RedShades / Software carries the workflowTECHNICAL EDITION
Platform scope

Put models to work. Keep software in control.

Long technical investigations ask more of a system than a good answer. RedShades gives smaller, specialized models defined decisions while deterministic software owns scheduling, evidence, policy and recovery. A native workspace brings those decisions, their sources and the tools behind them into view.

Put models to work.
Keep software in control. — operator workspace
Keep source notes, context and investigation progress together.

The investment thesis is integration: useful work can accumulate across model sessions, tool changes and runtime replacement. The architecture supports that thesis; comparative model cost and reliability still require controlled measurement.

Independent engineering · September 202601
RedShades / Software carries the workflowTECHNICAL EDITION
Evidence-driven scheduling

The next step is a software decision

Each stage declares the evidence it needs. The scheduler advances eligible branches and revisits waiting work when observations change. Models interpret uncertain inputs; they do not have to reconstruct the workflow or remember which branch can run.

Evidence-driven scheduling — source-derived relationship diagram
Evidence-driven scheduling · overview.

The Executive supervises progress. Capability development and software repair have separate owners, so a stalled investigation can be routed to the appropriate kind of work. Child investigations retain their scope, parent context and completion relationship.

Independent engineering · September 202602
RedShades / Software carries the workflowTECHNICAL EDITION
Model allocation

Spend intelligence on the uncertain part

Scheduling, state, policy and validation are software responsibilities. Interpretation and synthesis are model responsibilities. That division gives a small specialist a complete, bounded job instead of asking it to manage an entire engagement.

Model allocation — source-derived relationship diagram
Model allocation · overview.

The 70% deterministic / 30% neural framing describes the design philosophy. It is not a measured share of code, runtime or success. Model economics remain a question for controlled evaluation.

Independent engineering · September 202603
RedShades / Progress worth keepingTECHNICAL EDITION
Shared engagement state

Memory belongs to the engagement

Versioned records link observations, identities, routes, artifacts and outcomes. A new model session or replacement worker can read the accepted state and its sources without rebuilding the investigation from a conversation.

Shared engagement state — source-derived relationship diagram
Shared engagement state · overview.

The scheduler and native views draw on the same records. Revision references identify the inputs behind a decision; they also make stale results distinguishable from current work.

Independent engineering · September 202604
RedShades / Progress worth keepingTECHNICAL EDITION
Evidence attribution

A finding should lead back to its source

A tool result retains its source, context and interpretation. Later stages can reuse it, and an operator can inspect what actually supported a conclusion. Competing observations remain distinguishable until there is evidence to resolve them.

Attribution is the connection between tool integration and model quality: a specialist receives inspectable material with context, rather than an untraceable summary.

Independent engineering · September 202605
RedShades / Progress worth keepingTECHNICAL EDITION
Conditional stage coverage

A repertoire, selected by evidence

The Validated Core contains 88 conditional stages spanning discovery, service and identity analysis, web investigation, artifacts and reporting. Thirteen C2 continuation stages add shared and platform-specific session work.

Prerequisites, platform context and policy determine the path. The atlas identifies the available responsibilities; its order does not prescribe an execution sequence.

Independent engineering · September 202606
RedShades / Progress worth keepingTECHNICAL EDITION
Branch-local progress

A local question need not stop the run

An endpoint review or missing identity fact can hold one branch while unrelated work continues. A global pause is an explicit operator decision with a different scope.

Branch-local progress — source-derived relationship diagram
Branch-local progress · overview.

Waiting work retains the input that could make it eligible. New observations can reopen useful branches without turning every unresolved item into a retry loop.

Independent engineering · September 202607
RedShades / Give each model the right jobTECHNICAL EDITION
Bounded model calls

A complete job for a specialist

Core includes 100 fine-tuned specialist adapters for bounded stateless calls and code-review roles. Each call receives a defined purpose and structured evidence. Software validates its response and retains the accepted result with model attribution.

Bounded model calls — source-derived relationship diagram
Bounded model calls · overview.

Capacity, token accounting and response limits surround the call. The task boundary selects the specialist; the engagement keeps the evidence and review history.

Independent engineering · September 202608
RedShades / Give each model the right jobTECHNICAL EDITION
Persistent model sessions

Harder work needs a persistent workspace

The fine-tuned 30B3A Flash model supports persistent higher-complexity sessions. Executive, capability-development and repair workspaces carry accepted artifacts, prior review and progress between segments.

Persistent model sessions — source-derived relationship diagram
Persistent model sessions · overview.

Access to fine-tuned models and specialist adapters follows controlled subscription gates. Weekly model credits and selective weights entitlements support different deployment needs; the bundle comparison sets out those terms.

Independent engineering · September 202609
RedShades / Give each model the right jobTECHNICAL EDITION
Capability development

Build the missing interaction against a contract

The Adaptive Capability Pipeline (ACP) is an adaptive capability-generation harness. It develops candidates from observed evidence and source mechanics, retaining the contract through binding, SDK selection, adapter generation, review and replica validation.

Capability development — source-derived relationship diagram
Capability development · overview.

A compatible catalog artifact or SDK can remove unnecessary generation work. New candidates retain their correction history and supporting artifacts for review.

Independent engineering · September 202610
RedShades / Give each model the right jobTECHNICAL EDITION
Candidate publication

Generated code needs an admission boundary

Source findings and advisories can inform a typed capability candidate. Source, metadata and tests are published together with their digests, giving review a specific artifact set to examine.

Candidate publication — source-derived relationship diagram
Candidate publication · overview.

The workbench can retain a candidate for controlled evaluation when a ready-made implementation is absent. Publication establishes artifact identity; admission determines whether it can be used.

Independent engineering · September 202611
RedShades / Give each model the right jobTECHNICAL EDITION
Independent capability review

Test what happens when the names change

An isolated reviewer checks a candidate against its contract and provenance. Counterfactual cases change names, ordering, missing evidence and competing candidates to assess whether the behavior generalizes.

Independent capability review — source-derived relationship diagram
Independent capability review · overview.

The reviewer receives a read-only packet and returns a typed verdict. Generation, review and execution permission remain separately owned.

Independent engineering · September 202612
RedShades / Give each model the right jobTECHNICAL EDITION
Runtime software repair

Repair has to end with a working hand-back

The Autonomic Engineering Plane (AEP) is an adaptive software-repair harness. It owns diagnosis, a persistent repair session, scoped changes, tests, build admission and hot replacement, ending with verified hand-back to the run.

Runtime software repair — source-derived relationship diagram
Runtime software repair · overview.

A missing interaction belongs to capability development; a defect in supported platform behavior belongs to software repair. The repair loop is assessed as a complete transaction, beyond the existence of a patch.

Independent engineering · September 202613
RedShades / Continuity is an engineering problemTECHNICAL EDITION
Provider replacement

Replace the worker. Retain the record.

Versioned providers give runtime replacement a defined boundary. New work can adopt a replacement while existing work retains its implementation and the engagement state stays outside the provider.

Provider replacement — source-derived relationship diagram
Provider replacement · overview.

The Runtime Composition Kernel owns publication, leases, rollback and cleanup. This supplies the lifecycle foundation for repair without requiring the investigation record to move with the code.

Independent engineering · September 202614
RedShades / Continuity is an engineering problemTECHNICAL EDITION
Worker result attribution

Old work cannot silently become current

Isolated workers receive immutable execution envelopes. Acceptance checks the artifact, input and generation lease, so an expired worker cannot publish a plausible result into the current run.

Worker result attribution — source-derived relationship diagram
Worker result attribution · overview.

In-process handlers and isolated workers have different replacement boundaries. A lease identifies the implementation responsible for a result. Process ownership, bounded output, cleanup handles and token accounting make resource use inspectable.

Independent engineering · September 202615
RedShades / Continuity is an engineering problemTECHNICAL EDITION
Workspace integration

Keep specialist tools in their native setting

The Qt workspace combines dense investigation views with retained tool surfaces. Gitea, BloodHound, build workflows, RDP and development harnesses can sit alongside the operator environment.

Workspace integration — source-derived relationship diagram
Workspace integration · overview.

Lightweight QML chrome surrounds native widgets. Embedded windows preserve specialist interfaces while the investigation remains visible. Binary and source analysis remain beside the workbench; their results return to the same investigation record.

Independent engineering · September 202616
RedShades / Continuity is an engineering problemTECHNICAL EDITION
Third-party execution

Integration begins after the tool runs

Network, web, directory, browser and source-inspection tools produce different kinds of output. Their value to the platform comes from controlled execution and the attributed evidence returned to the engagement.

Third-party execution — source-derived relationship diagram
Third-party execution · overview.

Admitted third-party proof-of-concept work can use isolated containers. Tool availability, candidate review and execution permission remain separate inputs.

Independent engineering · September 202617
RedShades / Continuity is an engineering problemTECHNICAL EDITION
Artifact identity

Built bytes need a traceable identity

Versioned builds, transformation and obfuscation components form the artifact toolchain. VM-oriented transformation sits within that engineering scope; digests and provenance connect the resulting material to its recorded role.

Built bytes need a traceable identity — operator workspace
Compare versioned artifacts and their build states.

Native artifact views expose the inventory to the operator. A build record identifies material and purpose without implying that the artifact was deployed or a session established.

Independent engineering · September 202618
RedShades / Continuity is an engineering problemTECHNICAL EDITION
Session continuation

A session adds context to the same investigation

Registered sessions make platform-aware continuation available. Common, Windows and Linux stage families retain their prerequisites while artifacts and attached work remain linked to the parent engagement.

Session continuation — source-derived relationship diagram
Session continuation · overview.

The 13 C2 continuation declarations complement the 88 Core stages. Session context selects applicable work.

Independent engineering · September 202619
RedShades / A workspace for close inspectionTECHNICAL EDITION
Network Graph

See where an observation belongs

Network Graph places observed hosts and relationships in the wider investigation. Selecting a host or link connects that overview to its available context.

See where an observation belongs — operator workspace
Locate each host and its observed relationships in the wider investigation.

A displayed relationship aids orientation. Its presence does not establish an admitted route or a verified capability.

Independent engineering · September 202620
RedShades / A workspace for close inspectionTECHNICAL EDITION
WebRecon overview

Read the source without losing the overview

WebRecon places web observations, source detail and endpoint review in one native surface. The operator can inspect a selected item while retaining the surrounding investigation.

Read the source without losing the overview — operator workspace
Follow web observations from the page to the evidence record.

Source material stays near the observation it supports, with selected evidence and review context available together.

Independent engineering · September 202621
RedShades / A workspace for close inspectionTECHNICAL EDITION
WebRecon review and gate state

Make the pending decision specific

A review state identifies the affected endpoint or branch and its supporting evidence. The operator can see what is waiting and where the decision applies.

Make the pending decision specific — operator workspace
Detail crop of the same native capture
See the endpoint, scope and evidence behind a pending review.

A displayed gate communicates scope. Enforcement is established by policy and lifecycle validation, beyond the screenshot.

Independent engineering · September 202622
RedShades / A workspace for close inspectionTECHNICAL EDITION
Investigation Graph

Trace a hypothesis to its observations

Investigation Graph arranges evidence and interpretations as relationships. Detail views retain the source references needed to examine a hypothesis.

Trace a hypothesis to its observations — operator workspace
Trace each conclusion through support, counter-evidence and review.

The graph offers an overview while the workbench carries fuller records. Observations remain distinct from their interpretation.

Independent engineering · September 202623
RedShades / A workspace for close inspectionTECHNICAL EDITION
Investigation Workbench

Give difficult evidence room

The Investigation Workbench provides a dedicated surface for source references, context and available continuation. Selection exposes detail without forcing every field into a graph node.

Give difficult evidence room — operator workspace
Detail crop of the same native capture
Compare canonical records and the sources behind the current revision.

Review source references, competing observations and the current revision together. Open the image to inspect the record in detail.

Independent engineering · September 202624
RedShades / A workspace for close inspectionTECHNICAL EDITION
Session and artifact surfaces

Distinguish a record from availability

Session and artifact views place stored records, versioned builds and observed availability together. Offline and unknown states remain visible alongside selected detail.

Distinguish a record from availability — operator workspace
Review host identity and recorded availability before continuing work.

Host identity, recorded state and artifact history help an operator distinguish stored records from current availability.

Independent engineering · September 202625
RedShades / A workspace for close inspectionTECHNICAL EDITION
Model and runtime controls

Configuration within reach of the work

Model and runtime controls remain accessible alongside the investigation. They expose the choices an operator needs to review without leaving the native workspace.

Configuration within reach of the work — operator workspace
Detail crop of the same native capture
Review model selection and bounded provider settings.

Configuration expresses the selected policy. Runtime admission, attribution and accounting establish how that policy is applied.

Independent engineering · September 202626
RedShades / What the evidence supportsTECHNICAL EDITION
Verification coverage

Match the claim to the check

Focused contracts, integrated simulations, race checks, repetition, fuzzing and fault injection examine different failure modes. The Mega and Ultra acceptance suites organize that work.

Verification coverage — source-derived relationship diagram
Verification coverage · overview.

Revision-bound receipts connect checks to commands and outputs. A component result supports its tested boundary; whole-system reliability needs integrated evidence.

Independent engineering · September 202627
RedShades / What the evidence supportsTECHNICAL EDITION
Disclosure study

A vocabulary that can be tested on new material

The Trigger Methodology Graph study grouped 200 public disclosures into 37 recurring families. Of 40 identity-disjoint held-out disclosures, 39 belonged to a represented family.

Disclosure study — source-derived relationship diagram
Disclosure study · overview.

This measures family coverage in a curated study. It does not count discoveries made by the product. Synthetic calibration recorded 600 activations; no candidates were live-exercised or admitted in the reported study.

Independent engineering · September 202628
RedShades / What the evidence supportsTECHNICAL EDITION
Evidence-gap analysis

A useful hypothesis names the missing fact

Trigger Methodology Graph produces evidence-bound hypotheses. Shadow Capability Graph examines missing prerequisites from an immutable snapshot. Policy gates retain review over proposed hypotheses.

Evidence-gap analysis — source-derived relationship diagram
Evidence-gap analysis · overview.

The result identifies uncertainty and the evidence needed to resolve it. A diagnostic suggestion does not acquire scheduling authority.

Independent engineering · September 202629
RedShades / What the evidence supportsTECHNICAL EDITION
CTF validation

An evaluation history across more than 691 CTF labs

Validation spans more than 691 CTF labs. The learning curve averaged about 90% after lab 328 and rose steadily toward 97%.

CTF validation — source-derived relationship diagram
CTF validation · overview.

Successive evaluations connect model learning with the practical demands of sustained technical work. The history complements the platform’s component, integration and fault-testing program.

Independent engineering · September 202630
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

implant deployment Validated Core

implant_deployment

Artifact and session work · Admitted artifact and authorized context → Artifact/session records

ACL operator review (post-summary) Validated Core

acl_operator_action

Directory analysis · Directory evidence and operator review → Review record

AD compositional capability planning Validated Core

ad_capability_planning

Directory analysis · Directory evidence → Directory analysis records

AD effective capability discovery Validated Core

ad_capability_discovery

Directory analysis · Directory evidence → Directory analysis records

BloodHound collection Validated Core

bloodhound_collection

Directory analysis · Directory context → Graph analysis material

Cross-realm Kerberos service-ticket custody Validated Core

ad_cross_realm_kerberos

Directory analysis · Directory evidence → Directory analysis records

masscan discovery Validated Core

discovery_masscan

Discovery · Scope and observation context → Network observations

nmap service and OS scan Validated Core

discovery_nmap

Discovery · Scope and observation context → Network observations

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202631
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

passive OSINT (WHOIS / DNS / ASN) Validated Core

osint_passive

Discovery · Scope and public observations → Context evidence

query discovered ports Validated Core

discovery_ports

Discovery · Scope and observation context → Network observations

BloodHound ACL attack path analysis Validated Core

post_acl_analysis

Extended investigation · Session, artifact or investigation context → Attributed investigation records

chisel SOCKS5 reverse pivot Validated Core

post_pivot_chisel

Extended investigation · Session, artifact or investigation context → Attributed investigation records

DCSync domain hash dump Validated Core

post_dcsync

Extended investigation · Session, artifact or investigation context → Attributed investigation records

Disabled legacy advisory handoff Validated Core

post_nopac

Extended investigation · Session, artifact or investigation context → Attributed investigation records

DPAPI artifact analysis (operator action) Validated Core

post_dpapi

Extended investigation · Session, artifact or investigation context → Attributed investigation records

Final assessment report Validated Core

post_pwndoc_export

Extended investigation · Session, artifact or investigation context → Attributed investigation records

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202632
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

Linux privilege escalation enumeration Validated Core

post_linux_privesc

Extended investigation · Session, artifact or investigation context → Attributed investigation records

pass-the-hash sweep Validated Core

post_pth

Extended investigation · Session, artifact or investigation context → Attributed investigation records

pass-the-ticket (golden/silver ticket) Validated Core

post_ptt

Extended investigation · Session, artifact or investigation context → Attributed investigation records

secretsdump credential harvest Validated Core

post_secretsdump

Extended investigation · Session, artifact or investigation context → Attributed investigation records

SMB binary credential extraction Validated Core

post_smb_binary_analysis

Extended investigation · Session, artifact or investigation context → Attributed investigation records

Windows privilege escalation enumeration Validated Core

post_windows_privesc

Extended investigation · Session, artifact or investigation context → Attributed investigation records

AD coercion (PrinterBug/PetitPotam/DFSCoerce) Validated Core

identity_coerce

Identity analysis · Identity and service context → Identity evidence

certipy AD CS Validated Core

identity_certipy

Identity analysis · Identity and service context → Identity evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202633
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

certipy AD CS exploitation (ESC1/ESC4/ESC8) Validated Core

identity_certipy_exploit

Identity analysis · Identity and service context → Identity evidence

enum4linux-ng Validated Core

identity_enum4linux

Identity analysis · Identity and service context → Identity evidence

GetNPUsers Validated Core

identity_getnpusers

Identity analysis · Identity and service context → Identity evidence

GetUserSPNs Validated Core

identity_getuserspns

Identity analysis · Identity and service context → Identity evidence

hash cracking Validated Core

identity_hash_cracking

Identity analysis · Identity and service context → Identity evidence

kerbrute Validated Core

identity_kerbrute

Identity analysis · Identity and service context → Identity evidence

LAPS password dump Validated Core

identity_laps

Identity analysis · Identity and service context → Identity evidence

ldapdomaindump Validated Core

identity_ldapdomaindump

Identity analysis · Identity and service context → Identity evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202634
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

lookupsid Validated Core

identity_lookupsid

Identity analysis · Identity and service context → Identity evidence

NTLM relay (ntlmrelayx) Validated Core

identity_ntlm_relay

Identity analysis · Identity and service context → Identity evidence

nxc null/guest enumeration Validated Core

identity_nxc_guest

Identity analysis · Identity and service context → Identity evidence

Responder NTLM hash capture Validated Core

identity_ntlm_capture

Identity analysis · Identity and service context → Identity evidence

targeted credential spray Validated Core

identity_credential_spray

Identity analysis · Identity and service context → Identity evidence

username permutation generation Validated Core

identity_username_anarchy

Identity analysis · Identity and service context → Identity evidence

credential reuse sweep Validated Core

credential_reuse_sweep

Investigation · Scoped evidence → Attributed records

Execution context: network path and domain time Validated Core

environment_adaptation

Platform adaptation · Environment context → Adaptation records

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202635
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

conditional mssqlclient Validated Core

remote_mssqlclient

Remote services · Service and authorized session context → Protocol evidence

conditional smbclient Validated Core

remote_smbclient

Remote services · Service and authorized session context → Protocol evidence

Kerberos ticket-backed WinRM validation Validated Core

remote_kerberos_winrm

Remote services · Service and authorized session context → Protocol evidence

MSSQL linked server ADIDNS poisoning Validated Core

mssql_linked_server_poison

Remote services · Database context → Database evidence

SMB file harvest Validated Core

remote_smb_harvest

Remote services · Service and authorized session context → Protocol evidence

smbmap share enumeration Validated Core

remote_smbmap

Remote services · Service and authorized session context → Protocol evidence

deterministic operator report Validated Core

summary

Reporting · Retained investigation evidence → Report projection

DNS zone transfer drill Validated Core

service_dns_axfr

Service analysis · Service observations → Service evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202636
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

dnsx Validated Core

service_dnsx

Service analysis · Service observations → Service evidence

FTP anonymous Validated Core

service_ftp_anon

Service analysis · Service observations → Service evidence

IPMI enumeration and hash extraction Validated Core

service_ipmi

Service analysis · Service observations → Service evidence

MySQL probe Validated Core

service_mysql

Service analysis · Service observations → Service evidence

NFS enumeration Validated Core

service_nfs

Service analysis · Service observations → Service evidence

Redis enumeration Validated Core

service_redis

Service analysis · Service observations → Service evidence

service CVE candidate sweep Validated Core

service_searchsploit_sweep

Service analysis · Service observations → Service evidence

service CVE workbench Validated Core

service_cve_workbench

Service analysis · Service observations → Service evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202637
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

SMTP user enumeration Validated Core

service_smtp_user_enum

Service analysis · Service observations → Service evidence

SNMP enumeration Validated Core

service_snmp_enum

Service analysis · Service observations → Service evidence

ssh-audit Validated Core

service_ssh_audit

Service analysis · Service observations → Service evidence

subfinder Validated Core

service_subfinder

Service analysis · Service observations → Service evidence

credential to shell attempts Validated Core

shell_attempts

Session work · Authorized execution context → Session-related records

xfreerdp RDP session Validated Core

rdp_session

Session work · Authorized session context → Session records

CMS scanning Validated Core

web_cms_scan

Web investigation · Web observations and scoped review → Web evidence

CMS/app-server RCE (Tomcat/Jenkins/Drupal) Validated Core

web_cms_exploit

Web investigation · Web observations and scoped review → Web evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202638
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

CVE PoC workbench review Validated Core

web_cve_poc_workbench

Web investigation · Web observations and scoped review → Web evidence

GoWitness endpoint review Validated Core

web_screenshot

Web investigation · Web observations and scoped review → Web evidence

HTTP verb tampering Validated Core

web_verb_tampering

Web investigation · Web observations and scoped review → Web evidence

IDOR / parameter enumeration Validated Core

web_idor_probe

Web investigation · Web observations and scoped review → Web evidence

LFI exploitation Validated Core

web_lfi_exploit

Web investigation · Web observations and scoped review → Web evidence

nuclei parallel Validated Core

web_nuclei

Web investigation · Web observations and scoped review → Web evidence

OS command injection probe Validated Core

web_cmdi_probe

Web investigation · Web observations and scoped review → Web evidence

post-auth CVE PoC workbench review Validated Core

web_post_auth_poc_workbench

Web investigation · Web observations and scoped review → Web evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202639
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

post-auth exploit probes Validated Core

web_post_auth_exploit_probes

Web investigation · Web observations and scoped review → Web evidence

post-auth surface harvest Validated Core

web_post_auth_harvest

Web investigation · Web observations and scoped review → Web evidence

SQLi OS shell (--os-cmd / --os-shell) Validated Core

web_sqli_post_exploit

Web investigation · Web observations and scoped review → Web evidence

SQLi probe Validated Core

web_sqli_probe

Web investigation · Web observations and scoped review → Web evidence

SSTI probe Validated Core

web_ssti_probe

Web investigation · Web observations and scoped review → Web evidence

target-specific password generation Validated Core

web_cewl

Web investigation · Web observations and scoped review → Web evidence

web content analysis Validated Core

web_content_analysis

Web investigation · Web observations and scoped review → Web evidence

web file upload attack Validated Core

web_file_upload_attack

Web investigation · Web observations and scoped review → Web evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202640
RedShades / Automatic stage atlasTECHNICAL EDITION
88 automatic declarations · conditional graph

Core stage atlas

Each entry identifies available work and its evidence context. Separate C2 families extend session work.

web fingerprint + wafw00f Validated Core

web_whatweb_waf

Web investigation · Web observations and scoped review → Web evidence

web fuzzing (vhost+dir+ext) Validated Core

web_fuzz

Web investigation · Web observations and scoped review → Web evidence

web login brute force Validated Core

web_login_bruteforce

Web investigation · Web observations and scoped review → Web evidence

web RCE candidate correlation Validated Core

web_rce_candidate_correlation

Web investigation · Web observations and scoped review → Web evidence

web RCE confirmation Validated Core

web_rce_confirm

Web investigation · Web observations and scoped review → Web evidence

web RCE deployment preparation Validated Core

web_rce_deployment_prepare

Web investigation · Web observations and scoped review → Web evidence

XSS probe Validated Core

web_xss_probe

Web investigation · Web observations and scoped review → Web evidence

XXE probe Validated Core

web_xxe_probe

Web investigation · Web observations and scoped review → Web evidence

Results return to the evidence-driven scheduler. Stage declarations describe available work, not a mandatory linear sequence.

Independent engineering · September 202641
RedShades / C2 continuationTECHNICAL EDITION
13 continuation stages

Session work follows platform-specific branches

Registered session context selects Windows, Linux and shared continuation work. These 13 stages complement the 88-stage Validated Core and are included in the 198-stage catalog.

permission enumerationwindowswindows_permission_enum
Linux permission enumerationlinuxlinux_permission_enum
pivot tunnel + internal discoveryCross-platformpivot_tunnel
filesystem enumerationwindowswindows_filesystem_enum
expanded privilege escalation enumerationwindowswindows_privilege_escalation
privilege escalation exploitationwindowswindows_privilege_escalation_exploit
Windows lateral movementwindowswindows_lateral_movement
Windows persistencewindowswindows_persistence
Linux filesystem enumerationlinuxlinux_filesystem_enum
expanded Linux privilege escalation enumerationlinuxlinux_privilege_escalation
Linux privilege escalation exploitationlinuxlinux_privilege_escalation_exploit
Linux lateral movementlinuxlinux_lateral_movement
Linux persistencelinuxlinux_persistence

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.

RedShades · September 202642
RedShades / Shared specialist toolsTECHNICAL EDITION
Planned integrations · packaging pending

Specialist domain and tool relationships

48 descriptors: 37 potential third-party packages, one external Apple toolchain and ten native or custom components. Domain totals overlap through reuse.

Cluster → capability → shared tool architecture
Domain clusterAnalysis capabilitiesPrimary and alternative components
Android / mobile8 stages · 10 referenced entriesartifact intake · provenance custody · configuration review · static analysis · topology modeling · evidence correlation · emulation simulation · reportingAndroguard · Apktool · Android bundletool · Cosign · JADX · Mobile Security Framework · RedShades artifact intake · RedShades typed evidence graph · RedShades policy and effect gate · RedShades evidence-backed reporting
Apple platforms8 stages · 8 referenced entriesartifact intake · provenance custody · binary decomposition · configuration review · static analysis · topology modeling · emulation simulation · reportingipsw · LLVM binary utilities · RedShades artifact intake · RedShades typed evidence graph · RedShades policy and effect gate · RedShades privacy/data-flow model · RedShades evidence-backed reporting · Apple codesign/security toolchain
Blockchain8 stages · 8 referenced entriesartifact intake · provenance custody · static analysis · evidence correlation · emulation simulation · topology modeling · reportingCosign · Echidna · Foundry · RedShades artifact intake · RedShades typed evidence graph · RedShades evidence-backed reporting · Slither · Solidity compiler
Bluetooth / BLE / NFC7 stages · 8 referenced entriesartifact intake · passive capture parsing · configuration review · evidence correlation · topology modeling · reportingBlueZ btmon · libnfc utilities · RedShades artifact intake · RedShades typed evidence graph · RedShades protocol observation normalizer · RedShades evidence-backed reporting · Wireshark/TShark · Zeek
Wi-Fi / RF8 stages · 9 referenced entriesartifact intake · topology modeling · passive capture parsing · static analysis · evidence correlation · policy gating · reportingGNU Radio · RedShades artifact intake · RedShades typed evidence graph · RedShades policy and effect gate · RedShades protocol observation normalizer · RedShades evidence-backed reporting · Suricata · Wireshark/TShark · Zeek
LLM / AI systems8 stages · 10 referenced entriesartifact intake · topology modeling · configuration review · emulation simulation · evidence correlation · supply chain analysis · reportinggarak · Inspect AI · OSV-Scanner · RedShades artifact intake · RedShades typed evidence graph · RedShades policy and effect gate · RedShades privacy/data-flow model · RedShades evidence-backed reporting · Syft · Trivy

97 expansion stages: 80 Advanced (78 domain stages and two shared helpers) and 17 Ultimate. Licensing and validation apply to each integration. The 48 entries include 47 stage-referenced components and one foundational router.

RedShades · September 202643
RedShades / Shared specialist toolsTECHNICAL EDITION
Planned integrations · packaging pending

Specialist domain and tool relationships

48 descriptors: 37 potential third-party packages, one external Apple toolchain and ten native or custom components. Domain totals overlap through reuse.

Cluster → capability → shared tool architecture
Domain clusterAnalysis capabilitiesPrimary and alternative components
Satellite / space7 stages · 10 referenced entriesartifact intake · passive capture parsing · configuration review · topology modeling · emulation simulation · reportingGNU Radio · gr-satellites · Orekit · RedShades artifact intake · RedShades typed evidence graph · RedShades protocol observation normalizer · RedShades evidence-backed reporting · RedShades OT/space safety model · Wireshark/TShark · Zeek
Quantum readiness6 stages · 6 referenced entriescryptographic inventory · evidence correlation · configuration review · topology modeling · emulation simulation · reportingCirq · Qiskit SDK · RedShades artifact intake · RedShades cryptographic evidence normalizer · RedShades typed evidence graph · RedShades evidence-backed reporting
Hardware / firmware9 stages · 11 referenced entriesartifact intake · binary decomposition · supply chain analysis · static analysis · configuration review · evidence correlation · emulation simulation · reportingBinwalk · Cosign · Ghidra · ipsw · LLVM binary utilities · QEMU · RedShades artifact intake · RedShades typed evidence graph · RedShades evidence-backed reporting · Syft · Trivy
ICS / SCADA9 stages · 11 referenced entriesartifact intake · passive capture parsing · topology modeling · safety modeling · configuration review · static analysis · evidence correlation · emulation simulation · policy gatingOpenSCAP · QEMU · RedShades artifact intake · RedShades typed evidence graph · RedShades policy and effect gate · RedShades protocol observation normalizer · RedShades evidence-backed reporting · RedShades OT/space safety model · Suricata · Wireshark/TShark · Zeek
Defensive patching8 stages · 9 referenced entriessupply chain analysis · evidence correlation · static analysis · reporting · policy gatingCosign · Grype · OSV-Scanner · RedShades typed evidence graph · RedShades defensive change planner · RedShades policy and effect gate · RedShades evidence-backed reporting · Syft · Trivy
Digital forensics9 stages · 12 referenced entriesprovenance custody · artifact intake · forensic analysis · evidence correlation · reportingCosign · Plaso · RedShades artifact intake · RedShades typed evidence graph · RedShades policy and effect gate · RedShades evidence-backed reporting · The Sleuth Kit · Velociraptor · Volatility 3 · Wireshark/TShark · YARA · Zeek
Shared Advanced helpers2 stages · 3 referenced entriesevidence correlationRedShades artifact intake · RedShades typed evidence graph · RedShades evidence-backed reporting

The two shared helpers normalize cross-domain evidence and correlate observations into a converged assessment record.

97 expansion stages: 80 Advanced (78 domain stages and two shared helpers) and 17 Ultimate. Licensing and validation apply to each integration. The 48 entries include 47 stage-referenced components and one foundational router.

RedShades · September 202644
RedShades / BundlesTECHNICAL EDITION
Under testing

Specialist application domains

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.

RedShades · September 202645
RedShades / BundlesTECHNICAL EDITION
Under testing

Wireless and AI assessment domains

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.

RedShades · September 202646
RedShades / BundlesTECHNICAL EDITION
Under testing

Satellite systems and quantum readiness

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.

RedShades · September 202647
RedShades / BundlesTECHNICAL EDITION
Under testing

Physical and industrial systems

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.

RedShades · September 202648
RedShades / BundlesTECHNICAL EDITION
Under development

PurpleShades and digital forensics

PurpleShades · Defensive patching

8 stages · Under development

Asset and finding intake opens parallel exposure, dependency and remediation analysis. A change plan brings the branches together with rollback criteria, canary observations and approval requirements.

Advisories → assessment branches → change proposal → rollback / canary criteria → approval → review packet

The workflow assembles a reviewed proposal and defines the evidence required to validate a future change.

Digital forensics

9 stages · Under development

Case intake establishes evidence identity and custody. Artifact, timeline and correlation branches preserve source attribution and converge into a reviewable case record.

Case intake → evidence preservation → analysis branches → correlation → review → case report

Integrity checks precede analysis. Incomplete or conflicting observations remain visible in the final evidence account.

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.

RedShades · September 202649
RedShades / BundlesTECHNICAL EDITION
Annual pricing per seat

Annual pricing and bundle entitlements

Each annual seat brings the native workspace, integrated tool workflows and controlled model access together. Select the assessment scope and deployment entitlement that fit the work.

Core

Starting at$7,000/ year per seat

88 Core stages + 13 C2 continuation stages

Validated Core

100 fine-tuned specialist adapters for bounded stateless calls and code-review roles. Gated 30B3A Flash access includes 50,000 credits per week throughout the active annual subscription.

Advanced

Starting at$14,000/ year per seat

Core stage scope + 80 Advanced stages

Under testing

Fine-tuned 30B3A Flash model weights included under NDA for persistent higher-complexity sessions. The weights entitlement gives qualified deployments direct access to the model asset.

Ultimate

Starting at$20,000/ year per seat

Core and Advanced stage scope + 17 defensive and forensic stages

Under development

50,000 credits per week throughout the active annual subscription. The proprietary multi-encoder suite adds task-specific embedding and representation variants for defensive and forensic work; it is not an LLM. An optional additional $5,000 weights entitlement under NDA supports intensive parallel and large-network deployments.

Fine-tuned model and adapter access is controlled by subscription gates. Weights access is a separate, selective entitlement under NDA. Active subscriptions receive applicable weights and stage updates at least every six months.

198 stages: 88 Validated Core + 13 C2 continuation + 80 Advanced + 17 Ultimate.

88 Core + 13 C2 continuation + 80 Advanced + 17 Ultimate = 198 stages.