How it works
Three steps. Infinite operations.
Write a template
Define your operation as a JSON node graph. Nodes connect by parent_id (execution order) and context_from (data flow). Parametrize with {{target}}, {{user}}, {{password}}.
{ "id": "scan", "type": "core.shell",
"action": "nmap -sV {{target}}",
"parent_id": "root" }AI runs every node
Click Run. Altron walks the graph — parallel branches execute concurrently, conditional branches evaluate with shell exit codes or LLM judgment, for_each iterates lists.
[running] scan → nmap -sV 10.0.0.1 [found] 22/ssh 80/http 443/https [running] analyze → core.simple_task [done] 3 findings identified
Findings recorded automatically
core.session, core.credential, core.finding, and core.persistence nodes write structured records to the red team data model. Query, export, and build on them in future ops.
✓ Session: root@10.0.0.1 ✓ Cred: admin / Summer2024! ✓ Finding: Weak Password [CRIT] ✓ Persist: cron @ /etc/cron.d/
Features
Everything a red teamer needs.
Node graphs that run themselves
Every operation is a JSON plan template — a directed graph of typed nodes. Write it once, replay it anywhere. The node library covers shell commands, LLM tasks, web browsing, file writing, process control, and more.
- 26 built-in templates across 6 categories
- Parametric: swap targets without editing the graph
- Version-controlled JSON — diff, branch, share
- Custom templates auto-registered to the AI planner
Safety architecture
Deterministic by design.
Every node in Altron either runs a real, pre-authored action or narrates around data it didn't create. The only place the model ever actually chooses anything is a Decision node — and even then, only from a closed set of branches you wired into the graph yourself.
A Decision node's inspector — "Closed-set choice — the model can only pick one of the two branches wired below, never invent a third."
Closed-set decisions
A Decision node's valid answers are derived live from the graph — whatever branches you actually connected to it in the editor. The model returns one exact branch ID or the literal string "none." There's no way for it to answer with something that isn't already sitting on the canvas.
Narration, not authorship
An LLM can write the flavor text around an event, but never the event itself. Findings, hosts, credentials, and persistence are all structured records written by deterministic nodes — the model only describes what a pre-authored node already did.
Every step is inspectable
Open any node in the Tasks tab and see its full chain of thought — what it was told, what it decided, what it ran. Nothing executes off-graph, and nothing is hidden from the operator.
Safe enough to run live, unattended
The same engine now drives Mission Tree scenarios — Gate, Trigger, and Reaction nodes that react to a trainee in real time without ever letting the model author payload content. That's what makes a live, adversarial training exercise safe to leave running.
Template library
Ready-to-run attack plans.
26 templates across 6 categories
Screenshots
See Altron in action.
Roadmap
What's coming.
Mission Tree Editor
ShippedVisual scenario builder for live training exercises — Stage, Gate, Reaction, Trigger, and Decision nodes, connected by drag-and-drop, with live status updates as a mission runs.
Deterministic decision safety model
ShippedThe model only ever chooses from a closed set of branches an operator actually wired into the graph — it can narrate, but it can never author a new action or invent an option.
Character-driven narrative + trainee portal
ShippedMission-scoped cast with a live narrative feed, an SSH bastion that relays and records trainee sessions, and a dedicated trainee-facing web page.
Auto-generated mission reports
ShippedDeterministic technical appendix plus an LLM-narrated summary, scored against an operator-authored rubric — generated automatically when a mission completes.
Guided in-app tours
ShippedInteractive walkthroughs for every panel, including a full first-run onboarding flow that builds a real template and mission end to end.
26 built-in red team templates
ShippedFull library of ready-to-run offensive operation templates across recon, initial access, priv-esc, persistence, lateral movement, and more.
Node graph template editor
ShippedVisual JSON node graph editor for building and editing operation templates directly in the GUI.
Graphiti memory integration
ShippedPersistent long-term memory via Graphiti — entities, relationships, and findings persist across operations.
Red team data model (sessions, creds, findings, persistence)
ShippedStructured recording of all red team artifacts: sessions, credentials, findings, and persistence mechanisms.
Custom LLM provider support
ShippedSwap the local Ollama executor for Claude, OpenAI, or any OpenAI-compatible endpoint (LM Studio, vLLM, llama.cpp) per backend, with automatic fallback.
CoT-driven red team panel auto-population
In ProgressChain-of-thought output automatically populates the red team panel — no explicit recording nodes needed in templates.
Operator timeout extension prompt
In ProgressWhen a node times out, the operator is prompted with an LLM time estimate and the option to extend before retrying.
Windows AD attack template library
PlannedA full library of Active Directory attack templates: AS-REP roasting, Kerberoasting, DCSync, NTLM relay, and more.
Collaborative multi-operator mode
PlannedMultiple operators share a live mission session, with role-based access and real-time task coordination.
Mobile operator dashboard
PlannedRead-only mobile view of active mission state: live task tree, findings, sessions, and credentials.
Tasks tab
Inspect every step.
Every task is a tree. Drill into any completed node to replay its chain of thought — see exactly how the AI planned and executed each action, with full context in and out.
Pricing
Currently in beta. Join the waitlist.
Built for operators.
Join the beta.
Altron runs entirely on your machine. No telemetry. No cloud dependency. Your ops stay yours.
Request Beta Access


