RedAmon

Web · Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

RedAmon is a free, open-source framework for authorized security testing that automates reconnaissance, exploitation, and post-exploitation operations. Its parallel reconnaissance process maps attack surfaces from domains, IP/CIDR targets, or domain batches, then combines findings in a Neo4j graph for AI-assisted planning and exploitation. GVM/OpenVAS integration supports network vulnerability scanning with more than 170,000 NVTs; separate tools detect secrets and vulnerable or malicious packages. RedAmon supports twelve AI providers and more than 400 language models, and its MCP server allows external agents to drive the framework. The Dockerized application runs on Linux, macOS, and Windows and can be deployed on-premises. Separate containers, temporary per-job filesystems, and network namespaces isolate tools and agents. Rules of Engagement, approval gates, and scope controls govern operations, with a guardrail blocking government, military, and intergovernmental targets. On macOS, SYN-based scanners cannot see the local LAN because they run inside Docker Desktop's LinuxKit VM. The project warns that API keys and credentials are stored unencrypted in PostgreSQL, which users are responsible for securing.

Who it is for

RedAmon suits security professionals, educators, and researchers conducting authorized testing. It is intended for users who can manage a self-hosted Docker deployment and secure its PostgreSQL database.

What is good

  • Maps targets into a Neo4j attack-surface graph
  • GVM/OpenVAS scanning includes over 170,000 NVTs
  • Supports twelve AI providers
  • Runs on Linux, macOS, and Windows
  • Includes scope controls and approval gates

What to know first

  • Credentials are stored unencrypted in PostgreSQL
  • macOS SYN scanners cannot see the local LAN
  • Intended only for authorized security testing

Verdict

RedAmon brings reconnaissance, scanning, and AI-driven operations together in a self-hosted framework. Review its macOS scanning limitation and database credential warning before deployment.

RedAmon plans and pricing

All plans
Open-source self-hosted Free MIT license · Docker stack · commercial and personal use redamon.org · 1 Oct 2026

Compared on penetration testing software

Free plan
Yes

Best RedAmon alternatives

See all 20