FLAGSHIP / DECEPTICON

A continuous attack graph for the operator in the loop.

Decepticon is an Apache-2.0 autonomous hacking agent for red teams. It carries context across an authorized engagement while human operators keep control of scope, risk, and evidence.

Request early access
decepticon / system graphSCOPE: LOCKED
D:DECEPTICONLANGGRAPH ORCHESTRATOR
NEO4JSLIVERGHIDRAMITRE
HUMAN APPROVALENFORCED
01 / SYSTEM/real-stack

An agent stack built around continuity.

Each component has a distinct job. The orchestration layer holds the plan, the graph holds relationships, specialist tools handle analysis, and MITRE ATT&CK keeps the evidence legible.

ORCH

LangGraph

Stateful agent orchestration

GRAPH

Neo4j

Attack-graph memory

C2

Sliver C2

Authorized C2 operations

IDENT

BloodHound CE

Identity path analysis

RE

Ghidra MCP

Reverse-engineering interface

MAP

MITRE ATT&CK

Technique mapping and evidence

ISO

Kali sandbox

Controlled execution boundary

02 / DEPLOY/choose-boundary

Meet the team at its control boundary.

Choose the deployment model that matches your engagement, data, and infrastructure constraints. The underlying open-source project remains inspectable.

MANAGED

Cloud

A managed deployment path for teams that want a controlled operating surface without owning the runtime layer.

YOUR BOUNDARY

Self-host

Run Decepticon inside infrastructure your team controls, aligned to your network and evidence requirements.

OPEN SOURCE

Python package

Install the Apache-2.0 project directly for inspection, testing, and local operator workflows.

EXACT VALIDATION RESULT
102/10498%

on the XBOW validation benchmarks

DIFFICULTYCOMPLETEDRATE
Easy45/45100%
Medium50/5198%
Hard7/887.5%

Benchmark performance is a validation data point, not a promise of outcomes on every environment or engagement.

03 / OPERATOR CONTRACT/accountability

Autonomy inside a human-owned engagement.

The product is positioned to extend a professional red team, not replace it. Authorization, scope, approval, and remediation ownership stay with people.

Before execution

  • Written authorization and rules of engagement
  • Explicit assets, identities, and prohibited actions
  • Human approval points and stop conditions

During the engagement

  • Controlled execution inside the agreed boundary
  • MITRE-mapped evidence for operator review
  • Escalation paths for uncertain or high-risk actions

After validation

  • Reproducible findings and attack-path context
  • Human prioritization and remediation decisions
  • Evidence handling aligned to engagement policy
EARLY ACCESS

Bring Decepticon into the red-team workflow.

Tell us how your team operates and which deployment boundary you prefer. The waitlist collects interest only.