Automated red team reconnaissance and vulnerability audit framework for Raspberry Pi 5 field deployments.
RedAudit is a modular, field-deployable security audit framework designed to run on a headless Raspberry Pi 5. It orchestrates a full reconnaissance pipeline — from host discovery through vulnerability validation — and produces AI-enriched reports suitable for red team engagements and network security assessments.
Operates under an "Assume Breach" physical-access methodology with a minimal IDS footprint. All AI inference runs locally via Ollama — no client data ever leaves the device.
- Automated recon pipeline — passive sniffing, SYN scanning, service fingerprinting, VLAN hop detection, SMB enumeration, and AD enumeration
- Vulnerability validation — Nmap NSE scripts with severity classification (Critical / High / Medium)
- Nuclei integration — template-driven web vulnerability scanning
- AI-enriched reports — offline Ollama inference summarizes findings and recommends remediations
- Egress testing — jittered HTTPS exfiltration to validate DLP controls
- Notification system — Slack / webhook alerts on scan completion
- Offline-capable — runs headless on battery or PoE; no cloud dependency required
- Raspberry Pi 5 (Debian Trixie / 64-bit)
- Python 3.13+
uvpackage managernmap,nuclei, andollamainstalled on the OS- Root /
sudoaccess for raw socket operations
# Clone the repository
git clone https://github.com/d5aint/RedAudit.git
cd RedAudit
# Bootstrap OS dependencies, Python venv, Nuclei binary, and Ollama models
chmod +x setup.sh && ./setup.sh
# Install Python dependencies
uv sync
# Run against a single target
sudo uv run python -m red_audit network -t 192.168.1.1
# Run against a CIDR range
sudo uv run python -m red_audit network -t 192.168.1.0/24
# Auto-discover live hosts first, then scan
sudo uv run python -m red_audit network -t autoReports are written to the reports/ directory.
# Passive zero-packet reconnaissance
sudo uv run python -m red_audit passive -i eth0 --timeout 600
# Nmap vulnerability scan on discovered hosts
sudo uv run python -m red_audit nmap -t auto -p 135,139,445
# SMB share enumeration (password auth)
sudo uv run python -m red_audit smb -t 192.168.1.0/24 -d CORP -u jsmith -p Password123!
# Active Directory enumeration
sudo uv run python -m red_audit ad -t 192.168.1.10 -d CORP.LOCAL -u jsmith -p Password123!
# Web application scanning with Nuclei
sudo uv run python -m red_audit web -t http://10.0.0.50:8080# Run full test suite (206 tests across 20 modules)
uv sync --group dev
uv run pytest
# Run the AI code auditor (requires Ollama)
uv run python scripts/ai_code_auditor.pyFull technical documentation — architecture, module reference, OPSEC deployment guide, systemd setup, and AI reporting — is in DOCS.md.
This project is licensed under the GNU General Public License v3.0.