Overview
RedAmon is a modular, containerised penetration-testing framework for authorised engagements. It runs as a Docker stack — webapp, Postgres, Neo4j, the agent, a Kali sandbox, a recon orchestrator and a filtering Docker-socket broker — so no security tooling is installed on the host, and scan jobs are spawned as ephemeral sibling containers that are torn down when they finish. The project is explicit about scope in its own disclaimer: never point it at a system you do not own or have written permission to test.
The pipeline runs on a fan-out / fan-in architecture. A reconnaissance phase takes one input — a root domain, a subdomain list, IP or CIDR ranges, or a batch of domains — and fires as many of its 40-plus integrated tools in parallel as the work allows before converging on the next phase: subdomain discovery, port scanning, Nmap service detection and NSE scripts, HTTP probing, resource enumeration and vulnerability detection, plus dedicated scanners for GraphQL APIs, subdomain takeovers, hidden virtual hosts and web cache poisoning. A stealth mode restricts the whole pipeline to passive sources when active probing is off-limits.
Everything lands in a Neo4j knowledge graph with 17 node types and 20-plus relationship types, and that graph — not a transcript — is what the agent reads before each decision. The orchestrator is built on LangGraph: it reasons over the graph, selects tools through MCP, and moves through informational, exploitation and post-exploitation phases while an operator can steer it from chat. A second graph, EvoGraph, persists each step, finding, decision and failure so intelligence accumulates across sessions rather than restarting with every scan.
The part that distinguishes it from a scanner is what happens after the findings. CypherFix scores every finding from the graph against a fixed risk model, groups the ones that share a fix, has a model check the evidence behind each group, and emits one fix item per group; a CodeFix agent then clones the target repository, works it with a ReAct loop over eleven code-aware tools, and opens a pull request for review. Governance is built for teams: multi-user and multi-project tenancy with `user_id + project_id` scoping, Rules-of-Engagement enforcement, human approval gates, 500-plus per-project settings, and a hard guardrail that blocks government, military and intergovernmental targets regardless of configuration. The platform has been assessed end to end under STRIDE, with the threat model and control catalogue published in the repository.
What it does
- A parallel reconnaissance pipeline integrating 40+ industry tools inside a Kali container, with a stealth mode that stays on passive sources only
- A Neo4j attack-surface graph (17 node types, 20+ relationship types) as the single source of truth the agent queries before every decision
- A LangGraph orchestrator that selects tools over MCP and moves through informational, exploitation and post-exploitation phases under live chat steering
- EvoGraph — a persistent attack-chain graph that carries steps, findings, decisions and failures across sessions
- CypherFix remediation: risk-scored triage, evidence checking and grouping, then a CodeFix agent that clones the repo and opens a GitHub pull request
- Optional GVM/OpenVAS network scanning, GitHub secret hunting, a secret multiscanner and offline OSV supply-chain checks
- Enterprise controls — multi-tenant scoping, Rules of Engagement, approval gates, 500+ per-project settings, and a non-disableable government/military target guardrail
Getting started
Docker and Docker Compose v2 are the only host requirements — no Node.js, Python or security tools are installed outside the containers. Size the machine first: the lighter install needs 2 cores, 4 GB RAM and 80 GB of free disk, while the full stack with GVM/OpenVAS needs 4 cores, 8 GB (16 GB recommended) and 110 GB, and its first launch spends around 30 minutes synchronising vulnerability feeds.

Clone and install
One script builds every image and starts the services. The --gvm flag adds the OpenVAS scanner and its four runtime containers; --kbase adds the local knowledge base (~4.4 GB heavier). Flags can be combined.
git clone https://github.com/samugit83/redamon.git
cd redamon
# Without GVM (lighter, faster startup):
./redamon.sh install
# With GVM / OpenVAS (full stack, ~30 min first run):
./redamon.sh install --gvmCreate the admin account
The installer prompts for a name, an email and a password of at least 12 characters. On a heavy first boot the prompt can be skipped — create the admin at any time with this command, which waits for the webapp and is safe to re-run.
./redamon.sh create-adminConfigure providers and keys in the UI
Open http://localhost:3000/settings — there is no .env file to edit. Add an LLM provider (OpenAI, Anthropic, OpenRouter, AWS Bedrock or any OpenAI-compatible endpoint such as Ollama, vLLM or Groq; each can be tested before saving), then any third-party intelligence keys you hold. Settings are stored per user in the database, and multiple keys per tool are rotated round-robin to avoid rate limits.
http://localhost:3000/settingsSet the rules of engagement, then scan
Sign in at http://localhost:3000, create a project and define the target. Scope, approval gates and tool confirmation live in the project's Rules of Engagement — set them before the first run, because they are what keeps an autonomous pipeline inside the boundary you are authorised to test.
http://localhost:3000Day-to-day lifecycle
One script handles everything. `update` pulls the latest code, rebuilds only the images whose sources changed, and preserves volumes — databases, scan results and reports are never deleted.
./redamon.sh status # running services, version, GVM and KB mode
./redamon.sh up # start (auto-detects the install-time mode)
./redamon.sh down # stop, preserving data
./redamon.sh update # pull + smart rebuild of changed servicesRunning it on a server
The quick start binds to localhost. For a shared, internet-reachable instance the repository ships a single-host deploy that drives redamon.sh over SSH and wraps the stack in the internet-facing layer the local install deliberately omits: nginx with Let's Encrypt TLS, a host firewall, SSH hardening and fail2ban behind one public HTTPS origin.
cd tooling/deploy/single-host
cp .env.example .env # set DOMAIN, HOST_IP, SSH_KEY_PATH, ADMIN_* ...
./deploy.sh init # builds the full stack and brings it up over SSHCommands and code are distilled from the project's own documentation — always check the official repo for the latest.
When to use it
- Reach for it when an authorised external engagement needs the whole attack surface mapped from one domain, and you want the result as a queryable graph rather than a folder of tool output
- Reach for it when findings from many tools need deduplicating and ranking by exploitability instead of being read scanner by scanner
- Reach for it when the goal is a merged patch rather than a report — CypherFix triages and the CodeFix agent opens the pull request
- Reach for it when a security team needs multi-project tenancy, Rules-of-Engagement enforcement and human approval gates around an autonomous pipeline
How RedAmon compares
RedAmon alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.
| Tool | Stars | What it does |
|---|---|---|
| PentAGI | ★ 25.2k | PentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools. |
| PentestGPT | ★ 15.7k | An open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop. |
| IDA Pro MCP | ★ 12.4k | An MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database. |
| HexStrike AI | ★ 12.3k | An MCP server that gives an AI agent a single interface to 150+ installed security tools — Nmap, Nuclei, SQLMap, Ghidra, Hashcat and more — so it can drive reconnaissance, scanning and binary analysis itself. |
| CAI | ★ 9.8k | CAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation. |
| AI-Infra-Guard | ★ 6.7k | Tencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations. |
| T3MP3ST | ★ 6.3k | A multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI. |
| RedAmon | ★ 2.9k | A containerised offensive-security platform for authorised testing that maps an attack surface into a Neo4j graph, reasons over it with a LangGraph agent, then triages the findings and opens remediation pull requests |