Dreadnode
New Castle, US Β· Founded 2023 Β· 20 employees on LinkedIn Β· 4 known investors
Dreadnode builds infrastructure for deploying AI-powered security agents at scale, serving security teams and operators who need to operationalize artificial intelligence for offensive and defensive security operations.
Also known as Dreadnode Strikes
Founders & leadership
Dreadnode was founded in 2023 by Will Pearce.

Investors Β· 4
Company profile
researched Aug 2026Dreadnode develops infrastructure for the security stack, providing a platform that covers the full agent development lifecycle β build, evaluate, optimize, deploy, observe, and iterate. Its product is described as a terminal-native platform for building, evaluating, and deploying offensive security agents, with components including a TUI, hosted evaluations, training and optimization, and a self-hostable deployment via Helm on Kubernetes.
The platform bundles pre-built "capabilities" (agents, tools, skills, MCP servers, and workers) authored by the company's own operators, evaluation tooling for baselining and benchmarking agent behavior against security tasks, observability that extends beyond session logs to tool- and model-call traces, and sandboxed, segmented environments for agent execution. It is positioned as model- and framework-agnostic. A component called Worlds performs synthetic data generation for Active Directory environments and generates trajectories for model training. Advertised capability areas include AI red teaming, penetration testing, vulnerability research, network operations, web application penetration testing, AI security probing and safety assessment, agentic security testing, multi-modal and multilingual probing, and model evaluations.
Dreadnode also publishes research, papers, talks, and open-source code. Public benchmarks and tools include DreadIndex, an offensive-security evaluation index scoring language models 0-100 across 76 public and private tasks in 10 categories with cost-per-model and cheated/refused flags; AIRTBench; PentestJudge and ScopeJudge (LLM judges gating offensive agent tool calls); Ares, an autonomous multi-agent red/blue team system for live Active Directory environments; and DreadGOAD, a programmatically deployable Active Directory lab forked from GOAD.
Founding story
The company was started by offensive security operators and describes itself as built by and for that community, founded to prove AI could carry out offensive security operations.
Business model
Dreadnode offers a platform product available as a hosted service at app.dreadnode.io and as a self-hosted deployment installed onto a customer's own Kubernetes cluster via Helm. A CLI installer and an open-source SDK (the Dreadnode Strikes SDK) provide entry points, and a library of capabilities is published in a public repository for use out of the box or as a base for customer-built agents.
Traction
Public open-source traction includes the rigging framework at roughly 418 GitHub stars, dyana at about 366, agent-lens at about 114, DreadGOAD at about 99, robopages at about 90, and Ares at about 71, across 31 repositories in the organization. The company reports red teaming Meta's Llama Scout with 232 critical vulnerabilities identified in three hours, and has built multimodal offensive security evaluations for a tier-1 frontier model provider. The platform shipped monthly feature releases through 2025-2026, including multimodal AI red teaming, a traditional-ML red teaming suite, agent memory and triage, and Kubernetes Gateway API support.
βΈFull profile β market position, technology, go-to-market, history, risks & controversies
Market position
The company positions itself as an infrastructure layer rather than a point solution, arguing that model intelligence is commoditizing while the infrastructure that turns model capability into reliably deployed security agents is not, and that security lacks the ML ops infrastructure that emerged around AI-assisted software engineering.
Stated differentiators include an infrastructure-first, model- and framework-agnostic posture; a terminal-native workflow; pre-built capabilities authored by in-house offensive security experts; deep observability at the tool- and model-call level; synthetic environment and trajectory generation for training via Worlds; and a substantial body of published benchmarks, papers, and open-source tooling.
Technology
The platform spans the agent lifecycle with a terminal user interface, hosted evaluations against published tasks, agent training/optimization, session and trace inspection covering every tool and model call, agent memory, triage and session monitoring, and structured agent output backed by a versioned item type registry. Deployment is model- and framework-agnostic, with sandboxed, segmented, scalable environments, an API, function and MCP interfaces, and Kubernetes Gateway API support for on-prem installs. Supporting open-source projects include rigging (a lightweight LLM interaction framework), robopages (a YAML format describing tools to LLMs) and its Rust CLI, dyana (a sandbox for loading, running and profiling models and other file types), agent-lens (agent observability and replay tooling), Ares, and DreadGOAD. Red teaming workflows are grounded in a stated 45+ adversarial attacks, 450+ transforms, and 130+ scorers.
Go-to-market
Dreadnode markets through a public CLI install, extensive documentation, an open-source GitHub presence, published research including blogs, papers and conference talks (for example a talk at Offensive AI Con 2025), live red-teaming demonstrations against frontier models, public benchmarks such as DreadIndex, and policy engagement including a response to the 2025 Regulatory Reform for Artificial Intelligence RFI.
Security teams and offensive security operators β including red teams, penetration testers, vulnerability researchers, and AI red teams β that want to build and operate agent-driven security programs; the company has also run instrumented evaluations for a frontier model provider.
History
Dreadnode was founded with the mission of proving that AI can perform offensive security operations. The company states that thesis has been validated across use cases and that it has since broadened its scope from offensive security to infrastructure for the wider security stack, while continuing to prioritize offensive security and AI red teaming capabilities.
Risks & controversies
The company's own research documents reliability limitations relevant to its product area: benchmarking of LLM judges for runtime scope gating found the best judge still missed roughly 1 in 10 tool scope violations, and a controlled prompt-ablation study across 23 tasks and 1,518 audited traces examined how frequently frontier models cheat on offensive cyber benchmarks. The platform's capabilities β including autonomous malware research such as work on eliminating the C2 server β are inherently dual-use.
Compiled by commissioned research from 6 cited public sources β announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed β not independently audited.
Competitors Β· 6
by search overlapCompanies competing with Dreadnode for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline Β· 10
launches, deals, and filingsEvasion, extraction, membership inference, and model inversion red teaming in one platform.
An offensive cybersecurity evaluation index for language models covering 76 public and private tasks across 10 categories, scoring models 0-100 with cost per model and cheated/refused flags.
Probing of vision, audio, and video models with media rendering in findings and traces.
Long-running background processes that orchestrate multi-agent pipelines, bridge external tools, and run scheduled tasks in a few lines of Python.
Ares is an autonomous multi-agent system running red and blue team evaluations against live Active Directory environments; DreadGOAD is a reproducible, programmatically deployable Active Directory lab forked from GOAD.
A world model system generating synthetic Active Directory data and training trajectories; an 8B model trained on this data achieved Domain Admin on GOAD.
Dreadnode's response focuses on optimizing AI-enabled cybersecurity through strategic, machine-readable automations.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
βΈResearch sources Β· 6
primary sources listed
- Dreadnodedreadnode.io Β· web
6 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Dreadnode do?
- Dreadnode builds a terminal-native platform for building, evaluating, and deploying AI security agents for offensive security work.
- Who founded Dreadnode?
- Dreadnode was founded by Will Pearce in 2023.
- Who are Dreadnode's investors?
- Dreadnode's investors include Aviso Ventures, Decibel Partners, Next Frontier Capital, In-Q-Tel.
- Where is Dreadnode headquartered?
- Dreadnode is headquartered in New Castle, US.





