
Decepticon v1.1.44
Autonomous AI-driven red team agent that executes realistic attack chains—reconnaissance, exploitation, privilege escalation, lateral movement, and C2—with hardened sandbox isolation and MITRE ATT&CK-mapped engagement planning.
Decepticon — Autonomous Red Team Agent
"Another AI hacker? Let us guess — it runs nmap and writes a report."
Commercial product demo
☁️ Don't want to self-host? Decepticon is live in the cloud.
Skip the Docker setup — run autonomous red-team engagements right from your browser.
Open-source CLI demo
Install
Prerequisites: Docker and Docker Compose v2. Supported on macOS (Apple Silicon + Intel), Linux (amd64 + arm64), and Windows (amd64 + arm64) — native via PowerShell or via WSL2 (Ubuntu / Kali).
macOS / Linux / WSL2
curl -fsSL https://decepticon.red/install | bash
decepticon onboard # Interactive setup wizard (provider, API key, model profile)
decepticon # Start the core stack and drop into the terminal CLI
The default start brings up the core management plane (LiteLLM, PostgreSQL, Neo4j, Skillogy, LangGraph, sandbox) and launches the terminal CLI. Specialist workloads (BloodHound CE, Sliver C2, Ghidra MCP, …) and the web dashboard come up on demand — the orchestrator spawns specialists via ops_start("ad") etc., and you bring up the dashboard from inside the CLI with /web (see Web Dashboard).
Windows (PowerShell, native)
irm https://decepticon.red/install.ps1 | iex
decepticon onboard
decepticon
→ Quick start · Full setup walkthrough
Use from Claude Code or Codex
After starting Decepticon, register its MCP server in your coding agent:
claude mcp add --scope user decepticon -- decepticon mcp serve
codex mcp add decepticon -- decepticon mcp serve
Use the command for the coding agent you have installed, then run
decepticon skill install to add the operator guide to both agents. See the
external agent guide for the Agent Skill,
tool workflow, and source installation path.
Use as a library (pip)
Building on top of the agents — a product, a research integration, or a custom orchestrator? Install the SDK from PyPI:
pip install decepticon # core SDK
pip install "decepticon[neo4j]" # + the knowledge-graph attack-chain tools
decepticon is a client SDK: it ships the agent factories, middleware, tools, and skills, and routes LLM calls and sandbox execution to runtime services over HTTP (DECEPTICON_LLM__PROXY_URL, SANDBOX_URL). Running agents still needs those services — use the Docker stack above, or point the URLs at your own equivalents. See Decepticon as a library for the factory override surface, declarative PluginBundle plugins, and the safety gate.
💖 Support Decepticon
We're building Decepticon toward an Offensive Vaccine for the AI-driven threat landscape. If you believe in autonomous red teaming as a path to stronger defense, consider supporting the project.
Benchmark
| Benchmark | Difficulty | Pass Rate |
|---|---|---|
| XBOW validation-benchmarks | Easy (Level 1) | 45 / 45 (100 %) |
| XBOW validation-benchmarks | Medium (Level 2) | 50 / 51 (98.0 %) |
| XBOW validation-benchmarks | Hard (Level 3) | 7 / 8 (87.5 %) |
| XBOW validation-benchmarks | All levels | 102 / 104 (98.08 %) |
- Full per-challenge index, attack-class matrix, and LangSmith traces
- Comparison vs other AI pentest agents (Strix, PentestGPT, MAPTA, Cyber-AutoAgent, XBOW commercial, …)
What is Decepticon?
The "AI + hacking" space is full of demos that run nmap and print a report. That's not what this is.