RedAmon is a free, open-source framework for authorized security testing that automates reconnaissance, exploitation, and post-exploitation operations. Its parallel reconnaissance process maps attack surfaces from domains, IP/CIDR targets, or domain batches, then combines findings in a Neo4j graph for AI-assisted planning and exploitation. GVM/OpenVAS integration supports network vulnerability scanning with more than 170,000 NVTs; separate tools detect secrets and vulnerable or malicious packages. RedAmon supports twelve AI providers and more than 400 language models, and its MCP server allows external agents to drive the framework. The Dockerized application runs on Linux, macOS, and Windows and can be deployed on-premises. Separate containers, temporary per-job filesystems, and network namespaces isolate tools and agents. Rules of Engagement, approval gates, and scope controls govern operations, with a guardrail blocking government, military, and intergovernmental targets. On macOS, SYN-based scanners cannot see the local LAN because they run inside Docker Desktop's LinuxKit VM. The project warns that API keys and credentials are stored unencrypted in PostgreSQL, which users are responsible for securing.
Who it is for
RedAmon suits security professionals, educators, and researchers conducting authorized testing. It is intended for users who can manage a self-hosted Docker deployment and secure its PostgreSQL database.
What is good
- Maps targets into a Neo4j attack-surface graph
- GVM/OpenVAS scanning includes over 170,000 NVTs
- Supports twelve AI providers
- Runs on Linux, macOS, and Windows
- Includes scope controls and approval gates
What to know first
- Credentials are stored unencrypted in PostgreSQL
- macOS SYN scanners cannot see the local LAN
- Intended only for authorized security testing
Verdict
RedAmon brings reconnaissance, scanning, and AI-driven operations together in a self-hosted framework. Review its macOS scanning limitation and database credential warning before deployment.
RedAmon plans and pricing
All plansCompared on penetration testing software
- Free plan
- Yes