Open Source Security Framework

K.O.D.A.

Kinetic Operative Defense Agent

Autonomous vulnerability detection, real-time monitoring, and automated response. Pure Python. Zero dependencies. Works with any LLM.

Pipeline

From signal to action.

01

Scan

7 scanners. Unified output.

02

Enrich

NVD, CISA KEV, EPSS scores.

03

Correlate

Chain events across time.

04

Respond

Block, kill, quarantine.

05

Report

SARIF 2.1.0. Any format.

7

Scanners

23

LLM Tools

10k+

Lines

Zero

Dependencies

Capabilities

Built for real infrastructure.

01

Scanner Integration

Wraps Semgrep, Trivy, Bandit, Gitleaks, Nuclei, OSV-Scanner, and Nmap. Run any combination, get unified findings.

02

Multi-Agent Architecture

Five hardcoded security roles — Sentinel, Recon, Analyst, Operator, Auditor — each with scoped permissions and audit trails.

03

Event Correlation

Stateful rule engine chains events across time windows. Built-in detection for brute force, port scans, cryptominers, privilege escalation.

04

Active Response

Automated, reversible containment — block IPs, kill processes, quarantine files, disable accounts. Time-boxed with auto-reversal.

05

Guardian Monitor

Real-time file integrity monitoring, auth log analysis, suspicious process detection, and anomalous network connection alerting.

06

SARIF 2.1.0

Full SARIF parser and generator. Import from any tool, export for GitHub Code Scanning, VS Code, and CI/CD pipelines.

terminal
$curl -fsSL koda.vektraindustries.com/install | bash
$koda scan ./my-project
$koda guard

Secure your systems.

View on GitHub

MIT Licensed · Built by Vektra Industries