mrkeyoor.com_
Wed 30 Sept 15:08 UTC
Automationevaluationupdated 30 Sept 2026

ARES review

ARES is a self-hosted platform for authorized red-team and purple-team engagements. It combines scoped offensive modules, campaign controls, attack-path graphs, credentials and evidence storage, operator roles, reports, an API, and an optional MCP gateway in one system.

Verdict

Our ARES run installed 196 packages, built in 9 seconds, and reached only 22% of its tests before the 900-second limit, while pip-audit found 1 known vulnerability. That is enough to justify a lab evaluation, not a client engagement. Experienced teams may value its campaign controls and unusually specific security model, but they should prove the OS-level containment and finish the suite on their own deployment before any live target enters scope.

We ran it

Lab card: what happened when we ran ARESScreenshot of ARES (github.com/Mafifrizi/ARES)
Install✓ · 73s196 packages · 499 MB
Build✓ · 9s
Tests✗ timed out · 900sran, no count parsed
Known vulns1(pip-audit)
Repo529 files~273,772 lines of source · 32.1 MB · 1 CI workflows · tests dir

Answers from our run

Does ARES build from source?

Dependencies installed in 73 seconds (196 packages), and the build succeeded in 9 seconds. We cloned commit 49bd11a into a clean Debian container with 3 CPUs and no project-specific setup.

Do ARES's tests pass?

We could not finish them: the suite was still running after 15 minutes in our container.

Does ARES have known vulnerabilities in its dependencies?

pip-audit flagged 1 known advisory in the dependency tree at the time of our run.

Who should not use ARES?

Beginners learning penetration testing: ARES can run credential access, lateral movement, and evasion modules, so it assumes legal authorization and experienced operators.

What are the alternatives to ARES?

Apache CALDERA, Atomic Red Team, Metasploit Framework. Our ARES run installed 196 packages, built in 9 seconds, and reached only 22% of its tests before the 900-second limit, while pip-audit found 1 known vulnerability.

Setup2/5The build passed, but 196 packages and host security controls add work
Docs5/5The security model states exact enforcement limits and deployment duties
Community3/5554 stars and a September 30 push, with 8 open dependency PRs
Maturity2/5v6.0.0 is broad, but our 900-second suite stopped at 22%

Who it’s for

Internal red teams and security consultancies that need repeatable, authorized campaign workflows with an audit trail.
Purple teams that want scoped attack modules, MITRE ATT&CK mapping, and reports in the same interface.
Security engineers prepared to validate network containment on their own operating system and deployment topology.
Teams that want to connect an AI client through MCP while retaining human approval for live actions.

Who it’s NOT for

Beginners learning penetration testing: ARES can run credential access, lateral movement, and evasion modules, so it assumes legal authorization and experienced operators.
Buyers who need a proven zero-collateral guarantee: the security model says several kernel firewall, namespace, and privilege boundaries were not verified in a live elevated runtime.
Teams unwilling to manage signing keys, an encryption key, TLS, database state, operator accounts, scope lists, and stored customer evidence.
Release gates that require a completed test suite and a clean dependency audit: our tests reached 22% before timing out, and pip-audit found 1 known vulnerability.

Setup reality

Our commit 49bd11a checkout installed 196 Python packages in 73 seconds and used 499 MB. The build succeeded in 9 seconds. Tests reached 22% and were still running when our 900-second cap expired. Pip-audit reported 1 known vulnerability.

The documented development path also needs Node.js for the React frontend. A real deployment needs fresh session and encryption secrets, a changed initial admin password, HTTPS, durable database storage, scope definitions, and careful operator roles. Claude, OpenAI, or Ollama is optional for planning.

Some advertised containment depends on the host. The security model says OS firewall rules and namespace isolation need elevated Linux or Windows execution, while Python socket hooks cannot contain every external binary. Strict mode rejects configurations that lack the requested boundary, which is safer than silently downgrading but raises the operating burden.

ARES puts campaign governance around offensive modules

ARES tries to replace a folder of red-team scripts with an operator system. Campaigns carry approved CIDR ranges, noise limits, findings, evidence, and credentials. Modules cover Active Directory, Windows, Linux, cloud, and network work, while an attack graph maps possible pivots. Operators can stage dry runs, execute approved work, watch events, and turn results into PDF, HTML, Markdown, or JSON reports.

The README counts 66 active execution modules among 70 catalogued entries and maps them to more than 60 MITRE ATT&CK techniques. A React dashboard sits over a FastAPI backend, SQLite or PostgreSQL storage, encrypted vault records, role-based access, and WebSocket telemetry. Optional Claude, OpenAI, or Ollama planning can propose a sequence. An MCP gateway exposes 9 tools with short-lived human confirmation for live offensive actions.

What happened when we ran it

Our run cloned commit 49bd11a into a fresh unprivileged Debian container with 3 CPUs and 8 GB of RAM. Installing the Python project succeeded in 73 seconds, pulled 196 packages, and occupied 499 MB. The build completed in 9 seconds. Pip-audit reported 1 known vulnerability; the supplied measurement does not identify its package or severity, so that requires separate triage.

The test command did not finish within 900 seconds. Its last output showed steady progress through Windows enumeration, WMI cleanup, pivot handling, Active Directory behavior, dependency preflight, adaptive OPSEC, ADCS, and API endpoint tests. The counter reached 22%, with no failure shown in the tail we received. That does not establish a passing suite. It means this broad test run needs more than our 15-minute limit.

The repository contained 529 files, about 273,772 lines of source, and occupied 32.1 MB before installation. Our scan found a tests directory, one CI workflow, and no Dockerfile. ARES documents Docker as one possible isolation tier, yet the checkout did not provide a root Dockerfile for a ready-made deployment. The measured build is encouraging; the unfinished suite and audit finding prevent a clean release verdict.

The security model is more useful than the zero-risk slogan

ARES says every campaign is guarded by approved scope and that strict mode fails closed. Python socket interception covers standard library connections, while elevated host firewall rules can add OS enforcement. The security document deserves credit for saying exactly where those controls stop. Compiled extensions and external binaries can bypass Python hooks, and online Docker bridge traffic is not scope-restricted for external binaries without an explicit exception.

Several boundary checks remain unproved on a live privileged host. The matrix marks Linux Netfilter, Windows Defender Firewall, subprocess network namespaces, and privilege dropping as not verified at actual runtime because they require root, administrator access, or kernel support. Mocked command tests prove construction and state transitions. They do not prove that an offensive packet cannot escape. Any claim of zero collateral risk is therefore stronger than the project's own evidence.

A real deployment needs security operations, not one command

The Windows quick start asks for Python 3.12, Node.js 18 or newer, a virtual environment, Python extras, frontend dependencies, and a browser path for PDF smoke testing. It then starts a development dashboard at 127.0.0.1:5173. The documented initial user is admin, with Admin123456! as the default when ARES_DEFAULT_ADMIN_PASSWORD is absent. Change that before exposing any interface beyond loopback.

Production adds more. The security guide requires separate session-signing and AES-256-GCM encryption secrets, stable backup of the encryption key, HTTPS or WSS through a reverse proxy, protected database storage, and TLS plus authentication for Redis when used. Operators must choose isolation tiers and supply dedicated sandbox identities where UID-wide firewall rules might affect unrelated processes. This is security infrastructure carrying harvested hashes and client evidence, not a disposable scanner.

MCP approval reduces risk without removing operator duty

ARES can connect Cursor, Claude Desktop, Windsurf, Cline, Zed, and other MCP clients. Its setup writes the active Python environment into the client's configuration. Read operations include campaign state and scope checks. A live action uses a single-use HMAC confirmation token with a 60-second life, and the two-pane monitor gives a person an approve or reject control.

That design keeps an AI-generated instruction from immediately becoming offensive traffic. It cannot decide whether a target is legally authorized or whether a module is safe for a fragile production host. An operator still owns the written permission, CIDR boundaries, credentials, noise budget, and final action. Teams that do not already have that discipline should start with isolated Atomic Red Team checks rather than an agent-connected execution surface.

September code activity is newer than the June release

GitHub showed 554 stars, a September 30 push, and 8 open issues and pull requests combined. A separate search returned 0 open issues, so all 8 listed items were pull requests. Their titles were dependency updates, with activity on September 23 and 30. Release v6.0.0 was published June 22. The newer push and PR activity mean the older release date alone is not evidence of abandonment.

ARES is ambitious enough to demand an evidence-led adoption. Our 9-second build proves the package can assemble in a small Debian sandbox, while 22% test progress after 900 seconds shows that full validation is much heavier. Use a segregated lab, resolve the single audit finding, finish the entire suite, and test the real kernel boundary on the exact hosts that will run modules. Only then consider a tightly scoped internal exercise.

Alternatives

ProjectWhat it isPick it when
Apache CALDERAAn adversary-emulation platform built around operations, agents, abilities, and plugins.pick this instead when established adversary emulation and a plugin ecosystem matter more than ARES's integrated vault, reports, and MCP approval flow.
Atomic Red TeamA library of small portable tests mapped to MITRE ATT&CK techniques.pick this instead when you want focused detection tests that can be reviewed and run individually without adopting a campaign platform.
Metasploit Framework gh↗A long-running framework for exploit development and authorized penetration testing.pick this instead when module depth and hands-on exploitation matter more than dashboards, campaign governance, and generated reports.
BloodHoundAn attack-path analysis tool centered on identity relationships and privilege routes.pick this instead when Active Directory and identity attack paths are the job, rather than running a broader engagement platform.

What people are saying

  1. [github-trending] Mafifrizi/ARES
  2. [velocity-scout] miuuyy/Astra-Ares

Sources

  1. ARES README
  2. ARES security model
  3. ARES v6.0.0 release
  4. ARES module catalog

More automation reviews

appium · huashu-mac-use · cloudflare-turnstile-solver · stop-stutter · warp-masque-actions · ansible · the whole board →