Skip to content

About

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

 
 

Latest commit

 

History

977 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

RedAmon / The Red House

🔴 THE RED HOUSE

XUNIA Authorized Security • Knowledge Graph • AI Triage • Remediation

The Red House is XUNIA’s authorized adversarial-security and remediation layer. It converts controlled security testing into structured findings, ontology-ready relationships, prioritized risk, evidence, and reviewable fixes that can flow back into the wider XUNIA ecosystem.

XUNIA Ecosystem Guide · Ecosystem Manifest · Full RedAmon Documentation · Security Policy

AUTHORIZED USE ONLY: The Red House is for systems you own or have explicit written authorization to assess. Cross-house membership, repository access, or ecosystem affiliation does not create authorization to test an external target.


XUNIA ecosystem role

XUNIA HQ / CONTROL PLANE
          ↓
   🔴 THE RED HOUSE
   ├─ authorized reconnaissance
   ├─ controlled validation
   ├─ security knowledge graph
   ├─ AI finding triage
   ├─ risk normalization
   └─ remediation / reviewable PRs
          ↓
   SHARED XUNIA ONTOLOGY
          ↓
BLACK HOUSE • GREEN HOUSE / BIO • ZYRA • APPROVED SERVICES

The Red House wraps the upstream RedAmon security framework with a XUNIA integration contract. The underlying project provides containerized reconnaissance, security validation, Neo4j attack-surface graphs, AI-assisted triage, and remediation workflows. The XUNIA layer adds ecosystem identity, ontology bindings, cross-house boundaries, and machine-readable integration metadata.

Core ecosystem objects

Object Role
Asset Approved host, service, repository, API, container, or environment
Finding Normalized security observation or vulnerability
Evidence Reproducible evidence attached to a finding
Risk Severity, exploitability, exposure, confidence, and impact
Relationship Graph edge linking assets, identities, findings, controls, and fixes
Control Defensive policy or technical safeguard
Remediation Proposed or implemented fix
ChangeSet Reviewable code/configuration mutation
Run Auditable execution record

BIO / Green House boundary: biotechnology, health, pharma, research, or similarly sensitive workloads are treated as high-sensitivity and non-destructive by default. External activity requires explicit scope and authorization.


Maintainers & ecosystem stewards

Samuele Giampieri
Samuele Giampieri
Upstream Creator, Maintainer & AI Platform Architect

AI platform architect and full-stack lead behind RedAmon, with production experience across agentic AI, ML, cloud systems, and security automation.

LinkedIn · GitHub · Devergo Labs
Ritesh Gohil
Ritesh Gohil
Upstream Maintainer & Lead Security Researcher

Security engineer and researcher with experience across Web, API, Mobile, Network, and Cloud penetration testing, CVE research, and security architecture.

LinkedIn · GitHub
Douglas Brown
Douglas Brown
XUNIA Ecosystem Maintainer & AI/Security Systems Builder

Maintainer of the XUNIA / ZYRA integration layer, focused on governed agentic systems, security architecture, ontology-driven workflows, AI application development, and auditable human-controlled execution. ZYRA currently records a reconciled 34-record credential, training, and professional-development ledger with evidence tiered by issuer verification and supplied provenance.

Selected credential evidence
Palantir Foundry Aware · Introduction to Foundry & AIP for Enterprise Organizations · Deep Dive: Data Protection Tools in Foundry · Palantir Data Science Fundamentals · Google Cybersecurity Professional Certificate · Google AI Professional Certificate · IBM Quantum Machine Learning · Red Hat System Administration I training · Foundations of Business Intelligence.

LinkedIn · GitHub · ZYRA
Credential ledger

Attribution boundary: Samuele Giampieri and Ritesh Gohil are identified here for their upstream RedAmon roles. Douglas Brown’s maintainer role applies to the sonoxo/theredhouse XUNIA integration/fork and does not imply maintainer status in the upstream samugit83/redamon project.


Upstream platform

The Red House is built around the open-source RedAmon framework. To keep the complete technical documentation, architecture, installation instructions, tool matrix, security model, community information, and original maintainer material intact, the previous README is preserved verbatim here:

Upstream project: samugit83/redamon
Upstream website: redamon.org


XUNIA integration contract

The machine-readable integration contract lives at .xunia/ecosystem.json. Current Red House capabilities include:

  • authorized reconnaissance and controlled security validation;
  • security knowledge-graph generation;
  • finding triage and risk normalization;
  • remediation orchestration and reviewable GitHub PR flows;
  • security telemetry export into approved XUNIA ontology consumers;
  • explicit authorization context and human review for disruptive actions;
  • no implicit cross-house authorization.

See XUNIA_ECOSYSTEM.md for the human-readable architecture and operating boundaries.


Repository map

Resource Purpose
XUNIA_ECOSYSTEM.md Red House role inside the ecosystem
.xunia/ecosystem.json Machine-readable ecosystem identity and ontology contract
UPSTREAM_REDAMON_README.md Preserved complete upstream-facing README
SECURITY.md Security policy
DISCLAIMER.md Authorized-use and legal boundaries
LICENSE Repository license
THIRD-PARTY-LICENSES.md Third-party licensing inventory
ZYRA credential ledger Douglas Brown credential/provenance evidence used by this fork

🔴 RED HOUSE // XUNIA
Authorized security in. Structured evidence out. Human control at consequential boundaries.

About

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages