27 uncensored security LLMs mapped by hardware cost, not hype
on: JoasASantos/Offensive-Security-AI-Models
Twenty-seven open-weight models, catalogued by parameter count, VRAM requirement, uncensoring method, and deployment stack - this is a working reference for practitioners who need to run security-capable LLMs locally or on rented GPU infrastructure, not a theoretical survey.
The collection splits cleanly into two camps. Security-fine-tuned models have been trained on domain-specific corpora: HackerOne bug bounty reports, CVE writeups, GTFOBins, MITRE ATT&CK mappings, pentest traces. The smallest entry here is a 1.5B Qwen2.5 variant needing roughly 2 GB of VRAM; the largest practical option for a single workstation is probably RavenX-CyberAgent, a 36B MoE model trained across 745K examples from 110 sources in 12 progressive rounds, fitting in around 24 GB at Q4_K_M. The second camp is abliterated general models - weight-level interventions that orthogonalize the refusal direction out of the residual stream without retraining, following the Arditi et al. 2024 method. These are faster to produce and broader in capability, but carry no security-specific knowledge by default.
A few entries stand out for specific reasons. The pentest-v2 model achieves 100% accuracy on GTFOBins queries against a 25% zero-shot baseline from its Qwen3-8B parent, using only a LoRA with rank 4 trained on 2,804 samples - a striking result for how little data it required. Cyber-Prime 1.1 is the only entry with a published benchmark score on CyberBench, reporting 0.592 average F1/accuracy across tasks including phishing detection at 0.890. REDCELL-26B is the only model explicitly oriented toward OSINT and threat actor attribution rather than active exploitation, using a domain-weighted quantization scheme that weights roughly 70% of its calibration data from its own training corpus.
The deployment section is genuinely useful: VRAM figures are given at specific quantization levels (Q4_K_M, Q6_K, BF16), and the cloud provider table distinguishes managed inference APIs from raw GPU rentals. The DeepSeek-V4.1-Flash entry is unusual - it ships as a modular overlay of roughly 1.1 GB applied on top of an existing quantized base, not a standalone checkpoint.
The glossary defines abliteration, obliteration, imatrix quantization, MTP, and the RATH protocol used by RavenX. That last item - a six-step autonomous assessment framework covering attack surface, exploit, impact, remediation, documentation, and prevention - hints at where the more ambitious entries are headed: not just answering security questions but running structured agentic workflows.
The list is dated September 2026 and sourced from HuggingFace model cards, so specifications reflect what individual model authors published, not independent verification. Benchmark numbers where they exist come from the releasing teams themselves.
A dense, VRAM-grounded catalogue of 27 uncensored security LLMs that separates domain-fine-tuned from abliterated models and tells you exactly what hardware each one needs.