Skip to content
d5aintPublic

About

Automated red team reconnaissance and vulnerability audit framework for Raspberry Pi 5 field deployments.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

RedAudit

Automated red team reconnaissance and vulnerability audit framework for Raspberry Pi 5 field deployments.

Python 3.13 License: GPL v3 Platform: Raspberry Pi 5


Overview

RedAudit is a modular, field-deployable security audit framework designed to run on a headless Raspberry Pi 5. It orchestrates a full reconnaissance pipeline — from host discovery through vulnerability validation — and produces AI-enriched reports suitable for red team engagements and network security assessments.

Operates under an "Assume Breach" physical-access methodology with a minimal IDS footprint. All AI inference runs locally via Ollama — no client data ever leaves the device.


Key Features

  • Automated recon pipeline — passive sniffing, SYN scanning, service fingerprinting, VLAN hop detection, SMB enumeration, and AD enumeration
  • Vulnerability validation — Nmap NSE scripts with severity classification (Critical / High / Medium)
  • Nuclei integration — template-driven web vulnerability scanning
  • AI-enriched reports — offline Ollama inference summarizes findings and recommends remediations
  • Egress testing — jittered HTTPS exfiltration to validate DLP controls
  • Notification system — Slack / webhook alerts on scan completion
  • Offline-capable — runs headless on battery or PoE; no cloud dependency required

Requirements

  • Raspberry Pi 5 (Debian Trixie / 64-bit)
  • Python 3.13+
  • uv package manager
  • nmap, nuclei, and ollama installed on the OS
  • Root / sudo access for raw socket operations

Quick Start

# Clone the repository
git clone https://github.com/d5aint/RedAudit.git
cd RedAudit

# Bootstrap OS dependencies, Python venv, Nuclei binary, and Ollama models
chmod +x setup.sh && ./setup.sh

# Install Python dependencies
uv sync

# Run against a single target
sudo uv run python -m red_audit network -t 192.168.1.1

# Run against a CIDR range
sudo uv run python -m red_audit network -t 192.168.1.0/24

# Auto-discover live hosts first, then scan
sudo uv run python -m red_audit network -t auto

Reports are written to the reports/ directory.


Common Usage

# Passive zero-packet reconnaissance
sudo uv run python -m red_audit passive -i eth0 --timeout 600

# Nmap vulnerability scan on discovered hosts
sudo uv run python -m red_audit nmap -t auto -p 135,139,445

# SMB share enumeration (password auth)
sudo uv run python -m red_audit smb -t 192.168.1.0/24 -d CORP -u jsmith -p Password123!

# Active Directory enumeration
sudo uv run python -m red_audit ad -t 192.168.1.10 -d CORP.LOCAL -u jsmith -p Password123!

# Web application scanning with Nuclei
sudo uv run python -m red_audit web -t http://10.0.0.50:8080

Testing

# Run full test suite (206 tests across 20 modules)
uv sync --group dev
uv run pytest

# Run the AI code auditor (requires Ollama)
uv run python scripts/ai_code_auditor.py

Documentation

Full technical documentation — architecture, module reference, OPSEC deployment guide, systemd setup, and AI reporting — is in DOCS.md.


License

This project is licensed under the GNU General Public License v3.0.

About

Automated red team reconnaissance and vulnerability audit framework for Raspberry Pi 5 field deployments.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages