Decepticon
Autonomous Hacking Agent for Red Team
Decepticon is an autonomous red team AI agent built to execute professional penetration testing engagements with realistic attack chains spanning reconnaissance, exploitation, privilege escalation, and lateral movement. It operates 16 specialist sub-agents organized by kill-chain phase, each with fresh context windows, and runs all offensive tools in isolated Kali Linux sandbox environments. Before any testing begins, the agent generates complete engagement documentation including Rules of Engagement, Concept of Operations, and MITRE ATT&CK-mapped operational plans. The system achieves 98% pass rate on XBOW validation benchmarks and supports both self-hosted Docker deployment and cloud-hosted browser access.
Key Features
Use Cases
- 01Autonomous penetration testing engagements following professional red team methodology
- 02Active Directory attack path discovery and lateral movement simulation
- 03Multi-stage exploitation chains with privilege escalation and persistence
- 04Cloud infrastructure security assessments with automated reconnaissance and exploitation
- 05Smart contract vulnerability research and blockchain security testing
- 06Binary reverse engineering with integrated Ghidra MCP server automation
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
Decepticon — FAQ
What is Decepticon?+
Decepticon is an autonomous red team AI agent that executes professional penetration testing engagements with realistic attack chains. It coordinates 16 specialist sub-agents to perform reconnaissance, exploitation, privilege escalation, and lateral movement while generating complete engagement documentation including Rules of Engagement and MITRE ATT&CK-mapped operational plans.
How do I install Decepticon?+
Decepticon requires Docker and Docker Compose v2. On macOS, Linux, or WSL2, run the install script with curl, then execute 'decepticon onboard' for interactive setup and 'decepticon' to start. On Windows PowerShell, use the .ps1 install script. Alternatively, install via pip with 'pip install decepticon' to use as a library, though runtime services are still required.
What API keys or prerequisites does Decepticon need?+
Decepticon requires Docker and Docker Compose v2 as prerequisites. During the onboard wizard, you configure LLM provider credentials (Anthropic, OpenAI, Google Gemini, DeepSeek, xAI, Mistral, or local Ollama) and select a model profile. The agent supports subscription OAuth for Claude Max/Pro, ChatGPT Pro/Plus, Gemini Advanced, and other services.
Is Decepticon free to use?+
Decepticon is open source under the Apache-2.0 license. The software itself is free, but you need LLM provider API access or subscriptions. A cloud-hosted version is available at app.decepticon.red for users who don't want to self-host.
Which AI clients or platforms does Decepticon work with?+
Decepticon is a standalone autonomous agent system, not a plugin for other AI clients. It provides its own terminal CLI and web dashboard interfaces. The agent orchestrates LLM calls through LiteLLM proxy supporting multiple providers including Anthropic, OpenAI, Google Gemini, and local Ollama models.
Can I use Decepticon legally?+
You must obtain explicit written authorization from system owners before using Decepticon on any network or system. Unauthorized access to computer systems is illegal, and users are solely responsible for their actions and compliance with applicable laws.
How do I install Decepticon?+
Open the source repository on GitHub and follow its README. Decepticon is a agent — MCP Agents Market links you directly to the official repo.
Is Decepticon free?+
Decepticon is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.