151 1 month ago

Neo is an open-weights 9B parameter cybersecurity AI model featuring a 256K token context window. Optimized for consumer GPUs (6GB VRAM), it performs offline threat hunting, tool-assisted penetration testing with zero API cost.

tools thinking
ollama run C4YP70N1C/neo

Applications

Claude Code
Claude Code ollama launch claude --model C4YP70N1C/neo
OpenCode
OpenCode ollama launch opencode --model C4YP70N1C/neo
Hermes Agent
Hermes Agent ollama launch hermes --model C4YP70N1C/neo
OpenClaw
OpenClaw ollama launch openclaw --model C4YP70N1C/neo

Models

View all →

1 model

neo:latest

5.8GB · 256K context window · Text · 1 month ago

Readme

Local Autonomous Cybersecurity & Threat Intelligence Agent

262,144 Context Window. 9B Parameters. Offline Threat Analysis on a 6GB VRAM GPU.

Neo is a specialized, open-weights model designed for local offensive and defensive cybersecurity operations. Built with a massive 256K context window, neo ingests massive log files, full-repository source code, packet captures, and dynamic threat intelligence feeds running 100% offline on consumer-grade hardware like an RTX 3060 6GB.

neo.jpeg


Core Security Capabilities

  • Full-Repository Source Code Auditing: Feed entire codebases in a single prompt to identify OWASP Top 10 vulnerabilities (XSS, SQLi, IDOR, SSRF, RCE) and hardcoded secrets.
  • Massive Log & SIEM Parsing: Analyze gigabytes of raw Apache, Nginx, Linux auth, and Sysmon logs to pinpoint threat vectors and anomalous behavior.
  • Reverse Engineering & Malware Decompilation: Parse disassembled binaries, assembly snippets, and obfuscated JavaScript to reconstruct malware execution flows.
  • Network & PCAP Packet Analysis: Ingest raw packet captures and Wireshark dumps to detect unauthorized C2 traffic, exfiltration attempts, and lateral movement.
  • 100% Private Air-Gapped Operation: Execute sensitive SOC, red-team, or threat hunting tasks offline without sending proprietary code or user data to external cloud APIs.

Hardware Specs

  • Base Model: Qwen 3.8 9B (Qwen3.8-9B-Q4_K_M.gguf)
  • Engine Architecture: qwen35 (GGUF execution kernel)
  • Parameters: 9 Billion
  • Context Length: 262,144 Tokens (~256K)
  • Minimum VRAM: 6 GB (Full GPU offload via Q4_K_M GGUF)
  • System Memory: 16 GB RAM
  • Primary Domains: Vulnerability Detection, Threat Hunting, Log Analysis, Static Code Analysis

Quickstart Guide

Pull and run via Ollama CLI:

ollama run C4YP70N1C/neo

Maximize Context Window in Ollama

To unlock the full 256K context for deep log and source code scans, create a custom Modelfile:

  1. Create a file named Modelfile:
# 1. BASE MODEL SOURCE
FROM C4YP70N1C/neo

# 2. RUNTIME PARAMETERS
# Unlocks full 256K context window and optimizes precision for security tasks
PARAMETER num_ctx 262144
PARAMETER temperature 0.2
PARAMETER top_p 0.95
PARAMETER top_k 20
PARAMETER repeat_penalty 1.1

# 3. CHAT TEMPLATE WITH DEEP TOOL-CALLING & THINKING CAPABILITIES
# Required for Ollama to automatically register 'tools' and 'thinking' tags
TEMPLATE """{{- if .System }}<|im_start|>system
{{ .System }}{{ if .Tools }}

# Tools Available
You have access to the following tools:
{{ .Tools }}

To execute a tool call, respond in JSON matching the specified tool schema.
{{ end }}<|im_end|>
{{ end }}{{- range .Messages }}<|im_start|>{{ .Role }}
{{ .Content }}{{ if .ToolCalls }}
{{ .ToolCalls }}{{ end }}<|im_end|>
{{ end }}<|im_start|>assistant
{{ if .Thinking }}<|thought|>
{{ .Thinking }}<|thought|>
{{ end }}"""

# 4. SYSTEM PROMPT & CORE OPERATIONAL PERSONA
SYSTEM """
You are Neo, an elite Cybersecurity Analyst and Operations Specialist built on the Qwen 3.8 9B architecture. You operate across all domains of the cybersecurity lifecycle—from offensive red teaming to defensive blue teaming and governance.

**Core Persona:**
* Direct, highly technical, and objective with zero operational fluff.
* Approach every query with a defense-in-depth mindset, analyzing problems through both attacker vectors and defender controls.

**Full Operational Scope:**

1. Application & Software Security (AppSec)
* Code Auditing: Static (SAST) and Dynamic (DAST) analysis across modern programming languages.
* Vulnerability Identification: OWASP Top 10, API security, logic flaws, memory safety issues, and insecure dependencies.
* Secure SDLC: Threat modeling (STRIDE/PASTA), secure coding standards, and CI/CD pipeline security.

2. Network & Infrastructure Security (NetSec)
* Architecture Review: Perimeter defense, zero-trust network architecture (ZTNA), segmentation, and VPN security.
* Protocol Analysis: Packet inspection, traffic analysis, and hardening protocols (DHCP/ARP/IGMP snooping, TLS, SSH).
* Device Hardening: Router, switch, firewall, and load balancer configuration audits and security baselines.

3. Cloud, Identity, & Infrastructure (CloudSec & IAM)
* Cloud Platforms: AWS, Azure, and GCP security configurations, containerization (Docker/Kubernetes) security, and IAC auditing.
* Identity & Access Management: Least-privilege access, PAM, OAuth/SAML, and Active Directory / LDAP security.

4. Offensive Security & Red Teaming (OffSec)
* Penetration Testing: Reconnaissance, exploitation mechanics, lateral movement techniques, and privilege escalation concepts.
* Security Research: Reverse engineering binaries, malware analysis, and vulnerability research.

5. Defensive Operations & Incident Response (Blue Team / SOC)
* Threat Hunting & Detection: Writing detection logic (YARA, Sigma, Snort/Suricata rules) and analyzing SIEM logs.
* Incident Response (IR): Triage, containment, eradication, recovery, forensic analysis, and root-cause reconstruction.

6. Governance, Risk, Compliance, & Strategy (GRC)
* Risk Assessments: Framework mapping (NIST CSF, ISO 27001, CIS Benchmarks, MITRE ATT&CK), threat modeling, and policy drafting.

**Response Structure & Formatting Rules:**
* **Executive Summary:** Provide a 1-2 sentence core finding, risk assessment, or direct answer up front.
* **Technical Breakdown:** Analyze the core vector, issue, or configuration details using exact terminology, CLI commands, or scripts where relevant.
* **Detection & Mitigation Rules:** Always include ready-to-use detection signatures (Sigma, YARA, Snort), remediation commands, or code patches.
* **MITRE ATT&CK Mapping:** Map relevant tactics, techniques, and IDs (e.g., T1059) to findings when analyzing threats or attacks.

**Operational Directives:**
* Provide full technical clarity, exact commands, configurations, and detection signatures whenever applicable.
* Balance technical depth with actionable, prioritized remediation strategies for immediate deployment.
"""
  1. Build and launch:

ollama create neo -f Modelfile
ollama run neo


Example prompt for Penetration Testing

Act as an expert penetration tester and offensive security specialist responsible for conducting controlled, thorough security assessments to identify vulnerabilities across target networks and applications before malicious actors can exploit them. In this role, you will execute a structured end-to-end testing workflow starting with passive and active reconnaissance to map the target’s attack surface, moving into systematic vulnerability scanning and fuzzing, proceeding to controlled exploitation and privilege escalation, and concluding with comprehensive risk analysis and reporting. Use project workspace path as ”/Your_Working_Directory/”. All testing artifacts, command logs, dynamic proofs-of-concept (PoC), and final reports must be securely stored in designated local directory structure “Project workspace path/{recon|scans|exploits|reports}/”. Every phase must strictly adhere to operational boundaries, where all authorized target assets are defined in scope.md and all off-limits IPs, domains, and systems are listed in outofscope.md. Those files are stored in project workspace path. find them and read it. Testing must observe strict operational controls, including custom request headers (User-Agent: Authorized-Pentest), a strict rate limit of 10 requests per second, and benign, payloads. Any critical vulnerability discovery or accidental service interruption must be immediately reported. Every assessment runs under full legal authorization guided strictly by the Written Scope Document, Rules of Engagement (RoE), and target owner Authorization Letters reviewed by legal counsel and strictly complies with established Non-Disclosure Agreements (NDA) and data destruction protocols to guarantee zero unauthorized disruption or data compromise. After, reviewing scope and outofscope outlines, make necessary folders and start your testings and make a bug-bounty report.


Ideal Cyber Use Cases

  • Autonomous SOC & SIEM Analytics: Continuously ingest multi-gigabyte telemetry streams including Sysmon, cloud audit trails (AWS CloudTrail, GCP Audit), Windows Event Logs, and EDR logs to correlate complex multi-stage attack chains and suppress alert fatigue.

  • Full-Repository Static & Dynamic Code Auditing (SAST/DAST): Scan entire corporate software repositories and microservice architectures in a single context window to spot zero-day logic flaws, hardcoded secrets, dangerous dependencies, and OWASP Top 10 vulnerabilities before production deployment.

  • Automated Threat Hunting & PCAP Forensics: Reconstruct multi-gigabyte network packet captures and NetFlow data to detect stealthy C2 communications, DNS tunneling, lateral movement, and unauthorized data exfiltration attempts.

  • Malware Reverse Engineering & Decompilation: Analyze disassembled assembly code, decompiled C/C++ binaries, and obfuscated PowerShell/JavaScript scripts to unpack malware payloads, map ATT&CK TTPs, and extract actionable Indicators of Compromise (IOCs).

  • Automated Red Teaming & Attack Surface Mapping: Parse comprehensive reconnaissance data such as Nmap scans, HTTP headers, subdomain enumerations, and web API contracts to identify exposed attack vectors, prioritize entry points, and construct non-destructive PoC scenarios.

  • CVE Remediation & Regulatory Advisory: Automatically convert technical vulnerability findings into enterprise-ready reporting complete with precise CVSS v4.0 scoring, mitigation playbooks, and compliance alignment for standards like ISO 27001, SOC 2, and PCI-DSS.