Tuesday, October 6, 2026

Inside Decepticon: an autonomous red team agent built around rules of engagement

Inside Decepticon: an autonomous red team agent built around rules of engagement

Decepticon is a Python-based autonomous red team agent that plans, executes, and documents authorized attack chains inside a hardened Docker sandbox, generating a full engagement package before any packet leaves the wire.

ToolBitterSecurity/Decepticon — autonomous red team agent in Python, Apache-2.0, ~5,654 stars
CategoryLLM-driven offensive security orchestration platform
Primary UseExecuting full kill chains — recon, exploitation, privilege escalation, lateral movement, C2 — inside lab and authorized engagement environments under a generated RoE/OPPLAN
Safe UseAuthorized penetration tests and red team engagements with explicit written permission from the system owner, plus lab benchmarks such as the XBOW validation suite
Telemetry NoteEvery command runs in persistent tmux sessions inside a Kali sandbox on a dedicated sandbox-net, and findings are persisted to a dual-homed Neo4j knowledge graph — a rich, centralized audit trail for both operators and defenders

The AI-hacking space has a credibility problem, and the Decepticon README opens by acknowledging it head-on: “Another AI hacker? Let us guess — it runs nmap and writes a report.” The project, published as BitterSecurity/Decepticon in Python under an Apache-2.0 license with roughly 5,600 stars, positions itself explicitly against that demo-tier output. It is a self-described professional autonomous red team agent that executes realistic attack chains — reconnaissance, exploitation, privilege escalation, lateral movement, and C2 — as an adversary would rather than as a checkbox scanner. What makes it interesting from an editorial standpoint is not just capability but governance: the tool generates a complete engagement package before doing anything.

That engagement discipline is the project's stated differentiator, and it deserves attention. Before any activity begins, Decepticon produces a rules of engagement document (RoE), a concept of operations (ConOps), a Deconfliction Plan, and an OPPLAN with MITRE ATT&CK mapping, and every subsequent action is constrained inside those defined rules. For authorized professionals, this is architecturally significant: the engagement boundary is not a hopeful promise in a disclaimer but a generated, machine-enforced artifact that precedes execution. It also makes the tool more documentable in scope-of-work terms than most agent frameworks, where authorization is frequently an afterthought.

Deployment is via Docker and Docker Compose v2, with support across macOS (both Apple Silicon and Intel), Linux on amd64 and arm64, and Windows native via PowerShell or WSL2 with Ubuntu or Kali. The onboarding flow is a two-step affair: decepticon onboard runs an interactive wizard covering provider selection, API key entry, and model profile, after which a bare decepticon starts the core stack and drops the operator into a terminal CLI. A PowerShell equivalent (irm https://decepticon.red/install.ps1 | iex) exists for Windows, and the maintainers also operate a hosted cloud app at app.decepticon.red for teams that do not want to self-host — a distribution model worth noting given how rare managed delivery still is in this niche.

The architecture is a two-network Docker design, and the README is unusually candid about its internals. An always-on management plane hosts LiteLLM for model routing, PostgreSQL, Skillogy, and LangGraph, the last of which drives the sandbox via the Docker socket. A separate always-on sandbox plane runs a Kali Linux environment on sandbox-net, deliberately segregated from the management network decepticon-net, with the C2 server and targets living alongside it. Everything outside those core services is dynamic-spawn: the web dashboard comes up from inside the CLI with /web, and specialist workloads like BloodHound CE, Sliver C2, and a Ghidra MCP server are only started when the orchestrator explicitly calls ops_start(...). The design is documented in an ADR-0006 decision record on agent-driven container lifecycle, which tells you the team is treating architecture as an evolving, reviewed artifact rather than a README diagram.

One of the more practical engineering decisions is how the agent handles interactive tooling. Real offensive tools are conversational — msfconsole, sliver-client, evil-winrm all drop into prompts that defeat naive automation. Decepticon runs every command inside persistent tmux sessions with automatic prompt detection, so when a tool enters an interactive mode, the agent can send follow-up commands natively instead of resorting to wrappers or expect-style hacks. For anyone who has watched LLM agents fail precisely at this boundary, this is the kind of detail that separates a working operator platform from a conference demo. It also means every operator action leaves a session transcript, which doubles as evidence for the engagement record.

The agent layer is organized into sixteen specialists grouped by kill chain phase: orchestration, reconnaissance, exploitation, post-exploitation, and vulnerability research, plus a set of domain specialists covering Active Directory, cloud, smart contracts, reversing, and analysis. Each objective gets a fresh context window, which the README frames as avoiding accumulated noise — a sensible pattern given how quickly long offensive sessions degrade LLM reasoning. Findings flow into a dual-homed Neo4j instance so the agent on the management network can persist knowledge graph attack chains written from inside the sandbox, turning scattered command output into a queryable model of the compromised environment.

Model routing is tier-based and credentials-aware. Operators declare which credentials they hold in priority order, and Decepticon builds a primary-to-fallback chain at every tier from that inventory. Three profiles ship out of the box: eco assigns per-agent tiers (high for orchestrator, exploiter, patcher, and analyst; mid for execution; low for recon), max puts every agent on the high tier for high-value targets, and test pins everything low for development and CI. Supported providers span Anthropic, OpenAI, Google Gemini, DeepSeek, xAI, Mistral, OpenRouter, Nvidia NIM, and local Ollama, alongside subscription OAuth flows for Claude Max, ChatGPT Pro, Gemini Advanced, Copilot Pro, and others.

The benchmark section is one of the stronger credibility signals in the README. Against the published xbow-validation-benchmarks suite, the project reports 45/45 on easy challenges, 50/51 on medium, and 7/8 on hard — an aggregate 102/104 (98.08%) — with a full per-challenge index, an attack-class matrix, and LangSmith traces available in the repository. There is also a comparison document against other AI pentest agents including Strix, PentestGPT, MAPTA, Cyber-AutoAgent, and commercial XBOW. Because the validation suite is itself published, the numbers are at least independently re-runnable, which is more than most projects in this category offer.

Interoperability is treated as a first-class concern. Decepticon exposes an MCP server that can be registered into coding agents such as Claude Code or Codex with a single decepticon mcp serve registration, after which decepticon skill install adds the operator guide to both agents. There is also a pip install decepticon client SDK for teams building products or research integrations on top of the agent factories, middleware, tools, and skills; the SDK routes LLM calls and sandbox execution to runtime services over HTTP via DECEPTICON_LLM__PROXY_URL and SANDBOX_URL, with a declarative PluginBundle surface and a safety gate documented for library consumers.

From a defensive perspective, the telemetry footprint is substantial and worth understanding even if you never run it. All execution happens inside a containerized Kali sandbox on a dedicated operational network, with tmux transcripts, a PostgreSQL management database, and a Neo4j graph of every finding. The planned Offensive Vaccine loop — attack, defend, verify — signals the maintainers' intent to close the loop into defense improvements, and blue teams studying autonomous adversary tradecraft will find the knowledge graph schema and MITRE ATT&CK-mapped OPPLAN structure instructive for purple-team exercise design.

The disclaimer is unambiguous and matches the editorial position here: do not use this project on any system or network without explicit written authorization from the system owner, and unauthorized access to computer systems is illegal. Within those boundaries — scoped penetration tests, lab ranges, benchmark environments — Decepticon is one of the more disciplined entries in the autonomous red teaming category, pairing real kill-chain execution with pre-generated rules of engagement, hardened network isolation, and reproducible benchmarks. For operators evaluating agent-assisted engagements, the two-network architecture, interactive-shell handling, and credential-aware fallback chains are the details most worth a close read of the docs/architecture.md and docs/engagement-workflow.md material.

Official project repository for BitterSecurity/Decepticon.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.