RedDaemonCORE
v1.1 · private build
Autonomous Offensive Security Platform

Always running.
Always hunting.

An AI operator that reasons across your attack surface, executes real exploitation, and unifies offense with defense in one pane — scope-gated, approval-gated, fully audited.

Restricted tool · authorized red-team use only · not on public app stores
NEW IN 1.1 · "MORE TEETH"
Capabilities

From detecting attacks to proving them

1.1 turns RedDaemon from a scanner into an operator — real credential and Active-Directory execution, post-exploitation, and a purple loop that no competitor ships. Everything below runs behind a default-deny scope guard and human approval gates.

Autonomous Purple Loop

Attacks its own detections — mutates the attack through real evasions until it finds the blind spot, then hands you a hardened Sigma/SPL/KQL rule that closes it.

Signature · nobody else has this

Credential & AD Execution

Kerberoast, AS-REP, password spray, pass-the-hash, secretsdump, DCSync, ADCS abuse — via NetExec, Impacket, Certipy, Kerbrute. Real, gated, audited.

NetExec · Impacket · Certipy

C2 & Post-Exploitation

Sliver integration: generate implants, drive live sessions, pivot — allowlisted by default, dangerous actions gated, implants auto-killed at engagement close.

Sliver · sessions · pivot

Blind-Vuln Confirmation

An out-of-band (OAST) callback server confirms blind SSRF, XXE, and RCE actually fired — turning "possible" findings into proven ones.

OAST · HTTP + DNS

Encrypted Loot Vault

Every captured credential, hash, ticket, and certificate — AES-256 encrypted, engagement-scoped, chainable (crack a hash, reuse it downstream), purged on close.

AES-256 · chaining

Thousands of Templates

Nuclei template pipeline — catalog, search, select, author your own — widening detection from a handful of checks to the full community library.

Nuclei · custom rules
Builds · v1.1.0

Get the appliance

Desktop is a self-contained local security workstation; mobile is the remote console for dashboards, alerts, and approval gates. Every build is password-gated — your browser will prompt for the GHT team password on download. Don’t have it? Ask Connor.

Windows

NSIS installer · x64

macOS

Apple Silicon · .dmg

Linux

AppImage · x64

Android

Remote console · signed .apk
Coming soon
Access

Request a build

RedDaemon is distributed privately to authorized red teams and security orgs. Tell us who you are — approved requests get a download link and license.

GHT team: skip the form — the builds above are already unlocked with the shared team password.

  • 01
    You request

    Tell us your org and intended use. Authorized offensive-security use only.

  • 02
    We verify & approve

    Quick check that you're a legitimate red team or security org.

  • 03
    You get the build

    A signed-in download link to the desktop installers and Android console, plus your license.

  • 04
    Safe by default

    Ships loopback-only. Every intrusive action re-checks scope and stops at an approval gate you control.

Scope guard active · default-deny · loopback-only out of the box