
Physical & Cyber Security Projects
We build our own tools. Not as products, but because on live engagements we kept hitting gaps that off-the-shelf tooling could not close. Each of these came out of real work, and we released them because the community should have them.
Everything here is open source and free to use. The code lives on GitHub.
A complete penetration testing environment in one install. 50+ security tools plus custom automation frameworks, configured and maintained so you spend time testing instead of building your rig. Our most widely used project.
A modular honeypot system in Python for threat intelligence and network monitoring. It mimics real systems to capture how attackers actually operate against you, turning attempted intrusions into usable intelligence.
An automated reconnaissance framework for the early stage of an engagement. Point it at a target domain and it chains together DNS enumeration, subdomain and takeover detection, M365 and Azure AD tenant attribution, cloud storage discovery, email harvesting, LinkedIn employee mapping, GitHub secret scanning, and breach lookups, then compiles it into a structured report. It automates the tedious first hours of an assessment so the time goes to analysis instead of collection.
Passive RF detection built on HackRF One hardware. It identifies hostile radio frequency scanning and monitoring around a location, the kind of activity that precedes a physical or technical attack. Built for the point where physical security and signals intelligence meet.
A metadata extraction and analysis tool for penetration testers and researchers. It crawls sites to surface the document metadata and hidden information an organization leaks without realizing it, the raw material for an OSINT profile.
Enterprise-grade monitoring for Linux systems. Real-time file integrity monitoring, process integrity monitoring, and optional log integrity monitoring in a client-server model, for teams that need to know the moment something on a host changes.
A modern rebuild of the classic DumpSec. Deep security audits of Windows systems, surfacing permission and configuration gaps that standard scans miss, with findings laid out for the people who have to fix them.
A lightweight MAC address spoofing utility built for modern Windows 11, where most existing tools crash or fail silently. Made for physical security teams and red teamers who need reliable spoofing onsite, with a minimal footprint for OPSEC-sensitive work and a clean restore when the engagement ends.







