Always running.
Always hunting.
An AI operator that reasons across your attack surface, executes real exploitation, and unifies offense with defense in one pane — scope-gated, approval-gated, fully audited.
From detecting attacks to proving them
1.1 turns RedDaemon from a scanner into an operator — real credential and Active-Directory execution, post-exploitation, and a purple loop that no competitor ships. Everything below runs behind a default-deny scope guard and human approval gates.
Autonomous Purple Loop
Attacks its own detections — mutates the attack through real evasions until it finds the blind spot, then hands you a hardened Sigma/SPL/KQL rule that closes it.
Signature · nobody else has thisCredential & AD Execution
Kerberoast, AS-REP, password spray, pass-the-hash, secretsdump, DCSync, ADCS abuse — via NetExec, Impacket, Certipy, Kerbrute. Real, gated, audited.
NetExec · Impacket · CertipyC2 & Post-Exploitation
Sliver integration: generate implants, drive live sessions, pivot — allowlisted by default, dangerous actions gated, implants auto-killed at engagement close.
Sliver · sessions · pivotBlind-Vuln Confirmation
An out-of-band (OAST) callback server confirms blind SSRF, XXE, and RCE actually fired — turning "possible" findings into proven ones.
OAST · HTTP + DNSEncrypted Loot Vault
Every captured credential, hash, ticket, and certificate — AES-256 encrypted, engagement-scoped, chainable (crack a hash, reuse it downstream), purged on close.
AES-256 · chainingThousands of Templates
Nuclei template pipeline — catalog, search, select, author your own — widening detection from a handful of checks to the full community library.
Nuclei · custom rulesGet the appliance
Desktop is a self-contained local security workstation; mobile is the remote console for dashboards, alerts, and approval gates. Every build is password-gated — your browser will prompt for the GHT team password on download. Don’t have it? Ask Connor.
Request a build
RedDaemon is distributed privately to authorized red teams and security orgs. Tell us who you are — approved requests get a download link and license.
GHT team: skip the form — the builds above are already unlocked with the shared team password.
- 01You request
Tell us your org and intended use. Authorized offensive-security use only.
- 02We verify & approve
Quick check that you're a legitimate red team or security org.
- 03You get the build
A signed-in download link to the desktop installers and Android console, plus your license.
- 04Safe by default
Ships loopback-only. Every intrusive action re-checks scope and stops at an approval gate you control.
