BARE
Air-gap-native semantic exploit mapping
§ Workflow phase
- 01 hunt
- 02 analyze
- 03 enrich
- 04 report
- 05 instrument
Analysis. Characterises and classifies findings.
BARE is a single self-contained binary, embedded BERT encoder, embedded
3,904-module Metasploit corpus, no Python runtime, no pip install, no
internet. One scp to a classified network, ICS environment, or isolated
lab and it runs.
Pipe a findings.json (nuclei / nmap / Shodan adapters included) in, get
ranked exploit modules out, semantically matched, not keyword-matched.
Why this exists
Commercial vulnerability-to-exploit mapping tools assume connectivity. They phone home, they pull updates, they call out to a SaaS backend. None of that works in the environments where BARE was built to run: classified networks, ICS plants, isolated research labs.
BARE was designed from scratch for the air-gap case. ~101 MB, single binary, embedded models, it’s physical reach for offline operators.
Source
github.com/nuclide-research/BARE
In the field
Designed for ICS/OT engagements where commodity scanners can’t run. Works offline indefinitely; no telemetry, no callouts.
§ Used in
Used in
SURVEYS · 06
- 01
Argo Workflows Population Survey — Cat-29 (2026-05-31)
- 02
Data Labeling & Annotation: the registration knob that re-opens the door
- 03
Unauthenticated FinOps Cost APIs Hand Attackers a Free Cluster Recon Map
- 04
Vector-DB Stragglers Population Survey (2026-05-16)
- 05
Voice-Cloning Population Survey: Shodan-Reachable Slice (2026-05-15)
- 06
Arize AI Phoenix unauthenticated LLM-observability exposure (377-host population)
FIELD CASES · 06
- 01
NCKU Edge Host: a Kubernetes Control Plane Behind a MikroTik Gateway
- 02
Evolution API WhatsApp Broker — RedisInsight Open, 117 Keys Including WhatsApp Session State and Lead Phone Numbers
- 03
MikroWizard — Unauthenticated Redis Session Store, 2,940 Active MikroTik Router Management Sessions
- 04
116.202.28.181 — Pantaflow Live Transcription Server
- 05
Embedding Services Survey — Tier-2 Cloud (2026-05-21)
- 06
reputacion.digital: Multi-surface chained exposure (Phoenix + NFS + Prometheus + dev SMTP)
DISCLOSURES · 01
§ analyze layer