Kali-Terminus-v2

Kali-Terminus-v2 is a fine-tuned LFM2.5-350M model specialized for Kali Linux terminal command execution. It converts natural language instructions into precise shell commands with the exec tool-call format.

This is the Executor Agent in a multi-agent penetration-testing system — it translates one bounded instruction into one structured terminal action.

Model Details

Property Value
Base Model LFM2.5-350M
Architecture LFM2 hybrid (10 conv + 6 full-attention layers)
Parameters 350M
Context Length 128K tokens (trained with 1024)
Fine-Tuning LoRA (r=16, alpha=32, 11 target modules)
Training Data iselabvn/Kali-terminal-executor-v2 (2,418 samples)
Precision float32 (merged)
Format <|im_start|> / <|im_end|> with <call:exec> tool calls

Performance

Evaluated across 5 scenarios (26 turns) covering network recon, system enumeration, web recon, DNS recon, and self-correction:

Metric Score
Strict Pass Rate 88.46%
Tool Call Parse Rate 100.0%
Exactly One Tool Call 100.0%
Semantic Command Accuracy 88.46%

Comparison with V1

Model Strict Pass Rate Improvement
Kali-Terminus-v1 (FunctionGemma-270M) 65.8%
Kali-Terminus-v1 (LFM2.5-350M) 50.0%
Kali-Terminus-v2 88.46% +38.5 pp over v1 LFM2.5

Dataset

Fine-tuned on iselabvn/Kali-terminal-executor-v2, a curated collection of 2,418 shell command execution pairs combining 1,380 source records with 1,000 synthetically augmented records (DeepSeek-V4-Flash).

Top tools in training data: nmap · dig · gobuster · curl · whatweb · sqlmap · find · hydra · uname · ss · subfinder · dnsrecon · ffuf · id · nikto

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer

model = AutoModelForCausalLM.from_pretrained("iselabvn/Kali-Terminus-v2", trust_remote_code=True)
tokenizer = AutoTokenizer.from_pretrained("iselabvn/Kali-Terminus-v2", trust_remote_code=True)

messages = [
    {"role": "user", "content": "Scan port 80 on 192.168.1.1"}
]
inputs = tokenizer.apply_chat_template(
    messages,
    tools=[{
        "type": "function",
        "function": {
            "name": "exec",
            "description": "Execute a shell command in the Kali terminal.",
            "parameters": {
                "type": "object",
                "properties": {"command": {"type": "string"}},
                "required": ["command"]
            }
        }
    }],
    add_generation_prompt=True,
    return_tensors="pt"
)
outputs = model.generate(**inputs, max_new_tokens=256)
response = tokenizer.decode(outputs[0][inputs["input_ids"].shape[-1]:], skip_special_tokens=False)
print(response)
# Expected: <call:exec>{"command": "nmap -p 80 192.168.1.1"}</call:exec>

Intended Use

  • Executor Agent in multi-agent penetration-testing systems
  • Single-Turn Kali Terminal Assistant — converts natural language to shell commands
  • Not recommended for general conversation or chatbot use

Limitations

  • Designed for single-turn command generation; multi-turn interaction requires external state management
  • Commands target authorized lab environments only; not for production systems without human review
  • Best performance on the 15 core Kali/Linux tools seen during training

Training Details

Hyperparameter Value
LoRA rank 16
LoRA alpha 32
LoRA dropout 0.05
Target modules in_proj, out_proj, q_proj, k_proj, v_proj, w1, w2, w3, gate_proj, up_proj, down_proj
Learning rate 2e-4 (cosine)
Batch size 4
Gradient accumulation 4
Effective batch size 16
Epochs 3 (best checkpoint at step 352, ~2.7 epochs)
Max sequence length 1024
Optimizer AdamW
Precision bfloat16

Citation

@misc{kali-terminus-v2,
  author = {ISeLab},
  title = {Kali-Terminus-v2: Fine-tuned LFM2.5-350M for Kali Linux Terminal Execution},
  year = {2026},
  publisher = {Hugging Face},
  url = {https://huggingface.co/iselabvn/Kali-Terminus-v2}
}
Downloads last month
-
Safetensors
Model size
0.4B params
Tensor type
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for iselabvn/Kali-Terminus-v2

Finetuned
(16)
this model
Quantizations
1 model

Dataset used to train iselabvn/Kali-Terminus-v2

Evaluation results

  • Strict Pass Rate on Kali-Terminus Evaluation Suite
    self-reported
    88.460
  • Tool Call Parse Rate on Kali-Terminus Evaluation Suite
    self-reported
    100.000
  • Semantic Command Accuracy on Kali-Terminus Evaluation Suite
    self-reported
    88.460