Former IBM X-Force Red Leaders Launch Commercial Offensive Cyber Platform
RemoteThreat, a Fulton, Maryland-based cybersecurity startup, emerged from stealth mode on September 29, 2026, with $7 million in pre-seed funding from Osage University Partners and DataTribe. The company says it has built the first commercial end-to-end platform for offensive cyber operations, called the O/C/O Platform, aimed at enterprise and critical-infrastructure red teams, U.S. government mission teams, and vetted defense partners. RemoteThreat was founded by Chris Thompson (CEO) and Shawn Jones (CTO), both former leaders of IBM's X-Force Red offensive security team, and has already joined U.S. Special Operations Command's SOF RACER acquisition consortium and struck an integration partnership with defense contractor Talon Defense Inc.
Details
| Attribute | Value |
|---|---|
| Company | RemoteThreat |
| Headquarters | Fulton, Maryland |
| Milestone | Emerged from stealth mode, September 29, 2026 |
| Funding round | $7 million pre-seed |
| Investors | Osage University Partners, DataTribe |
| CEO | Chris Thompson — formerly led IBM X-Force Red |
| CTO | Shawn Jones — formerly led IBM X-Force Red |
| Strategic advisor | The Nakasone Group (retired Gen. Paul M. Nakasone) |
| Flagship product | O/C/O Platform for offensive cyber operations |
| Target customers | Enterprise/critical infrastructure red teams, U.S. government mission teams, vetted defense partners |
| Government/defense ties | SOF RACER consortium (USSOCOM); integration partner Talon Defense Inc. |
What the O/C/O Platform Does
Eight Connected Systems
RemoteThreat describes the O/C/O Platform as a single stack that unifies eight components that offensive teams have historically had to assemble themselves from separate tools:
- Mission planning and oversight
- Command and control (C2), with configurable traffic profiles that can run alongside a customer's existing C2 infrastructure
- Implants that work across operating systems and architectures, supporting in-memory execution
- An initial access framework
- A library of composable capabilities
- An obfuscation pipeline for control-flow obfuscation and payload composition
- Targeting, tasking, and analysis engines
- AI assistants, built for expert human operators rather than as autonomous replacements
The platform also bakes in governance controls — Rules of Engagement enforcement and audit trails — intended to keep human operators in the loop even as AI-assisted and autonomous task execution are layered on top of manual operation.
Built by Operators, With Government Backing
RemoteThreat's team draws from IBM X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, and Microsoft, along with defense contractors and government agencies. The Nakasone Group — the advisory firm founded by retired U.S. Army General Paul M. Nakasone, former head of U.S. Cyber Command and the NSA — is serving as a strategic advisor. CTO Shawn Jones framed the platform's purpose around a shifting adversary landscape: "Internal red teams are being asked to model adversaries whose capabilities change faster than the tools used to emulate them." He added, "The answer is not another black-box, automated penetration testing tool that removes the operator."
Positioning Against Existing Red-Team Tooling
RemoteThreat is explicitly targeting the gap between fragmented, DIY red-team toolchains (custom C2 frameworks, standalone implant kits, separate obfuscation and reporting tools) and fully automated penetration-testing products that reduce operator control. CEO Chris Thompson said expert operators "spend too much time assembling tools and building integrations, on top of the cognitive demands of planning operations," and described the company's goal as bringing "composable, tunable offensive capabilities, operational infrastructure, and governed AI into one platform — so teams can execute more advanced, complex attacks at speed and scale while maintaining the precise control each mission demands." Investor Osage University Partners said the founders' "experience running operations against the world's hardest targets gave them an early read on where the market was headed."
Policy Tailwinds Behind the Launch
RemoteThreat's launch lands amid a broader U.S. policy shift toward sanctioned private-sector offensive cyber activity. An August 12, 2026 presidential memorandum directed the creation of a program allowing vetted U.S. companies to conduct cyber operations against foreign cybercriminal groups. Separately, the Senate's fiscal 2027 defense authorization bill includes a trial program that would let private companies gain and maintain access to adversary networks under U.S. Cyber Command authority. RemoteThreat has joined U.S. Special Operations Command's SOF RACER (Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements) to pursue offensive cyber capabilities for special operations missions, and defense technology firm Talon Defense Inc. is integrating RemoteThreat's components into systems it already fields.
Impact Assessment
| Impact Area | Description |
|---|---|
| Red-team tooling market | A well-funded, operator-led entrant now competes with established commercial C2/adversary-emulation frameworks and boutique red-team consultancies by offering an integrated, end-to-end platform instead of point tools. |
| Defense-in-depth pressure | Consolidated mission planning, C2, implants, and AI-assisted tasking in one platform could shorten the time needed to plan and execute complex adversary emulation, raising expectations for blue-team detection and response speed. |
| Policy and regulatory shift | The launch coincides with the Aug. 12, 2026 presidential memorandum and pending FY2027 NDAA language expanding the legal basis for vetted private firms to conduct offensive operations against foreign adversary infrastructure. |
| Dual-use and proliferation risk | Commercial availability of composable implants, control-flow obfuscation, and configurable C2 — even gated to "vetted" customers — mirrors the trajectory of Cobalt Strike and Brute Ratel, both of which were later abused by real threat actors after wider distribution. |
| Government/defense market entry | SOF RACER membership and the Talon Defense Inc. integration give RemoteThreat an early foothold in the growing offensive-cyber-as-a-service segment tied to DoD and SOCOM mission requirements. |
Recommendations
For Red Team and Security Leaders Evaluating the Platform
- Independently verify governance claims before procurement. Ask for concrete detail on how Rules of Engagement enforcement and audit trails are technically implemented — not just described in marketing — and whether logs are tamper-evident and exportable for compliance review.
- Scope AI-assisted and autonomous task execution explicitly in contracts. Define what actions the platform's AI assistants can take without human sign-off, and require operator-approval gates for anything touching production systems or client environments.
- Assess vendor lock-in against configurable C2. The ability to run RemoteThreat's C2 alongside existing infrastructure is a selling point, but confirm data portability and exit terms before consolidating tooling onto a single new vendor.
For Blue Teams and Detection Engineers
- Treat newly commercialized offensive frameworks as future adversary tooling. Commercial red-team platforms have a track record of being reverse-engineered, cracked, or leaked and subsequently adopted by real intrusion actors; monitor threat intel feeds for O/C/O-related IOCs and TTPs as the platform gains adoption.
- Update detection logic for in-memory, cross-platform implants and configurable C2 traffic profiles. Static, signature-based detection is unlikely to catch payloads designed for tunable obfuscation; prioritize behavioral and memory-forensics-based detections.
- Use your own red team's adoption of composable platforms as a detection-engineering feedback loop. If your organization licenses O/C/O or similar tooling, feed its emulation runs directly into purple-team exercises rather than treating them as isolated engagements.
For Policymakers and Risk/Compliance Teams
- Track implementation of the August 2026 presidential memorandum and FY2027 NDAA provisions. The legal boundaries around vetted private-sector offensive operations against foreign infrastructure remain in formation and will shape liability and export-control exposure for vendors like RemoteThreat.
- Factor dual-use export control review into vendor risk assessments for any organization considering offensive platforms with government/defense ties, given the sensitivity of implant and C2 technology under existing export regimes.
Key Takeaways
- RemoteThreat emerged from stealth on September 29, 2026, with $7 million in pre-seed funding from Osage University Partners and DataTribe for its O/C/O offensive cyber operations platform.
- Founders Chris Thompson (CEO) and Shawn Jones (CTO) both formerly led IBM's X-Force Red team, and retired Gen. Paul M. Nakasone's Nakasone Group serves as strategic advisor.
- The O/C/O Platform integrates eight systems — mission planning, C2, implants, initial access, composable capabilities, obfuscation, targeting/tasking, and AI assistants — into one commercial stack.
- RemoteThreat is pursuing government and defense contracts, joining USSOCOM's SOF RACER consortium and integrating its components into systems fielded by Talon Defense Inc.
- The launch aligns with a policy shift toward sanctioned private-sector offensive cyber operations, following an August 12, 2026 presidential memorandum and pending FY2027 NDAA provisions.
- Security teams should treat the platform as both a legitimate red-team tool and a future dual-use risk — commercial C2 and implant frameworks have historically been co-opted by real threat actors after wider adoption.