSON format from enabled folders. Successfully imported files are deleted.
| Name | Folder | Status | Last State | Last Run | Actions |
|---|---|---|---|---|---|
| Loading... | |||||
Universal Adapter Evidence
Evidence ingested through Universal Adapter sources such as folder-based Morgana JSON integrations.
| Time | Integration | Host / OS | User | Process | Command line | Severity | Threat / Title | Techniques |
|---|---|---|---|---|---|---|---|---|
| Loading... | ||||||||
Global Detection & Telemetry Evidence
All evidence currently stored in Detection Fabric across vendor adapters, test-scoped telemetry retrieval and Universal Adapters.
| Detection ID | First Activity (UTC) | Last Activity (UTC) | Source | Type | Title | Severity | Status | Techniques | Events | Entities | Test Association | Actions |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Empty | ||||||||||||
Automation Center
Schedules
| Name | Target | Trigger | Mode | Status | Last Run | Next Run | Runs | |
|---|---|---|---|---|---|---|---|---|
| Loading... | ||||||||
Morgana Intelligence Lab
Admin
Server Information
The DNS name is used in one-liner installer commands. If empty, the server IP address is used. The IP address is read-only (detected from the host network interface).
API Keys
Keys authorize requests to this Morgana server. Create a named key with + New Key — the full value is shown once after creation. A Copy button appears in the table for keys created in this browser session.
| Name | Key (prefix) | Created | |
|---|---|---|---|
| Loading... | |||
Global Agent Defaults
Default beacon interval applied to newly enrolled agents.
Per-agent overrides can be set by clicking the Beacon value in the Agents table.
Logging
Configure log retention and the minimum severity level to record.
Database Backup
-Calibration Governance
Real execution is never automatic Gold. Every governed case must pass human review before entering the versioned calibration corpus. The original system label is preserved across any human override. Provider coverage gap (sensor lacks evidence) is kept distinct from Morgana ingestion gap (evidence exists but Morgana fails to normalize/persist it).
Morgana Brain
Cognitive Agents are internal Morgana AI specialists (Script / Test Result / Detection / Red / Report / Executive / Critic) that reason over evidence. Endpoint Agents are the Go/Windows/Linux services installed on targets that execute jobs. The Executive Brain never dispatches Endpoint Agent jobs in ANALYSIS_ONLY / PLAN_ONLY modes, and this kernel never dispatches them at all. Raw hidden chain-of-thought is never persisted — only structured decision evidence.
Cognitive Foundry
The Foundry discovers, acquires, benchmarks and specialises base models. Arena evidence outranks brand claims. No
trust_remote_code=True. No repository code execution. Adapters are learned specialist capabilities.
Cognitive Agents are runtime organs built from model + adapter + role.
Self Development
Morgana observes its own cognitive performance, creates Growth Needs, decides the appropriate improvement (routing, Skill, model switch, adapter, Agent clone, new Agent, or more data), and builds/evals it inside the
SANDBOX_AUTONOMOUS policy envelope. Normal growth happens through routing, memory, Skills, models,
adapters and Cognitive Agent definitions — never arbitrary source-code self-rewriting. No Endpoint Agent jobs
are dispatched, and dynamic Agents never exceed ANALYSIS_ONLY authority.
Intelligence Heritage
Morgana learning does NOT automatically leave the local installation. Validated knowledge is promoted by an operator through exactly one of three inheritance channels: the private Intelligence repository (Cognitive Agents + Skills manifests), the private Model Artifact Registry (adapters/models resolved by manifest + hash, never Git), and the public Camelot repository (sanitized generalized Variants via branch + PR, never a direct push to
main). Every outbound action requires an explicit preview and approval.