nesilabs/tosilos-24b-2512
nesilabs/tosilos-24b-2512 is a 24 billion parameter cybersecurity-specialized language model, QLoRA fine-tuned on the European-based Devstral-Small-2-2512. This model is designed for authorized security work, excelling in web application security and Active Directory attack paths with an operational framing. A key differentiator is its 0% refusal rate on authorized security tasks, addressing a common issue in previous versions.
Loading preview...
Tosilos-24B-2512: Cybersecurity-Specialized LLM
Tosilos-24B-2512, developed by nesilabs, is a 24 billion parameter model specifically fine-tuned for cybersecurity applications. It is built upon the European-based Devstral-Small-2-2512 architecture using QLoRA. This model is part of the Tosilos project, aiming to provide sovereign, European-base security models with measurable domain gains.
Key Capabilities & Differentiators
- Cybersecurity Specialization: Optimized for tasks like web application security (injection, XSS, SSRF, IDOR, CSRF, auth/authz, upload, CORS), Active Directory attack paths, recon, and triage.
- Operational Framing: Focuses on practical aspects such as sequencing, confirmation oracles, safe verification, and evidence-to-CWE mapping.
- Zero Refusals: A significant improvement over its predecessor, this model exhibits a 0% refusal rate on authorized, in-scope security tasks, making it highly usable for security professionals.
- Performance: Maintains general capabilities (MMLU-500 at 72.8%) while showing a +0.40 improvement in blind-judged domain answer quality compared to its base model.
Intended Use Cases
This model is designed for authorized security testing, CTFs (Capture The Flag), research, and education. It is framed to operate strictly within an established, authorized scope, prioritizing proof-of-impact over destructive actions. Users are responsible for ensuring they only use it against systems they are authorized to test.