samugit83/redamon
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
About samugit83/redamon
samugit83/redamon is an open-source project on GitHub, mainly written in Python. An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation It currently holds 2,743 stars and 567 forks with 16 open issues, and was last pushed on 2026-09-27 (repository created 2025-12-29).
Project Overview
Git Homed tracks it on the Today's Trending board, currently at rank #39 with 97 new stars today.
GitHub Repository Details
README
Unmask the hidden before the world does
An autonomous AI framework that chains reconnaissance, exploitation, and post-exploitation into a single pipeline, then goes further by triaging every finding, implementing code fixes, and opening pull requests on your repository. From first packet to merged patch, with human oversight at every critical step.
LEGAL DISCLAIMER: This tool is intended for authorized security testing, educational purposes, and research only. Never use this system to scan, probe, or attack any system you do not own or have explicit written permission to test. Unauthorized access is illegal and punishable by law. By using this tool, you accept full responsibility for your actions. Read Full Disclaimer
🏆 Flagship result: RedAmon solves 101 / 104 (97.1%) of the XBOW web-security benchmark fully black-box. Every solve ships a complete, unedited raw agent session and a reproducible, step-by-step walkthrough: open any row and read exactly how the flag fell, tool call by tool call. Auditable, line by line. See the XBOW Validation Benchmark scorecard.
📊 Coverage, measured and self-scored: the Bug Bounty Coverage — The Full Taxonomy Audit (PDF, 124 pages) audits RedAmon against all 397 classes of web bug-bounty finding, one line at a time, naming the exact module, skill or scanner behind every verdict, and scoring the recon pipeline and the agentic system separately against their own remit. It is deliberately self-critical, it records what is missing as plainly as what is covered: 134 classes complete, 210 in the build backlog, 44 deliberately excluded, with one explicit decision for every class.
Dynamic Multi-Tool Parallel Recon Pipeline
RedAmon launches multiple reconnaissance tools in parallel, each feeding results into a shared knowledge graph in real time. Tools spin up, adapt their scope based on live discoveries, and coordinate without manual intervention. The entire attack surface -- subdomains, ports, endpoints, parameters -- materializes in minutes, not hours.
Recon as a Living Knowledge Graph
Industry-standard scanners chained so each tool's output feeds the next, then merged into a single Neo4j knowledge graph. Findings are deduplicated, relationships are explicit, and the agent inherits a structured, fully connected attack surface ready to query in natural language.
Offense meets defense. One pipeline, full visibility.
Reconnaissance ➜ Exploitation ➜ Post-Exploitation ➜ AI Triage ➜ CodeFix Agent ➜ GitHub PR
RedAmon doesn't stop at finding vulnerabilities, it fixes them. The pipeline starts with a 6-phase reconnaissance engine that maps your target's entire attack surface, then hands control to an autonomous AI agent that validates CVE exploitability, tests credential policies, and maps lateral movement paths. Every finding is recorded in a Neo4j knowledge graph. When the offensive phase completes, CypherFix takes over: an AI triage agent correlates hundreds of findings, deduplicates them, and ranks them by exploitability. Then a CodeFix agent clones your repository, navigates the codebase with 11 code-aware tools, implements targeted fixes, and opens a GitHub pull request, ready for review and merge.
---
Roadmap & Community Contributions
We maintain a public Project Board with upcoming features open for community contributions. Pick a task and submit a PR!
Want to contribute? See CONTRIBUTING.md for how to get started.
Maintainers
![]() Samuele Giampieri: Creator, Maintainer & AI Platform Architect AI Platform Architect & Full-Stack Lead with 15+ years of freelancing experience and more than 30 projects shipped to production, including enterprise-scale AI agentic systems. AWS-certified (DevOps Engineer, ML Specialty) and IBM-certified AI Engineer. Designs end-to-end ML solutions spanning deep learning, NLP, Computer Vision, and AI Agent systems with LangChain/LangGraph. LinkedIn · GitHub · Devergo Labs ![]() From the same creator: Pathbreak - Agentic Cloud Security See the attack path. Then break it. Pathbreak is an agentic cloud security platform that discovers and validates the real attack paths a threat actor would exploit across your cloud. It catches the control-plane chains most tools miss. Pathbreak - agentic cloud security pathbreak.io |
![]() Ritesh Gohil: Maintainer & Lead Security Researcher Cyber Security Engineer at Workday with over 7 years of experience in Web, API, Mobile, Network, and Cloud penetration testing. Published 11 CVEs in MITRE, with security acknowledgements from Google (4×) and Apple (6×). Secured 200+ web and mobile applications and contributed to Exploit Database, Google Hacking Database, and the AWS Community. Holds AWS Security Specialty, eWPTXv2, eCPPTv2, CRTP, and CEH certifications with expertise in red teaming, cloud security, CVE research, and security architecture review. LinkedIn · GitHub |
Anthropic Cyber Verification Program: the team behind RedAmon is approved under Anthropic's Cyber Verification Program.
---
Quick Start
Prerequisites
- Docker & Docker Compose v2+
- macOS: Docker Desktop, with Memory raised to at least 4 GB (8 GB with
--gvm) in Settings → Resources. Clone under~/so the path is inside the default File Sharing list. - Windows: Docker Desktop with the WSL2 backend, run from inside the WSL2 filesystem (
~/), not/mnt/c/.
Minimum System Requirements
| Resource | Without OpenVAS | With OpenVAS (full stack) | |----------|----------------|--------------------------| | CPU | 2 cores | 4 cores | | RAM | 4 GB | 8 GB (16 GB recommended) | | Disk | 80 GB free | 110 GB free |
Without OpenVAS runs 7 containers: webapp, postgres, neo4j, agent, kali-sandbox, recon-orchestrator, and docker-broker (a filtering Docker-socket proxy that the recon orchestrator's spawned scan containers go through, so they can only launch the known tool images).
With OpenVAS adds 4 more runtime containers (gvmd, ospd-openvas, gvm-postgres, gvm-redis) plus ~8 one-shot data-init containers for vulnerability feeds (~170K+ NVTs). First launch takes ~30 minutes for GVM feed synchronization.
Dynamic recon and scan containers are spawned on-demand during operations and require additional resources.
Disk sizing for a real deployment. The figures above are bare minimums to build and run the stack (fixed platform footprint: ~70 GB without OpenVAS, ~95 GB with - measured by true on-disk image size after deduplicating the shared Kali base layers). For an always-on server running real engagements, add ~100 GB of free space for operational data - the Neo4j attack graph, scan artifacts/outputs, Postgres, and container logs all grow with use. That means 200 GB without OpenVAS, 250 GB with OpenVAS, each leaving well over 100 GB free for operations. See the deployment guide for the full breakdown.
1. Clone & Install
git clone https://github.com/samugit83/redamon.git
cd redamon
Without GVM (lighter, faster startup):
./redamon.sh install
With GVM / OpenVAS (full stack, ~30 min first run):
./redamon.sh install --gvm
The script builds all images and starts the services.
2. Create Admin Account
At the end of the install (and on every ./redamon.sh up or ./redamon.sh update if no admin exists), you will be prompted in the terminal:
[WARN] No admin user found. Let's create one.
Admin name: Your Name
Admin email: [email protected]
Admin password: ******
Confirm password: ****
- Admin name -- display name shown in the UI (e.g.
Admin, your name, anything you want). - Admin email -- used to log in at
http://localhost:3000/login. - Admin password -- minimum 12 characters.
--gvm, or a small VM) the webapp can take a while to come up, so the automatic prompt may be skipped. Create the admin at any time with:
>> ./redamon.sh create-admin
> It waits for the webapp, then prompts for the same details. It is safe to re-run: reusing an existing admin's email resets that password, a new email adds another admin.What the admin can do:
- Switch between all users via the user dropdown in the header (including users without a password).
- Create new users (with or without a password) and assign them
adminorstandardroles. - Set or change any user's password.
- Delete users (except themselves).
- Access the
If you forget the admin password, reset it from the terminal:
./redamon.sh reset-password # reset an EXISTING user's password
./redamon.sh create-admin # create the first admin, or reset an admin by re-entering its email
Use create-admin when no admin exists yet (it upserts on email); reset-password only updates a user that already exists.
3. Configure
Open
http://localhost:3000/settings (gear icon in the header) to configure everything. No.env file is needed.
4. Open the Webapp
Go to
http://localhost:3000 -- create a project, configure your target, and start scanning.For a detailed walkthrough of every feature, check theWiki.
> Prefer video? Watch theProduct Demos playlist on YouTube for step-by-step tutorials.
> Having issues? See theTroubleshooting guide or the Wiki Troubleshooting page.
Management Commands
All lifecycle management is handled by a single script:
| Command | Description |
|---------|-------------|
| ./redamon.sh install | Build + start lightweight (no GVM, no Knowledge Base, Tavily-only web search) |
| ./redamon.sh install --kbase | Build + start with the local Knowledge Base (~4.4 GB heavier) |
| ./redamon.sh install --gvm | Build + start with GVM/OpenVAS |
Flags can be combined: ./redamon.sh install --gvm --kbase
| Command | Description | |---------|-------------| |
./redamon.sh update | Pull latest version, smart-rebuild only changed services (preserves your install-time GVM/KB choice) |
| ./redamon.sh up | Start services (auto-detects GVM and KB mode from install) |
| ./redamon.sh up dev | Start in dev mode with hot-reload (auto-detects GVM and KB mode) |
| ./redamon.sh down | Stop services (preserves data) |
| ./redamon.sh status | Show running services, version, GVM mode, KB state |
| ./redamon.sh clean | Remove containers + images, keep data |
| ./redamon.sh create-admin | Create the admin login (or reset it) -- use if no prompt appeared at install |
| ./redamon.sh reset-password | Reset an existing user's password from the terminal |
| ./redamon.sh supply-chain-sync [ecosystems] | Populate the offline OSV database for the supply-chain feature (default: npm; e.g. npm PyPI Go) |
| ./redamon.sh purge | Remove everything including all data |
Updating to a New Version
Just run:
./redamon.sh update
The script pulls the latest code from GitHub, detects which Dockerfiles and source files changed, rebuilds only the affected images, and restarts the updated services. Your databases, scan results, and reports are preserved -- volumes are never deleted.
One-time note when a release adds a new background service.**update re-execs the freshly-pulled script so new build/start rules apply automatically -- but only for the script version you are updating from. When updating from a version that predates this self-heal (i.e. your first update onto it), run ./redamon.sh up once right after update so any newly added core service is started:
>> ./redamon.sh update && ./redamon.sh up
>upis idempotent -- it starts only what is missing and leaves running containers untouched. After this one-time step, plain./redamon.sh updatehandles everything on its own.
Upgrading across 6.9 (repository reorganization). 6.9 grouped the top-level directories underscanners/,services/,testing/,tooling/anddocs/.git pullmoves only tracked files, so data that git does not track -- the knowledge-base index, past scan outputs, and the single-host deploy.envand TLS material -- would otherwise be left behind at the old paths.update(andup/status) migrate it for you automatically and print what moved. If any file was written by a container as root and could not be moved, finish it with:
>> sudo ./redamon.sh migrate-layout
The webapp also checks for updates automatically and shows a notification in the UI when a new version is available.
Deploy to a Server (Production)
The Quick Start above runs RedAmon locally on localhost. To run a shared, internet-reachable instance on a Linux server (EC2, DigitalOcean, Hetzner, or bare metal), use the single-host deploy in tooling/deploy/single-host/. It drives redamon.sh over SSH from your laptop and wraps the stack in the internet-facing security layer RedAmon omits by default: nginx + TLS (Let's Encrypt), a host firewall, SSH hardening, and fail2ban, with a single public HTTPS origin so only the login page is reachable and everything else stays bound to loopback.
cd tooling/deploy/single-host
cp .env.example .env # set HOST_IP, DOMAIN, SSH_KEY_PATH, OPERATOR_ALLOW_CIDRS,
# LETSENCRYPT_EMAIL, ADMIN_* ...
./deploy.sh init # first build takes 30-60 min, then log in at https:///
Full walkthrough: Wiki: Deploying to a Server. Complete reference: tooling/deploy/single-host/README.md.
Development Mode
For contributors and active development with Next.js fast refresh:
./redamon.sh up dev # auto-detects GVM mode from install
Tool images are built automatically on first run if they don't exist yet. The dev override swaps the production webapp image for a dev container with your source code volume-mounted. Every file save triggers instant hot-reload in the browser.
When to Rebuild vs Restart
| What changed | Action needed |
|-------------|---------------|
| webapp/src/ (frontend code) | Nothing -- Next.js hot-reload handles it in dev mode |
| agentic/*.py (agent Python code) | docker compose build agent && docker compose up -d agent (source is baked into the image, so restart alone won't pick up .py changes) |
| recon_orchestrator/*.py | docker compose restart recon-orchestrator |
| mcp/servers/*.py (MCP servers) | docker compose restart kali-sandbox |
| agentic/Dockerfile or agentic/requirements.txt | docker compose build agent && docker compose up -d agent |
| recon_orchestrator/Dockerfile or its requirements.txt | docker compose build recon-orchestrator && docker compose up -d recon-orchestrator |
| mcp/kali-sandbox/Dockerfile | docker compose build kali-sandbox && docker compose up -d kali-sandbox |
| webapp/Dockerfile or webapp/package.json | docker compose build webapp && docker compose up -d webapp |
| recon/Dockerfile | docker compose --profile tools build recon |
| scanners/gvm_scan/Dockerfile | `docker compose --profile tools build vul


