Oyster by Red Orca. Understands the attack without becoming it.
Oyster is Red Orca's AI assistant for security work. Ask how an attack works and how to detect and prevent it. With a free account, you can also question your own files and get cited answers, plan authorized tests inside a scope you declare, and work through incident evidence in SOC Copilot. Oyster explains and plans — it has no access to your systems and runs nothing against them.
One free message a day without an account. A free account removes the daily limit.
Who it is for
Built for the people who do the security work.
Offensive technique is in scope as education for defenders: Oyster explains how attacks work so you can detect and prevent them.
People learning security
Students and career-changers who want attacks, defences and tools explained plainly, with concrete examples instead of generalities.
Security practitioners
Penetration testers, SOC analysts and detection engineers who want a second pair of eyes on a plan, a log, a rule or a piece of code.
Teams doing authorized work
Security teams that plan tests against systems they are allowed to test, and want the scope written down before anything else happens.
What it does today
Open it and ask. Sign up for the workspace.
What you can use depends on whether you have an account. Both are free.
Without an account
- Chat about security engineering: vulnerabilities, secure coding, hardening, threat modelling, incident response and defensive architecture
- One message a day
- The conversation stays in your browser — it is never stored on our servers and never used for training
With a free account
- Chat
- The same assistant with no daily limit, your history saved to your account, and a choice of models. One answer is generated at a time.
- Questions over your own files
- Upload documents, images or video to your private workspace and ask about them. Answers cite the passages they drew on. Up to 20 uploads a day, 50 MB per file, 500 MB in total.
- Red Team: Scope, Recon, Planner, Fix Advisor, Code Lab
- Declare what you are authorized to test first. Recon and test plans are only written for targets inside that scope, and Oyster only writes them — it does not scan, probe or run anything. Fix Advisor and Code Lab review code and suggest remediations.
- Blue Team: SOC Copilot
- A workbench for investigations: open a case, attach evidence, build a timeline, track indicators of compromise, map activity to MITRE ATT&CK, draft detection rules for Sigma, Splunk SPL and Elastic KQL/ES|QL, follow playbooks and export a report.
- Findings
- Keep what you learn as findings. They are private by default; you can share one as a read-only link, or publish it to a feed that other signed-in users can read.
Not offered to accounts: running tools against real hosts and connecting live security monitoring (SIEM) systems. Those stay with Red Orca's own operators.
A worked example
From a question to a detection.
An illustrative walkthrough of the workflow — not a recorded answer. Real answers vary with the question and the model.
01 — You ask
“What is Kerberoasting, and how would I spot it in our Windows event logs?”
02 — What Oyster does
Explains the technique — MITRE ATT&CK T1558.003: an attacker with any domain account requests Kerberos service tickets and cracks them offline to recover service-account passwords — and names the logs where it shows up. It connects to nothing and runs nothing.
03 — What you get back
The events to watch (Kerberos service-ticket requests, Windows event ID 4769, especially RC4-encrypted tickets), a starting point for a detection rule you can draft in SOC Copilot, and hardening steps: long random service-account passwords, managed service accounts, AES-only encryption.
04 — The limits
The answer comes from a language model: check it against your environment and the vendor's documentation before you act. Oyster sees your logs only if you upload them to your own workspace.
Pricing and access
Oyster is free.
The same Red Orca account also opens Dolphin and Shark.
Without an account
Free
- Chat only
- One message a day
- Nothing stored on our servers
Free account
Free
- No daily message limit
- Files, Red Team, Blue Team and Findings
- Conversations are used to improve Oyster — see below
Openweight editions
Not yet on sale
- Oyster packaged to run on your own hardware
- Listed in the app's Openweight tab
- Questions and files would stay on your machine
Your data
What happens to what you type.
- Without an account, your conversation stays in your browser. It is not stored on our servers and never used for training.
- With an account, your conversations are stored in your account, visible only to you, and are used to improve Oyster's AI. That is a condition of the free account, not an optional extra. Exchanges that contain credentials are dropped from training data, not redacted. You can withdraw in Settings — which also ends chat access — or delete your account and its data there at any time.
- Files you upload stay in your own private workspace. Other accounts cannot see them.
- Oyster's models run on infrastructure we operate ourselves, in the EU. Your conversations are not sent to a third-party AI provider.
The full detail is in the privacy policy and the terms of service.
Limits
What Oyster does not do.
- Answers come from a language model and can be wrong. Verify anything you act on.
- Oyster has no access to your systems. It cannot scan, probe or exploit anything, and you remain responsible for being authorized to test the systems you discuss.
- It runs on our own hardware, so answers can take several seconds, and each account gets one answer at a time.
- It is not a substitute for professional incident response, legal advice or a penetration test.
Questions
Before you open it.
What is Oyster?+
Oyster is a cybersecurity AI assistant made by Red Orca. It answers security engineering questions — how attacks work and how to detect and prevent them — and, with a free account, adds questions over your own files, red-team planning inside a declared scope, the SOC Copilot investigation workbench and Findings.
Is Oyster free?+
Yes. Without an account you get one message a day. A free Red Orca account removes the daily message limit and opens the full workspace. Openweight editions that run on your own hardware are listed in the app but are not on sale yet.
Are my conversations used for training?+
Anonymous conversations are never stored on our servers and never used for training. Conversations in a free account are stored in that account and used to improve Oyster's AI — that is the condition of the free account. Withdrawing in Settings stops it and also ends chat access.
Can Oyster attack or scan a system?+
No. For every account, Oyster explains and plans; it does not scan, probe or run tools. Red-team plans are only written for targets inside the scope you declare, and you are responsible for having authorization to test them.
What can I upload?+
With a free account: documents, images and video, into a private workspace only you can see. Up to 20 uploads a day, 50 MB per file and 500 MB in total. Answers about your files cite the passages they used.
How is Oyster related to Dolphin and Shark?+
They are Red Orca's three agents and share one account and one sign-in. Dolphin makes outbound sales calls and sends email, Shark keeps a team's organizational memory, and Oyster helps with security work.
Further reading
Why we are building Oyster.
Ask it something hard.
Start without an account, or create one to open the full workspace. Either way it is free.