Can LLMs Hack Enterprise Networks? --- RCR Package

Andreas Happe, Jürgen Cito · arXiv (Cornell University) · 2025

Cochise This is the software of a research project that investigates the use of LLMs for offensive security, especially their efficacy for exploiting vulnerabilities within common Microsoft Windows Active Directory (AD) enterprise networks. To evaluate the efficacy and efficiency of LLMs we wrote a python-based prototype, cochise, that can autonomously perform penetration-testing against enterprise networks. The results of our investigation were accepted to the TOSEM journal and are also available as pre-print on arxiv. The source code can be found on github. This replication package includes: a container cochise_docker.tar with the software used during evidence generation for our paper. a container cochise_replay_analysis.tar with a later version of the software including analysis scripts as well as gathered evidence from the first container. collected evidence (testruns_logs.zip) used for writing the paper installation instructions for both required infrastructure (REQUIREMENTS) as well as for the prototype itself (INSTALL). The prototype can either be installed manually or used through the containers. INSTALL also includes examples for using the provided containers for evidence generation and analysis. a pre-configured VMWare virtual machine containing Kali Linux. This can be used as an attacker machine within the testbed. While installation instructions for the virtual machine are also included within REQUIREMENTS, the pre-packaged VM (kali-linux-2025.3-vmware-amd64*) is provided for convenience purposes.

Read the paper · More papers on PaperTik