Purple team cybersecurity research platform built on OpenClaw.
Understand the sword. Build the shield.
RedClaw is a defensive cybersecurity research platform that addresses the emerging threat of weaponized AI agents. It extends OpenClaw — a powerful agentic AI platform — with four defensive pillars that detect, deceive, contain, and simulate adversarial AI behaviour.
┌─────────────────────────────────────────────────────────────────┐
│ RedClaw Platform │
├───────────────┬───────────────┬───────────────┬─────────────────┤
│ 🍯 DECEPTION │ 🔍 DETECTION │ 🛡️ CONTAINMENT │ 🎯 SIMULATION │
│ │ │ │ │
│ Honey-creds │ MITRE ATT&CK │ Zero-trust │ Purple team │
│ Canary files │ Signatures │ Policies │ Atomic tests │
│ Decoy svcs │ Anomaly score │ Blast radius │ Auth gates │
│ Honey-tokens │ Correlation │ Sandboxing │ Coverage matrix │
├───────────────┴───────────────┴───────────────┴─────────────────┤
│ OpenClaw Plugin · Hooks · Skills │
├─────────────────────────────────────────────────────────────────┤
│ OpenClaw Engine │
│ (bundled submodule — ./openclaw/) │
└─────────────────────────────────────────────────────────────────┘
Agentic AI platforms give autonomous agents the ability to execute shell commands, browse the web, manage files, persist memory across sessions, and spawn multi-agent swarms. These capabilities — designed for productivity — map directly onto offensive security operations.
The problem: You cannot build effective defenses against a threat you have never seen. Traditional security tools (signature-based AV, network IDS, behavioural UEBA) were not designed to detect AI agents that:
- Generate polymorphic payloads on the fly
- Blend C2 traffic with legitimate AI API calls
- Operate low-and-slow to evade rate-based detection
- Coordinate across multiple autonomous subagents
- Use context from LLM memory to adapt their tactics
The solution: RedClaw takes a purple team approach — simulating these attack patterns in controlled environments and building detection capabilities specifically targeting agentic AI threats.
RedClaw ships with CLAWSTRIKE-THREAT-MODEL.md — a detailed architectural analysis of how an agentic AI platform could theoretically be weaponized into an offensive tool called ClawStrike.
This document follows the "cut-off wires" principle:
| What's included | What's omitted |
|---|---|
| Full conceptual architecture | All offensive implementation code |
| MITRE ATT&CK kill chain walkthrough | Functional exploit code |
| Agent swarm coordination diagrams | Working C2 infrastructure |
| Evasion technique analysis | Actual evasion implementations |
| Defender gap analysis | Attack tool code |
Every omission is marked with a [CUT-OFF] marker explaining exactly what was removed and why. The document exists solely to inform the defenses that RedClaw builds — not to enable attacks.
Read ETHICS.md for the full responsible use policy.
AI agents are relentlessly thorough — they enumerate every file, credential, and service they can reach. This makes them uniquely vulnerable to deception. RedClaw deploys high-fidelity traps that provide zero-false-positive detection signals:
| Asset | What it looks like to an agent | What triggers detection |
|---|---|---|
| Honey-credentials | Fake AWS keys, API tokens, passwords in config files | Any read or use attempt |
| Canary files | passwords.xlsx, ssh-keys.tar.gz, secrets.env |
Any file open |
| Decoy services | Fake internal API endpoints that appear high-value | Any HTTP request |
| Honey-tokens | Fake API keys embedded in code repositories | Any token use attempt |
Any interaction with a deceptive asset is — by definition — malicious.
RedClaw hooks into OpenClaw's plugin lifecycle (before_tool_call, after_tool_call, subagent_spawning, etc.) to monitor every tool call, LLM interaction, and session event:
- 12 detection signatures across MITRE ATT&CK techniques T1593, T1059, T1053, T1003, T1087, T1021, T1041, T1005 and 4 behavioural patterns (agent swarm coordination, MCP-based C2, polymorphic payload generation, low-and-slow reconnaissance)
- Anomaly scoring — per-session risk scores that accumulate and decay over time (0.95× per minute)
- Event correlation — sliding window detection of multi-step attack patterns
- Kill chain mapping — correlating individual events into ATT&CK tactics
Zero-trust principles applied to AI agents at the before_tool_call enforcement point:
- Tool policies — block, allow, or require approval for specific tools and shell commands
- Blast radius analysis — maps the full capability surface a compromised agent has access to
- Agent isolation — restrict agents to read-only or tightly scoped tool sets
- Policy templates — zero-trust-agent, tool-restrictions, network-segmentation
Controlled, authorized attack simulations that validate your defenses work:
- Atomic-style tests — individual MITRE ATT&CK technique simulations (T1059, T1053, T1593 included)
- Authorization gates — every simulation requires a signed auth token with explicit scope
- Scope enforcement — simulations only target authorized hosts and tools
- Detection validation — automatically checks whether the detection engine caught the simulation
- Coverage reporting — shows which MITRE techniques you can and cannot currently detect
RedClaw provides three pre-configured OpenClaw agent definitions:
| Agent | Role | Simulate | Detect | Deploy Deceptions | Shell |
|---|---|---|---|---|---|
| 🔵 blue-agent | Defensive monitoring | ✗ | ✓ | ✓ | ✗ |
| 🔴 red-agent | Authorized simulation only | ✓ | ✗ | ✗ | Scoped |
| 🟣 purple-agent | Full purple team orchestration | ✓ | ✓ | ✓ | Scoped |
- Node.js ≥ 22
- pnpm (
npm install -g pnpm) — required for the OpenClaw engine
# Clone RedClaw with the OpenClaw engine submodule
git clone --recurse-submodules https://github.com/mmmykola/redclaw.git
cd redclawAlready cloned without
--recurse-submodules?git submodule update --init --recursive
# 1. Install and build the OpenClaw engine
cd openclaw && pnpm install && pnpm build && cd ..
# 2. Install RedClaw dependencies
npm install
# 3. Build RedClaw
npm run buildnpm testAdd RedClaw to your OpenClaw configuration (~/.openclaw/openclaw.json):
{
"plugins": {
"load": {
"paths": ["path/to/redclaw/dist/plugin"]
}
},
"skills": {
"load": {
"extraDirs": ["path/to/redclaw/skills"]
}
},
"hooks": {
"internal": {
"load": {
"extraDirs": ["path/to/redclaw/hooks"]
}
}
}
}Then start OpenClaw as normal — RedClaw activates automatically.
Once loaded, the following tools are available inside any OpenClaw session:
| Tool | Pillar | Description |
|---|---|---|
redclaw_deploy_deception |
Deception | Deploy a deception asset from a template |
redclaw_check_deception |
Deception | Check an event against deployed assets |
redclaw_detect |
Detection | Evaluate an event through the detection engine |
redclaw_contain |
Containment | Analyse an agent config for blast radius / policy violations |
redclaw_simulate |
Simulation | Run an authorized attack simulation |
redclaw_dashboard |
Dashboard | Generate a full platform status report |
redclaw/
├── openclaw/ # OpenClaw engine (git submodule)
│
├── CLAWSTRIKE-THREAT-MODEL.md # "Cut-off wires" threat documentation
├── ETHICS.md # Responsible use policy
│
├── plugin/ # OpenClaw plugin (main integration point)
│ ├── openclaw.plugin.json
│ └── index.ts
│
├── hooks/ # OpenClaw lifecycle hooks
│ ├── redclaw-monitor/ # Full session activity monitor
│ └── redclaw-policy/ # Policy enforcement audit hook
│
├── skills/ # OpenClaw skill definitions
│ ├── redclaw-deception/
│ ├── redclaw-detect/
│ ├── redclaw-contain/
│ ├── redclaw-simulate/
│ └── redclaw-dashboard/
│
├── agents/ # Agent role definitions
│ ├── blue-agent.json
│ ├── red-agent.json
│ └── purple-agent.json
│
├── src/ # Core TypeScript implementation
│ ├── types.ts # Shared type definitions
│ ├── constants.ts # MITRE techniques, thresholds, patterns
│ ├── config.ts # Configuration loader
│ ├── utils.ts # Shared utilities
│ ├── deception/ # Pillar 1
│ ├── detection/ # Pillar 2
│ ├── containment/ # Pillar 3
│ ├── simulation/ # Pillar 4
│ └── dashboard/ # Reporting
│
├── detections/ # Detection signature library (JSON)
│ ├── mitre-attack/ # T1059, T1053, T1003, T1087...
│ └── behavioral/ # agent-swarm, mcp-c2, low-and-slow...
│
├── deceptions/ # Deception asset templates (JSON)
├── policies/ # Security policy templates (JSON)
├── simulations/ # Attack simulation definitions (JSON)
│
├── test/ # Vitest test suite (44 tests)
└── docs/ # Additional documentation
├── ARCHITECTURE.md
├── SETUP.md
└── PURPLE-TEAM-GUIDE.md
RedClaw includes detection signatures and simulation definitions covering 13 of 14 MITRE ATT&CK Enterprise tactics.
Run redclaw_dashboard coverage inside any OpenClaw session to generate a live coverage matrix showing which techniques you can and cannot currently detect in your environment.
✓ test/simulation.test.ts (11 tests)
✓ test/containment.test.ts (7 tests)
✓ test/deception.test.ts (4 tests)
✓ test/integration.test.ts (5 tests)
✓ test/detection.test.ts (17 tests)
Test Files 5 passed
Tests 44 passed
See ETHICS.md for full contribution guidelines.
We welcome:
- New detection signatures (
detections/mitre-attack/ordetections/behavioral/) - Improved deception templates (
deceptions/) - Better event correlation rules
- Policy templates for specific environments
- Simulation definitions for additional MITRE techniques
- Bug reports and documentation improvements
We do not accept:
- Offensive implementation code or exploitation scripts
- Attack tool implementations (functional or partial)
- Any contribution that converts
[CUT-OFF]stubs into working attack code
MIT — see LICENSE
- OpenClaw — The agentic AI engine powering RedClaw (bundled as a submodule)
- MITRE ATT&CK — The threat framework structuring all detections and simulations
- Atomic Red Team — Inspiration for the simulation framework design
- The security research community for responsible disclosure practices