DECEPTICON / A BITTER SECURITY PRODUCT

The agent harnessfor securityresearch.

Coordinate specialist agents, tools, infrastructure, and evidence inside the scope you approve.

Open inquiry. Bounded action. Verifiable results.See it in practice

This isn't a script. It's a transcript.

Every sentence on screen is what the agent printed while it found a SQL injection on a login form, chained it into a cross-tenant read, and re-tested all sixteen findings against a negative control.

Recorded on a read-only sample engagement. The transcript, findings and evidence are real run output.
Public access

Preview first. Pay when you operate.

Platform membership funds the control plane and isolated runtime. Model usage stays separate through your own provider key or managed credits, so the fixed fee never hides variable token spend.

Free Preview
$0
Guided sample, cached public programs, and read-only engagement history. No card required.
Solo
$19 / month
One operator, live agents, isolated runtime, and report-ready evidence.
Pro
$39 / month
Three seats, parallel operations, more runtime, and the shared agent Browser.

Attackers are already using AI

Autonomous offense is here. The question is whether your red team runs with the same leverage, under rules you set.

  • Autonomy needs controls

    Agents stay bounded by scope, Rules of Engagement, OPSEC posture, and explicit operator concessions.

  • Plans must survive execution

    The OPPLAN tracks objectives, blockers, pivots, evidence, and next actions as the run changes.

  • Expertise should be reusable

    Specialist agents load Skillogy knowledge and ATT&CK context instead of relying on one generic prompt.

Highest published pass rate.

Pass rate across 104 real-world exploitation challenges, against every publicly reported agent.

Decepticon
98.08%
Strix
96.15%
Shannonwhite-box
96.15%
PentestGPT
86.5%
Red-MIRROR
86%
XBOWcommercial
85%
Cyber-Auto
84.62%
MAPTA
76.9%
PentestAgent
50%
AutoPT
46%
VulnBot
6%

Decepticon: black-box, vulnerability tags as hint, 102 / 104 solved. Shannon shown white-box, hint-removed. Figures as published by each project.

Questions operators ask.

Is it safe to run against real targets?
Every action is bounded by scope and Rules of Engagement enforced at runtime. Out-of-scope actions are blocked before they fire, and OPSEC posture stays under operator control.
How is this different from a single AI agent?
Recon, initial access, and post-exploitation run as specialist sub-agents grounded in ATT&CK and Skillogy playbooks, not one generic prompt. You watch each one work in real time.
Do I stay in control of the run?
Yes. You set the OPPLAN up front through a guided interview. It tracks objectives, blockers, pivots, and evidence, and updates as the run evolves. You approve scope and every concession.
What proof is there that it works?
Highest published pass rate on the XBOW validation benchmark: 98.08% (102 of 104 challenges), ahead of every publicly reported agent.
How do I try it?
Sign in and a guided demo walks you through a read-only sample engagement at no cost. Bring your own scope when you are ready to run.
What does it cost?
The guided demo and sample engagement are free. See current plans on the pricing page.

Run adversary emulation under control.

Start with scope, RoE, and an OPPLAN. Decepticon keeps autonomous red-team execution observable, constrained, and ATT&CK-mapped.

curl -fsSL https://decepticon.red/install | bash