About this project

RedAmon is an autonomous, AI-driven offensive security framework distributed as a Docker Compose stack with a Next.js web interface. It is positioned for authorized security testing, education and research, and the README carries an explicit legal disclaimer requiring written permission before scanning any system. Pipeline and capabilities - A multi-phase reconnaissance engine launches multiple scanners in parallel, with each tool's output feeding the next and results merged into a Neo4j knowledge graph of the attack surface (subdomains, ports, endpoints, parameters). - An autonomous agent then validates CVE exploitability, tests credential policies and maps lateral-movement paths, recording findings in the graph. - CypherFix adds an AI triage stage that correlates and deduplicates findings and ranks them by exploitability, followed by a CodeFix agent that clones a repository, navigates it with code-aware tools, implements fixes and opens a GitHub pull request. - The README describes a "Fireteam" parallel multi-agent mode, an "AI Gauntlet" offensive AI testing component, and TrafficMind, a mitmproxy-based HTTP capture component. - Reported integrations include Metasploit and OpenVAS/GVM, plus 100+ security tools, a large detection-rule set and support for many AI models through configurable providers. Setup and operations - Prerequisites are Docker and Docker Compose v2+; no host Node.js, Python or security tooling is required. Minimum resources are listed as 2 cores/4 GB RAM/80 GB disk without OpenVAS, and 4 cores/8 GB RAM/110 GB disk with it; the README recommends substantially more disk for always-on deployments. - Installation is driven by a single `redamon.sh` script with subcommands for install (optionally with `--gvm` and/or `--kbase`), update, up/down, status, clean, purge, admin creation and password reset. An admin account is created interactively, and settings such as LLM provider keys, OSINT/threat-intel API keys and tunneling are configured in the web UI rather than a `.env` file. - A single-host deployment helper under `tooling/deploy/single-host/` adds nginx with Let's Encrypt TLS, firewall rules, SSH hardening and fail2ban for internet-reachable instances. - A development mode provides Next.js hot reload, and the README documents which changes require rebuilding versus restarting individual services. Validation and documentation - The README cites a flagship result of 101/104 (97.1%) on the XBOW web-security benchmark, fully black-box, with raw agent sessions and step-by-step walkthroughs published per solve. - It also references a self-scored 124-page taxonomy audit against 397 classes of web bug-bounty findings, reporting 134 complete, 210 in backlog and 44 deliberately excluded. - Extensive documentation lives in the project wiki, with video playlists, a project board for contributions, and named maintainers with security backgrounds. The project is MIT-licensed and states approval under Anthropic's Cyber Verification Program.