Skip to content
mholovetskyiPublic

About

Purple team cybersecurity research platform built on OpenClaw

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

🦞 RedClaw

Purple team cybersecurity research platform built on OpenClaw.

Understand the sword. Build the shield.

License: MIT Node.js TypeScript Tests MITRE ATT&CK


What Is RedClaw?

RedClaw is a defensive cybersecurity research platform that addresses the emerging threat of weaponized AI agents. It extends OpenClaw — a powerful agentic AI platform — with four defensive pillars that detect, deceive, contain, and simulate adversarial AI behaviour.

┌─────────────────────────────────────────────────────────────────┐
│                        RedClaw Platform                         │
├───────────────┬───────────────┬───────────────┬─────────────────┤
│  🍯 DECEPTION │ 🔍 DETECTION  │ 🛡️ CONTAINMENT │  🎯 SIMULATION  │
│               │               │               │                 │
│ Honey-creds   │ MITRE ATT&CK  │ Zero-trust    │ Purple team     │
│ Canary files  │ Signatures    │ Policies      │ Atomic tests    │
│ Decoy svcs    │ Anomaly score │ Blast radius  │ Auth gates      │
│ Honey-tokens  │ Correlation   │ Sandboxing    │ Coverage matrix │
├───────────────┴───────────────┴───────────────┴─────────────────┤
│                  OpenClaw Plugin · Hooks · Skills                │
├─────────────────────────────────────────────────────────────────┤
│                       OpenClaw Engine                           │
│          (bundled submodule — ./openclaw/)                      │
└─────────────────────────────────────────────────────────────────┘

Why RedClaw?

Agentic AI platforms give autonomous agents the ability to execute shell commands, browse the web, manage files, persist memory across sessions, and spawn multi-agent swarms. These capabilities — designed for productivity — map directly onto offensive security operations.

The problem: You cannot build effective defenses against a threat you have never seen. Traditional security tools (signature-based AV, network IDS, behavioural UEBA) were not designed to detect AI agents that:

  • Generate polymorphic payloads on the fly
  • Blend C2 traffic with legitimate AI API calls
  • Operate low-and-slow to evade rate-based detection
  • Coordinate across multiple autonomous subagents
  • Use context from LLM memory to adapt their tactics

The solution: RedClaw takes a purple team approach — simulating these attack patterns in controlled environments and building detection capabilities specifically targeting agentic AI threats.


The ClawStrike Threat Model

RedClaw ships with CLAWSTRIKE-THREAT-MODEL.md — a detailed architectural analysis of how an agentic AI platform could theoretically be weaponized into an offensive tool called ClawStrike.

This document follows the "cut-off wires" principle:

What's included What's omitted
Full conceptual architecture All offensive implementation code
MITRE ATT&CK kill chain walkthrough Functional exploit code
Agent swarm coordination diagrams Working C2 infrastructure
Evasion technique analysis Actual evasion implementations
Defender gap analysis Attack tool code

Every omission is marked with a [CUT-OFF] marker explaining exactly what was removed and why. The document exists solely to inform the defenses that RedClaw builds — not to enable attacks.

Read ETHICS.md for the full responsible use policy.


The Four Pillars

🍯 Pillar 1 — Deception

AI agents are relentlessly thorough — they enumerate every file, credential, and service they can reach. This makes them uniquely vulnerable to deception. RedClaw deploys high-fidelity traps that provide zero-false-positive detection signals:

Asset What it looks like to an agent What triggers detection
Honey-credentials Fake AWS keys, API tokens, passwords in config files Any read or use attempt
Canary files passwords.xlsx, ssh-keys.tar.gz, secrets.env Any file open
Decoy services Fake internal API endpoints that appear high-value Any HTTP request
Honey-tokens Fake API keys embedded in code repositories Any token use attempt

Any interaction with a deceptive asset is — by definition — malicious.

🔍 Pillar 2 — Detection & Observability

RedClaw hooks into OpenClaw's plugin lifecycle (before_tool_call, after_tool_call, subagent_spawning, etc.) to monitor every tool call, LLM interaction, and session event:

  • 12 detection signatures across MITRE ATT&CK techniques T1593, T1059, T1053, T1003, T1087, T1021, T1041, T1005 and 4 behavioural patterns (agent swarm coordination, MCP-based C2, polymorphic payload generation, low-and-slow reconnaissance)
  • Anomaly scoring — per-session risk scores that accumulate and decay over time (0.95× per minute)
  • Event correlation — sliding window detection of multi-step attack patterns
  • Kill chain mapping — correlating individual events into ATT&CK tactics

🛡️ Pillar 3 — Containment & Policy

Zero-trust principles applied to AI agents at the before_tool_call enforcement point:

  • Tool policies — block, allow, or require approval for specific tools and shell commands
  • Blast radius analysis — maps the full capability surface a compromised agent has access to
  • Agent isolation — restrict agents to read-only or tightly scoped tool sets
  • Policy templates — zero-trust-agent, tool-restrictions, network-segmentation

🎯 Pillar 4 — Attack Simulation (Purple Team)

Controlled, authorized attack simulations that validate your defenses work:

  • Atomic-style tests — individual MITRE ATT&CK technique simulations (T1059, T1053, T1593 included)
  • Authorization gates — every simulation requires a signed auth token with explicit scope
  • Scope enforcement — simulations only target authorized hosts and tools
  • Detection validation — automatically checks whether the detection engine caught the simulation
  • Coverage reporting — shows which MITRE techniques you can and cannot currently detect

Agent Roles

RedClaw provides three pre-configured OpenClaw agent definitions:

Agent Role Simulate Detect Deploy Deceptions Shell
🔵 blue-agent Defensive monitoring ✗ ✓ ✓ ✗
🔴 red-agent Authorized simulation only ✓ ✗ ✗ Scoped
🟣 purple-agent Full purple team orchestration ✓ ✓ ✓ Scoped

Quick Start

Prerequisites

  • Node.js ≥ 22
  • pnpm (npm install -g pnpm) — required for the OpenClaw engine

Install

# Clone RedClaw with the OpenClaw engine submodule
git clone --recurse-submodules https://github.com/mmmykola/redclaw.git
cd redclaw

Already cloned without --recurse-submodules?

git submodule update --init --recursive

Build

# 1. Install and build the OpenClaw engine
cd openclaw && pnpm install && pnpm build && cd ..

# 2. Install RedClaw dependencies
npm install

# 3. Build RedClaw
npm run build

Run Tests

npm test

Wire into OpenClaw

Add RedClaw to your OpenClaw configuration (~/.openclaw/openclaw.json):

{
  "plugins": {
    "load": {
      "paths": ["path/to/redclaw/dist/plugin"]
    }
  },
  "skills": {
    "load": {
      "extraDirs": ["path/to/redclaw/skills"]
    }
  },
  "hooks": {
    "internal": {
      "load": {
        "extraDirs": ["path/to/redclaw/hooks"]
      }
    }
  }
}

Then start OpenClaw as normal — RedClaw activates automatically.


Available Tools

Once loaded, the following tools are available inside any OpenClaw session:

Tool Pillar Description
redclaw_deploy_deception Deception Deploy a deception asset from a template
redclaw_check_deception Deception Check an event against deployed assets
redclaw_detect Detection Evaluate an event through the detection engine
redclaw_contain Containment Analyse an agent config for blast radius / policy violations
redclaw_simulate Simulation Run an authorized attack simulation
redclaw_dashboard Dashboard Generate a full platform status report

Project Structure

redclaw/
├── openclaw/                     # OpenClaw engine (git submodule)
│
├── CLAWSTRIKE-THREAT-MODEL.md    # "Cut-off wires" threat documentation
├── ETHICS.md                     # Responsible use policy
│
├── plugin/                       # OpenClaw plugin (main integration point)
│   ├── openclaw.plugin.json
│   └── index.ts
│
├── hooks/                        # OpenClaw lifecycle hooks
│   ├── redclaw-monitor/          # Full session activity monitor
│   └── redclaw-policy/           # Policy enforcement audit hook
│
├── skills/                       # OpenClaw skill definitions
│   ├── redclaw-deception/
│   ├── redclaw-detect/
│   ├── redclaw-contain/
│   ├── redclaw-simulate/
│   └── redclaw-dashboard/
│
├── agents/                       # Agent role definitions
│   ├── blue-agent.json
│   ├── red-agent.json
│   └── purple-agent.json
│
├── src/                          # Core TypeScript implementation
│   ├── types.ts                  # Shared type definitions
│   ├── constants.ts              # MITRE techniques, thresholds, patterns
│   ├── config.ts                 # Configuration loader
│   ├── utils.ts                  # Shared utilities
│   ├── deception/                # Pillar 1
│   ├── detection/                # Pillar 2
│   ├── containment/              # Pillar 3
│   ├── simulation/               # Pillar 4
│   └── dashboard/                # Reporting
│
├── detections/                   # Detection signature library (JSON)
│   ├── mitre-attack/             # T1059, T1053, T1003, T1087...
│   └── behavioral/               # agent-swarm, mcp-c2, low-and-slow...
│
├── deceptions/                   # Deception asset templates (JSON)
├── policies/                     # Security policy templates (JSON)
├── simulations/                  # Attack simulation definitions (JSON)
│
├── test/                         # Vitest test suite (44 tests)
└── docs/                         # Additional documentation
    ├── ARCHITECTURE.md
    ├── SETUP.md
    └── PURPLE-TEAM-GUIDE.md

MITRE ATT&CK Coverage

RedClaw includes detection signatures and simulation definitions covering 13 of 14 MITRE ATT&CK Enterprise tactics.

Run redclaw_dashboard coverage inside any OpenClaw session to generate a live coverage matrix showing which techniques you can and cannot currently detect in your environment.


Testing

 ✓ test/simulation.test.ts    (11 tests)
 ✓ test/containment.test.ts   (7 tests)
 ✓ test/deception.test.ts     (4 tests)
 ✓ test/integration.test.ts   (5 tests)
 ✓ test/detection.test.ts     (17 tests)

 Test Files  5 passed
 Tests       44 passed

Contributing

See ETHICS.md for full contribution guidelines.

We welcome:

  • New detection signatures (detections/mitre-attack/ or detections/behavioral/)
  • Improved deception templates (deceptions/)
  • Better event correlation rules
  • Policy templates for specific environments
  • Simulation definitions for additional MITRE techniques
  • Bug reports and documentation improvements

We do not accept:

  • Offensive implementation code or exploitation scripts
  • Attack tool implementations (functional or partial)
  • Any contribution that converts [CUT-OFF] stubs into working attack code

License

MIT — see LICENSE


Acknowledgments

  • OpenClaw — The agentic AI engine powering RedClaw (bundled as a submodule)
  • MITRE ATT&CK — The threat framework structuring all detections and simulations
  • Atomic Red Team — Inspiration for the simulation framework design
  • The security research community for responsible disclosure practices

About

Purple team cybersecurity research platform built on OpenClaw

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages