SAPSAN-SKLEP/HIDra-30B-A3B-GGUF-uncensored-cybersec overview
<div align="center" <img src="https://huggingface.co/SAPSAN SKLEP/HIDra 30B A3B GGUF uncensored cybersec/resolve/main/banner.png" alt="HIDra" width="100%"/ </d…
Runs locally from ~13.70 GB disk (16 GB VRAM class GPUs with llama.cpp / guIDE).
Repository Files & Downloads
Model Details
| Model ID | SAPSAN-SKLEP/HIDra-30B-A3B-GGUF-uncensored-cybersec |
|---|---|
| Author | SAPSAN-SKLEP |
| Pipeline | text-generation |
| License | apache-2.0 |
| Base model | huihui-ai/Huihui-Qwen3-Coder-30B-A3B-Instruct-abliterated |
| Last modified | 2026-06-19T10:14:50.000Z |
Model README
---
license: apache-2.0
base_model: huihui-ai/Huihui-Qwen3-Coder-30B-A3B-Instruct-abliterated
tags:
- cybersecurity
- red-team
- pentesting
- offensive-security
- ctf
- cti
- code
- badusb
- uncensored
- gguf
- qwen3moe
- hidra
language:
- en
pipeline_tag: text-generation
---
<div align="center">
<img src="https://huggingface.co/SAPSAN-SKLEP/HIDra-30B-A3B-GGUF-uncensored-cybersec/resolve/main/banner.png" alt="HIDra" width="100%"/>
</div>
<p align="center">
🌐 <a href="https://sapsan-sklep.pl/en">Website</a> •
🤗 <a href="https://huggingface.co/SAPSAN-SKLEP">Hugging Face</a> •
💬 <a href="https://discord.gg/bVE76cCTQH">Discord</a> •
▶️ <a href="https://www.youtube.com/channel/UCuUA4tbGJS1AEtClDgomwsA">YouTube</a> •
📸 <a href="https://www.instagram.com/sapsanpentesting/">Instagram</a> •
𝕏 <a href="https://twitter.com/SAPSAN_CYBERSEC">Twitter</a> •
📘 <a href="https://www.facebook.com/people/SAPSAN/100070927734505/">Facebook</a>
</p>
HIDra-30B-A3B - Offline Red-Team & Offensive-Security Assistant (GGUF)
By SAPSAN CYBERSEC - built by cybersecurity professionals, for penetration testers.
HIDra is an uncensored, offline large language model purpose-built to assist real penetration testers and red-teamers: payload crafting, exploitation walkthroughs, CTF reasoning, offensive code, BadUSB/HID injection, and Cyber Threat Intelligence - all running locally on your own hardware, with no data leaving your machine.
---
Who made it
SAPSAN CYBERSEC is one of the largest specialist cybersecurity-hardware stores in the world (sapsan-sklep.pl/en). We live and breathe offensive security: we supply the gear pentesters actually use, and we work shoulder-to-shoulder with the red-team community every day. HIDra pours that hands-on experience into a model that speaks a pentester's language instead of refusing to.
---
Highlights
- Uncensored. Built on an abliterated base - it answers red-team, exploitation and CTF questions head-on, in the language professionals actually use, not a corporate disclaimer.
- Offline & private. Distributed as GGUF (Q3 / Q4 / Q5 / Q8). Your engagements and threat intel never leave the box.
- Code-native. Built on a strong coding model: writes and explains exploits, PoCs, scripts and tooling on demand.
- Works out of the box. Identifies as HIDra, SAPSAN's offline red-team assistant from the very first message - no system prompt required.
- Won't bluff. It won't fabricate flags, keys, hashes or results it cannot verify - it tells you so, and shows you how to obtain them for real.
- Real BadUSB depth. Knows DuckyScript and the syntax quirks of HID-injection hardware most models have never seen - including niche cables and boards from SAPSAN's catalog.
---
Capabilities
- CTF reasoning - works the problem across web, pwn, crypto, reversing and forensics: identifies the vulnerability class, explains the chain, and reasons toward the solution (e.g. padding-oracle decryption, ECDSA nonce-leak key recovery, JWT alg-confusion, SSTI to RCE, insecure-deserialization).
- Offensive payloads & techniques - web (XSS, SQLi, SSRF, auth bypass), command injection, reverse shells, privilege escalation, and common exploitation chains.
- Offensive code - writes and debugs exploit scripts, PoCs, and automation in the language you need, then explains exactly what each step does.
- BadUSB / HID injection - DuckyScript and beyond: elevated-shell droppers, exfiltration one-liners, cross-platform payloads, and the syntax quirks of niche cables/boards, drawn from SAPSAN's hardware catalog and field experience.
- Cyber Threat Intelligence - CVE to CWE mapping, MITRE ATT&CK technique association, and threat-report reasoning.
---
Quick start
LM Studio / Jan / Ollama: download a GGUF below and load it - no system prompt required, identity and behaviour are baked in.
llama.cpp:
llama-server -m HIDra-30B-A3B-Q4_K_M.gguf --ctx-size 8192 -ngl 99 --jinja
| Quant | Size | Use |
|---|---|---|
| Q3_K_M | ~14 GB | smallest - tight-memory machines |
| Q4_K_M | ~18.6 GB | recommended - runs on a 24 GB Mac mini |
| Q5_K_M | ~21.7 GB | better quality |
| Q8_0 | ~32 GB | maximum fidelity |
This model answers directly (no <think> block).
Recommended sampling parameters
temperature = 0.7
top_p = 0.8
top_k = 20
repetition_penalty = 1.05
---
Modality
This release is text-only.
Base model & identity
HIDra is built on an abliterated Qwen3-Coder-30B-A3B (Apache 2.0) - a sparse Mixture-of-Experts model
(~30.5B total, ~3.3B active per token, 128 experts) with safety refusals removed - and fine-tuned by SAPSAN
CYBERSEC to add its identity, offensive-security knowledge, and calibrated honesty. It identifies as *HIDra,
SAPSAN's offline red-team assistant*.
Intended use & responsible use
HIDra is intended for authorized penetration testing, red-team engagements, CTF competitions, security
research and education. By using it you agree to operate only against systems you own or have explicit written
permission to test. SAPSAN CYBERSEC accepts no liability for misuse. This is a professional tool that assumes
a professional, lawful operator.
Limitations
- No safety RLHF - it will discuss offensive techniques; the operator is responsible for legality.
- Quantized GGUF (~1-2 pts of drift vs full precision).
- Text-only; no vision input in this release.
---
Support the project & what's next
We invested significant own funds into the research, training and data collection behind HIDra. The training data was hand-curated by our team and draws on our own store's security and hardware expertise - this is not a scrape, it is field knowledge turned into a model.
If you want to help us keep building models dedicated to pentesters, the simplest way to support us is to buy something from our store: sapsan-sklep.pl/en. Every order funds the next model.
Partnerships & compute
We are open to collaboration. If your company provides GPUs, hardware or compute and would like to support the training of pentester-focused open models, we would love to talk - reach out through any of the channels below.
We will keep releasing more - including models on other bases (e.g. Gemma) tuned for offensive security. Follow us to catch them first:
- Hugging Face: https://huggingface.co/SAPSAN-SKLEP
- Discord: https://discord.gg/bVE76cCTQH
- YouTube: https://www.youtube.com/channel/UCuUA4tbGJS1AEtClDgomwsA
- Instagram: https://www.instagram.com/sapsanpentesting/
- X (Twitter): https://twitter.com/SAPSAN_CYBERSEC
- Facebook: https://www.facebook.com/people/SAPSAN/100070927734505/
---
License
Apache 2.0, inherited from the Qwen3-Coder base model. HIDra is built on an abliterated Qwen3-Coder-30B-A3B - credit to huihui-ai for the abliterated base.
Citation
If you use HIDra, please cite both this model and the Qwen3-Coder base:
@misc{hidra2026,
title = {HIDra-30B-A3B: Offline Red-Team & Offensive-Security Assistant},
author = {SAPSAN CYBERSEC},
year = {2026},
url = {https://huggingface.co/SAPSAN-SKLEP/HIDra-30B-A3B-GGUF-uncensored-cybersec}
}
@misc{qwen3coder2025,
title = {{Qwen3-Coder-30B-A3B-Instruct}},
author = {{Qwen Team}},
year = {2025},
url = {https://huggingface.co/Qwen/Qwen3-Coder-30B-A3B-Instruct}
}Run SAPSAN-SKLEP/HIDra-30B-A3B-GGUF-uncensored-cybersec with guIDE
Download guIDE — the AI-native code editor with local LLM inference and 69 built-in tools.
Source: Hugging Face · Compare models