A New Offensive-Security Startup Wants to Test What Happens After the Breach
Most red-team and breach-and-attack-simulation tools are built to answer one question: can an attacker get in? A new startup called RemoteThreat argues that's no longer the interesting part. Founded by former IBM X-Force Red leaders Chris Thompson (CEO) and Shawn Jones (CTO), the Fulton, Maryland-based company emerged from stealth on October 2, 2026 with $7 million in pre-seed funding and an AI-enabled offensive cyber operations platform called O/C/O. Rather than chasing initial access as the finish line, RemoteThreat is pitching enterprise and government red teams on emulating what a well-resourced adversary actually does once it is past EDR and already has a foothold — custom tradecraft, live command and control, and sustained post-exploitation activity designed to force detection teams to generate real noise instead of grading a static checklist.
Details
| Attribute | Value |
|---|---|
| Company | RemoteThreat |
| Founded | 2025 (publicly launched from stealth October 2, 2026) |
| Founders | Chris Thompson (CEO), Shawn Jones (CTO) — both former IBM X-Force Red leaders |
| Headquarters | Fulton, Maryland |
| Funding | $7 million pre-seed |
| Investors | Osage University Partners, DataTribe |
| Product | O/C/O Platform — integrated offensive cyber operations (OCO) suite |
| Category | Red teaming / breach-and-attack-simulation adjacent, positioned as a distinct "offensive cyber operations" category |
| Key differentiator | Tests post-compromise adversary behavior with custom, AI-assisted tooling rather than automating a fixed library of canned attack scripts |
| Strategic advisor | The Nakasone Group, led by retired General Paul M. Nakasone, former NSA director and U.S. Cyber Command commander |
What RemoteThreat Offers
The O/C/O Platform is built from eight connected components: mission planning and oversight, command and control (C2), implants, an initial access framework, composable capabilities, an obfuscation pipeline, targeting and tasking engines, and AI assistants layered across the workflow. According to the company, operators get cross-platform implants capable of in-memory execution, configurable C2 traffic profiles designed to blend into legitimate network behavior, and composable payloads and post-exploitation modules drawn from a library the company has described as roughly 1,000 tools. Teams can run engagements manually, with AI assistance, or in a more autonomous mode, with built-in rules-of-engagement controls, policy enforcement, and audit trails intended to keep high-intensity offensive exercises contained and accountable — a requirement for both enterprise clients and the government mission teams RemoteThreat says it also serves. The platform supports interchangeable AI backends, including models from OpenAI, Anthropic, or open-weight alternatives, rather than locking operators into a single provider.
RemoteThreat's 15-person team draws from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies — a roster the company says reflects both red-team tradecraft and the malware-development skill needed to build custom tooling per engagement rather than reusing off-the-shelf frameworks that defenders' tools may already fingerprint.
Why "After Defenses Fail" Matters
Thompson's pitch rests on a specific critique of the breach-and-attack-simulation (BAS) market: most tools validate whether a known technique trips a known control, which tells a security team little about what a determined, well-funded adversary does after that control is already bypassed. RemoteThreat's approach instead assumes the attacker gets past EDR and endpoint controls — the scenario security teams most need rehearsed — and then emulates the sustained, adaptive tradecraft a nation-state or advanced criminal operator would use afterward: pivoting, escalating, exfiltrating, and evading detection over an extended operation rather than a single scripted run. The goal, in Thompson's framing, is to force defenders to actually generate detections and alerts against live, human-directed (or AI-assisted) offensive activity, rather than passing a simulation that only checks for signature matches.
Underlying that pitch is a broader bet about where offensive capability is heading. Thompson has argued publicly that frontier AI models are advancing quickly enough that penetration testing, as practiced today, will look unrecognizable within roughly two years — and that security teams who only test against yesterday's techniques will be caught flat-footed by adversaries already using AI-accelerated tooling.
How This Fits the Red-Teaming Market
RemoteThreat is entering a crowded field that includes established BAS vendors (which largely emphasize automated, repeatable control validation) and traditional red-team consultancies (which emphasize bespoke, human-led engagements but scale slowly and expensively). RemoteThreat is positioning O/C/O as a middle path: a commercial, end-to-end platform that gives expert human operators AI-assisted tooling to build custom offensive infrastructure per engagement, aimed at both the enterprise/critical-infrastructure market and — notably — U.S. government mission teams and vetted defense partners conducting actual offensive cyber operations, not just simulated ones. That dual positioning, reinforced by the advisory partnership with The Nakasone Group, sets RemoteThreat apart from vendors that sell exclusively into the commercial security-testing market, and it signals an expectation that demand for integrated offensive tooling will keep growing across both government and private-sector buyers as AI lowers the cost of building adaptive attack infrastructure.
Impact Assessment
| Impact Area | Description |
|---|---|
| Red-team maturity | Pushes enterprise and critical-infrastructure red teams toward testing sustained post-compromise scenarios rather than only initial-access and control-validation exercises |
| Detection engineering | A platform built to generate real operational noise during engagements could meaningfully stress-test SOC detection and response playbooks beyond what canned BAS runs typically surface |
| Dual-use risk | An integrated, AI-assisted offensive platform with roughly 1,000 tools and custom-tooling capability raises the standard dual-use concern: the same capability that improves defensive testing could be misused if access controls, vetting, or rules-of-engagement enforcement are weak |
| Market dynamics | Backing from DataTribe (an investor with deep ties to the intelligence community) and an advisory role for a former NSA director/Cyber Command commander signal government-adjacent ambitions beyond the commercial red-team market |
| Vendor evaluation burden | Security leaders now face another category — "offensive cyber operations platforms" — to evaluate alongside established BAS and red-team service providers when planning adversary-emulation budgets |
Recommendations
For Security and Red-Team Leaders
- Treat post-compromise emulation as a distinct requirement from control-validation testing when scoping red-team or BAS engagements; ask vendors directly whether they test sustained, adaptive post-exploitation behavior or only scripted technique checks.
- Use any engagement with a platform like O/C/O to validate detection and response workflows end-to-end, not just whether a single alert fired — measure time-to-detect and time-to-contain against a live, adaptive operator.
- Confirm rules-of-engagement, logging, and audit-trail controls before granting any third-party offensive platform network access, regardless of vendor reputation or founder pedigree.
For Enterprise and Critical-Infrastructure Buyers
- Evaluate new offensive-security vendors against existing BAS and red-team contracts for overlap and complementary value rather than redundant spend.
- Request references and prior engagement case studies given RemoteThreat's early stage (stealth launch, 15 employees, pre-seed funding) before committing budget to a new, unproven vendor category.
- Factor AI-driven attacker tooling into tabletop exercises now; Thompson's two-year timeline for penetration testing's transformation is a vendor's sales narrative, but the underlying trend — AI lowering the cost of adaptive attack tooling — is already visible across the threat landscape.
For Government and Defense-Sector Security Teams
- Track how vetting and oversight (rules-of-engagement enforcement, audit trails) are implemented for any platform marketed for actual offensive cyber operations, not just simulation, given the regulatory and legal sensitivity of that use case.
- Weigh advisory relationships like The Nakasone Group partnership as a signal of intended government market fit, and factor that into procurement and security-clearance review timelines.
Key Takeaways
- RemoteThreat launched from stealth on October 2, 2026 with $7 million in pre-seed funding from Osage University Partners and DataTribe, founded by two former IBM X-Force Red leaders.
- Its O/C/O Platform integrates eight components — mission planning, C2, implants, initial access, composable capabilities, obfuscation, targeting/tasking, and AI assistants — into one offensive cyber operations suite.
- The core pitch is testing what happens after defenses fail: emulating sustained, adaptive post-compromise attacker behavior rather than only validating whether a known technique trips a known control.
- The platform targets both enterprise/critical-infrastructure red teams and U.S. government mission teams/vetted defense partners, a dual commercial-and-government positioning reinforced by an advisory partnership with The Nakasone Group.
- CEO Chris Thompson argues AI is accelerating offensive capability fast enough that traditional penetration testing will be fundamentally different within about two years.
- Security teams evaluating RemoteThreat or similar platforms should distinguish post-compromise emulation from standard control validation, and apply the same vetting rigor to offensive-tooling vendors that they would to any third party with privileged network access.