Skip to main content

Welcome to RTF — Red Team Framework

RTF is a professional red team engagement platform designed to help security teams plan, execute, and document their engagements — all in one place.

Whether you're running a full adversary simulation or a targeted assessment, RTF gives you the tools to stay organized, track your progress against real-world attack frameworks, and generate high-quality reports.


How RTF is Structured

RTF is a three-part platform. You interact with all three seamlessly, but understanding the separation helps when something needs attention:

PartHosted byWhat it handles
RTF AuthSandbox Security (cloud)Login, accounts, teams, licenses, team chat
RTF ClientSandbox Security (cloud)The web interface you use every day
RTF ServerYou (Docker, your machine)The core red team engine — all engagement data stays with you
Your data stays with you

All engagement data — findings, navigator state, AI plans, terminal sessions — lives on your RTF Server. The cloud components only handle identity and the UI. You own your data.


What You Can Do with RTF

Engagement Features (RTF Server)

CapabilityWhat It Means for You
MITRE ATT&CK NavigatorTrack techniques across all MITRE tactics in a visual map
MITRE ATLAS NavigatorSame for AI/ML system assessments
AI Attack PlanningGet AI-generated attack plans tailored to your target and scope
AI Scope SuggestionsLet AI recommend which techniques to include in scope
AI Tool SuggestionsGet tool recommendations for each technique as you work
FindingsRecord discoveries tied directly to MITRE techniques, with screenshot evidence
C2 InfrastructureMap your command-and-control setup visually
Web TerminalRun commands directly in the browser — no SSH needed
Analytics DashboardEngagement coverage, timelines, and top tools at a glance
AI/ML Model ScanningTest AI systems using ATLAS-based techniques
Package ManagerInstall and manage tools inside the RTF container

Account & Team Features (RTF Auth)

CapabilityWhat It Means for You
Secure LoginEmail + password with account lockout protection
Two-Factor Auth (2FA)TOTP-based MFA via any authenticator app
Password ManagementSecure password reset, change, and history enforcement
Role-Based AccessAdmin and Member roles with appropriate permissions
Organization ManagementManage your team, seats, and license from one place
Team ChatReal-time encrypted group chat with file sharing
Online PresenceSee which team members are currently active
Audit LogsFull record of all account and auth events (admin only)

How an Engagement Works

RTF is built around profiles. Every piece of work lives inside a profile:

Engagement (Profile)
├── MITRE ATT&CK Navigator ← track your techniques
├── MITRE ATLAS Navigator ← track AI/ML techniques
├── AI Attack Plan ← AI-generated plan
├── Findings ← what you discovered
├── C2 Infrastructure ← your infrastructure map
├── Terminal Sessions ← your active shells
├── Analytics Dashboard ← your progress metrics
└── Subprofiles ← organize by target segment
└── (each subprofile has its own findings)

Quick Navigation