Red team engagements run from a single terminal command
RedCell automates the full authorized red team lifecycle — reconnaissance, attack surface mapping, vulnerability discovery, exploit verification, and delivery-ready reporting — all enforced inside your defined scope and rules of engagement.
The RedCell red team engagement lifecycle
What RedCell does in a red team engagement
Autonomous attack surface mapping
RedCell maps your authorized target from the outside in — passive OSINT, subdomain enumeration, port scanning, and service fingerprinting — before any exploitation attempt.
CVE discovery & exploit verification
The agent scans for known CVEs using web-nuclei templates and verifies each finding with a real proof-of-concept check — cutting false positives before they reach your report.
Dark-web exposure analysis
RedCell queries Tor onion services for leaked credentials, paste dumps, and exposed data linked to your target — a step most red team workflows skip entirely.
Scope-guard enforcement
Every action is verified against the defined scope and rules of engagement. Out-of-scope targets, rate-limit violations, and prohibited techniques are blocked before execution.
MCP extensibility for custom tools
Connect your existing exploit scripts, custom MCP servers, and native security binaries into RedCell workflows — the agent orchestrates them as part of the engagement.
Executive & technical reporting
Findings are automatically logged with severity scores, evidence, and reproduction steps. Export to Markdown for technical review or JSON for downstream processing.
Built for professional red teamers
Authorized scope, always
RedCell enforces your defined scope on every single action. No accidental out-of-scope contacts, rate-limit violations, or impact breaches.
Extend with your own toolchain
Use MCP extensibility to plug your existing scripts, Metasploit modules, and custom binaries into the agent as orchestrated tools.
Session continuity
RedCell saves engagement state to ~/.redcell/sessions/. Resume or fork sessions across multiple days of a longer engagement.
Headless CI execution
Use redcell exec "<task>" for scripted, automated engagement steps in CI/CD pipelines and scheduled security jobs.
Run your first red team engagement today
Free plan. Single binary. No external dependencies.