All resources

Security models

Open-weight security-specialist LLMs — several served right here.

8 shown
  1. CyberSecQwen-4Bclassification

    Apache-2.0 4B CTI/CWE specialist for CVE-to-CWE mapping and cheap classification, transparent about its ~14,776-example LoRA recipe and easy to QLoRA fine-tune.

    In catalog →
  2. Foundation-Sec-8B-Reasoningtriage/reasoningserved here

    Cisco/Foundation AI Llama 3.1 8B security-reasoning model for vulnerability triage, attack-path reasoning, and CWE mapping, with an official 4.92 GB Q4_K_M GGUF.

    In catalog →
  3. Llama-Primus-Reasoningknowledge/criticserved here

    Trend Micro 8B security-reasoning model for security knowledge, report review, and mitigation advice; a Foundation-Sec challenger.

    In catalog →
  4. RedSage-Qwen3-8B-DPOoffensive-knowledgeserved herelicence

    Qwen3-8B model trained on 11.8B cyber tokens for broad offensive-security knowledge, CLI/tool interpretation, and recon triage.

    In catalog →
  5. Cisco 150M Apache-2.0 classifier (not a chatbot) for cheap first-pass filtering and ranking of suspicious code snippets; runs on CPU.

    Open ↗
  6. VulnLLM-R-7Bsource-analysisserved here

    Apache-2.0 Qwen2.5 derivative specializing in source-code vulnerability detection and data/control-flow reasoning across C/C++/Python with CodeQL-assisted context.

    In catalog →
  7. RedSageoffensive-knowledgedual-use

    An open-weight 8B language model specialized for cybersecurity tasks, trained on 11.8B tokens of curated security content and 266k multi-turn security dialogues, distributed on Hugging Face with vLLM deployment support. Ships an accompanying evaluation suite (RedSage-Bench, 30,000+ MCQs) for measuring cybersecurity capability.

    Open ↗
  8. Vext-labs-7Boffensive-knowledgedual-use

    An open-weight 7B model built to support autonomous penetration testing: it interprets output from 25+ security tools (nmap, sqlmap, nuclei, Burp, etc.), plans multi-step attack strategies, classifies vulnerabilities, and generates remediation guidance. Apache-2.0, trained on data from authorized engagements against intentionally-vulnerable apps and bug-bounty targets, with documented run/target counts and responsible-use guidelines.

    Open ↗