Skip to content

Releases: devZero-Security/redStackPRO

redStackPRO v0.9.0

Choose a tag to compare

@BaddKharma BaddKharma released this 28 Sep 22:42

redStackPRO v0.9.0

First public release. Pre-release: the pipeline works end to end, with more to come
before 1.0.

redStackPRO is a web canvas where you build red team infrastructure and cyber ranges
as a provider-agnostic topology, then export a complete, runnable working directory of
Terraform and Ansible. You run the export from your own machine. redStackPRO never
holds your cloud credentials and never deploys anything itself. The export is the
boundary.

One MIT tool, full feature set. There is no community vs pro split.

Highlights

  • One canvas, two modes. Offense for attack and operator infrastructure, Defense for
    defensive Active Directory ranges. One schema, one validator, one compiler, one
    export shape. The mode only gates the palette.
  • Compiles to what you already run. A topology becomes Terraform for the cloud and
    Ansible for the hosts, plus a briefing on what is planted where. Fill in your
    variables and run it.
  • API-first and agent-operable. The canvas is a thin layer over a local API and
    CLI; an agent can read the schema and drive compose, validate, and compile locally.
  • Solutions ship with the ranges. Each target range carries a written walkthrough,
    so a range is something you can practice against, not just stand up.

New in this release

  • Multi-user VPN access for attack infrastructure. An attack-infrastructure jumpbox can name a list
    of operators (handle plus role). Set its access mode to WireGuard or OpenVPN and every
    operator gets a personal tunnel config plus a Guacamole portal login; the portal then
    sits behind the tunnel instead of on a public port. Per-operator credentials are
    generated at apply time on the jumpbox and never live in the export. Add or remove a
    teammate on a running jumpbox with sudo rsp-operator add <handle>, and the roster
    survives a reconverge.
  • Deploy log for support. Each deploy writes a scrubbed logs/deploy-<timestamp>.log
    in the export (keys and passwords redacted) that you can attach to a GitHub issue.
    Deploy-failure and bug-report issue templates ship in the repo.
  • Generic teamserver for a custom C2. The C2 backends are Mythic, Sliver, Adaptix,
    or none. A none teamserver is a plain Debian box for a custom, operator-supplied C2:
    redStackPRO stands up no service and opens no control port, and the redirectors still
    front and forward its traffic. Other C2 backends such as Cobalt Strike are on the
    roadmap.

Included templates

  • Attack infrastructure: split-horizon C2, redirector rollover, the redStack
    blueprint, and two minimal starters, MinimalC2-CLI (a headless Sliver teamserver
    driven from a Kali operator over SSH) and MinimalC2-GUI (a Mythic teamserver with a
    GUI Kali operator desktop).
  • Target ranges: the GOAD family (goad, goad-light, goad-mini, dracarys, goad-wazuh,
    nha, sccm, minilab) and redStackPRO's own harbor forest.

Providers

  • GCP and AWS: supported and tested end to end, for both ranges and attack
    infrastructure.
  • Azure, Proxmox, ESXi: on the roadmap, not yet supported.

Run it

Docker (the canvas only, the API and web app on one port, no Terraform, Ansible, or
credentials inside):

docker run -p 8000:8000 -v redstackpro-data:/data ghcr.io/devzero-security/redstackpro:0.9.0

Or from source: see the README quickstart.

Notes

  • License: MIT. The GOAD range templates are derived from Orange Cyberdefense's GOAD
    and carry GPLv3.

A devZero Security Project.