Offensive Security
Automation
Platform.

Altron is a deployment platform for offensive security operations. Define workflows as JSON node graphs, deploy them in one click, and let the local AI executor drive each step — shell commands, browser actions, LLM reasoning — while recording every finding automatically.

Request Beta AccessSee how it works →
org.rootStartcore.shellnmap scancore.researchOSINTcore.taskAnalyzecore.sessionRecord
INITIALIZING

Three steps. Infinite operations.

01

Write a template

Define your operation as a JSON node graph. Nodes connect by parent_id (execution order) and context_from (data flow). Parametrize with {{target}}, {{user}}, {{password}}.

{ "id": "scan", "type": "core.shell",
  "action": "nmap -sV {{target}}",
  "parent_id": "root" }
02

AI runs every node

Click Run. Altron walks the graph — parallel branches execute concurrently, conditional branches evaluate with shell exit codes or LLM judgment, for_each iterates lists.

[running] scan → nmap -sV 10.0.0.1
[found]   22/ssh  80/http  443/https
[running] analyze → core.simple_task
[done]    3 findings identified
03

Findings recorded automatically

core.session, core.credential, core.finding, and core.persistence nodes write structured records to the red team data model. Query, export, and build on them in future ops.

✓ Session: root@10.0.0.1
✓ Cred: admin / Summer2024!
✓ Finding: Weak Password [CRIT]
✓ Persist: cron @ /etc/cron.d/

Everything a red teamer needs.

Node graphs that run themselves

Every operation is a JSON plan template — a directed graph of typed nodes. Write it once, replay it anywhere. The node library covers shell commands, LLM tasks, web browsing, file writing, process control, and more.

  • 26 built-in templates across 6 categories
  • Parametric: swap targets without editing the graph
  • Version-controlled JSON — diff, branch, share
  • Custom templates auto-registered to the AI planner
org.rootMission Startcore.shellnmap -sV scancore.researchOSINT lookupcore.simple_taskAnalyze resultscore.sessionRecord session
typeorg.roottitleMission Startparent_idnull

Deterministic by design.

Every node in Altron either runs a real, pre-authored action or narrates around data it didn't create. The only place the model ever actually chooses anything is a Decision node — and even then, only from a closed set of branches you wired into the graph yourself.

Mission Tree Decision node — the model can only pick from branches actually wired into the graph

A Decision node's inspector — "Closed-set choice — the model can only pick one of the two branches wired below, never invent a third."

  • Closed-set decisions

    A Decision node's valid answers are derived live from the graph — whatever branches you actually connected to it in the editor. The model returns one exact branch ID or the literal string "none." There's no way for it to answer with something that isn't already sitting on the canvas.

  • Narration, not authorship

    An LLM can write the flavor text around an event, but never the event itself. Findings, hosts, credentials, and persistence are all structured records written by deterministic nodes — the model only describes what a pre-authored node already did.

  • Every step is inspectable

    Open any node in the Tasks tab and see its full chain of thought — what it was told, what it decided, what it ran. Nothing executes off-graph, and nothing is hidden from the operator.

  • Safe enough to run live, unattended

    The same engine now drives Mission Tree scenarios — Gate, Trigger, and Reaction nodes that react to a trainee in real time without ever letting the model author payload content. That's what makes a live, adversarial training exercise safe to leave running.

Ready-to-run attack plans.

26 templates across 6 categories

Initial Reconnaissance

reconnmapmasscan
rt-recon-init.json

Initial Access — Default Credential Spray

initial-accessspraycredentials
rt-init-access.json

Web Application Attack — Default Creds, RCE, Shell Upload

webappJenkinsTomcat
rt-webapp.json

Privilege Escalation — Linux Host

privescsudoSUID
rt-privesc.json

Post-Root Credential Harvesting

credential-harvestshadowhashcat
rt-cred-harvest.json

LLMNR/NBT-NS Poisoning and NTLM Relay

BETA
responderNTLMrelay
rt-responder.json

SOCKS Pivot — Tunnel Through Compromised Host

pivotsocks5tunnel
rt-pivot-socks.json

Lateral Movement — Credential-Based Pivot

BETA
lateral-movementsshsmb
rt-lateral-move.json

AD Lateral Movement — Pass-the-Hash / WinRM

BETA
pass-the-hashwinrmad
rt-ad-lateral.json

Active Directory Full Enumeration

BETA
ad-enumbloodhoundldap
rt-ad-enum.json

Kerberoasting and AS-REP Roasting

BETA
kerberoastas-rephashcat
rt-ad-kerberoast.json

Full Domain Compromise — DCSync, Golden Ticket, DA Backdoor

BETA
dcsyncgolden-ticketkrbtgt
rt-domain-own.json

Start Reverse Shell Listeners

listenersc2reverse-shell
rt-start-listeners.json

OPSEC — Log Cleanup and Artifact Removal

opseccleanuplogs
rt-opsec-clean.json

Op Start — Full Red Team Init Sequence

BETA
workflowinitmacro
rt-op-start.json

LabGen Report Parse — Lab Doc to Ground Truth

labgenparsegroundtruth
labgen-report-parse.json

LabGen Report Parse (LLM) — Chunked Extraction

BETA
labgenparsellm
labgen-report-parse-llm.json

See Altron in action.

ScreenshotMission Tree Editor — Stage, Gate, Reaction, Trigger, and Decision nodes
ScreenshotDecision node — closed-set choice, wired branches only
ScreenshotLLM-narrated reaction — narration only, never authorship
ScreenshotCharacter cast + live trainee narrative feed

What's coming.

Mission Tree Editor

Shipped

Visual scenario builder for live training exercises — Stage, Gate, Reaction, Trigger, and Decision nodes, connected by drag-and-drop, with live status updates as a mission runs.

Deterministic decision safety model

Shipped

The model only ever chooses from a closed set of branches an operator actually wired into the graph — it can narrate, but it can never author a new action or invent an option.

Character-driven narrative + trainee portal

Shipped

Mission-scoped cast with a live narrative feed, an SSH bastion that relays and records trainee sessions, and a dedicated trainee-facing web page.

Auto-generated mission reports

Shipped

Deterministic technical appendix plus an LLM-narrated summary, scored against an operator-authored rubric — generated automatically when a mission completes.

Guided in-app tours

Shipped

Interactive walkthroughs for every panel, including a full first-run onboarding flow that builds a real template and mission end to end.

26 built-in red team templates

Shipped

Full library of ready-to-run offensive operation templates across recon, initial access, priv-esc, persistence, lateral movement, and more.

Node graph template editor

Shipped

Visual JSON node graph editor for building and editing operation templates directly in the GUI.

Graphiti memory integration

Shipped

Persistent long-term memory via Graphiti — entities, relationships, and findings persist across operations.

Red team data model (sessions, creds, findings, persistence)

Shipped

Structured recording of all red team artifacts: sessions, credentials, findings, and persistence mechanisms.

Custom LLM provider support

Shipped

Swap the local Ollama executor for Claude, OpenAI, or any OpenAI-compatible endpoint (LM Studio, vLLM, llama.cpp) per backend, with automatic fallback.

CoT-driven red team panel auto-population

In Progress

Chain-of-thought output automatically populates the red team panel — no explicit recording nodes needed in templates.

Operator timeout extension prompt

In Progress

When a node times out, the operator is prompted with an LLM time estimate and the option to extend before retrying.

Windows AD attack template library

Planned

A full library of Active Directory attack templates: AS-REP roasting, Kerberoasting, DCSync, NTLM relay, and more.

Collaborative multi-operator mode

Planned

Multiple operators share a live mission session, with role-based access and real-time task coordination.

Mobile operator dashboard

Planned

Read-only mobile view of active mission state: live task tree, findings, sessions, and credentials.

Inspect every step.

Every task is a tree. Drill into any completed node to replay its chain of thought — see exactly how the AI planned and executed each action, with full context in and out.

○TASKS▾
TASK HISTORY43 ENTRIES
List the files in the current directory and give me a one-line summary of what this project is.
Sep 25, 19:39DUR: 20.7sCOMPLETEqwen2.5:7b
[DEMO] Web App Assessment — Host Status Seed
Sep 25, 19:38DUR: 110msCOMPLETEqwen2.5:7b
[DEMO] Web App Assessment — Screenshot Seed
Sep 25, 19:35DUR: 261msCOMPLETEqwen2.5:7b

Currently in beta. Join the waitlist.

Built for operators.
Join the beta.

Altron runs entirely on your machine. No telemetry. No cloud dependency. Your ops stay yours.

Request Beta Access