Building offensive security tools — one wave at a time
| Tool | What It Does | Language |
|---|---|---|
| Aquifer | Linux post-exploitation framework with kernel namespace isolation and polymorphic beacons | |
| Siphon | Lightweight C2 framework — ECDH P-256 forward secrecy, AES-256-GCM, uTLS fingerprinting | |
| Wellspring | Payload delivery server — token-gated access, 12 delivery methods, AES-256-GCM encryption at rest | |
| Spillway | Reverse/bind FUSE filesystem mount over TLS 1.3 | |
| Undertow | Statically-linked SSH server — reverse shells, SFTP, port forwarding |
| Tool | What It Does | Language |
|---|---|---|
| Riptide | Collaborative browser terminal & playbook workspace for red teams | |
| Runoff | Extract AD attack paths & quick wins from BloodHound CE | |
| Maelstrom | NetExec wrapper — 35+ AD enumeration modules in a single command | |
| Rapids | Modular credential spraying — 28 protocol modules with pass-the-hash | |
| Seep | Windows privilege escalation enumeration — 16 checks, 97 tools, MITRE ATT&CK mapping | |
| Whirlpool | Privilege escalation reasoning engine — parses LinPEAS/WinPEAS output |
| Tool | What It Does | Language |
|---|---|---|
| Shallows | Browser-native Linux terminals powered by x86 emulation — no servers, no installs | |
| Ripple | Browser-based Vim editor — CodeMirror 6, Catppuccin Mocha, zero dependencies | |
| Deluge | Nmap & RustScan output parser with color-coded reports and multi-format export | |
| Surge | Offline-first command reference with fuzzy search & variable substitution | |
| Fathom | Lightning-fast offline man pages browser with TLDR summaries | |
| Sunken-Archive | Personal knowledge base & digital garden built on Quartz |
| Tool | What It Does | Language |
|---|---|---|
| Tidemark | Obsidian plugin — replace variables in markdown with YAML frontmatter values | |
| LigoloSupport | One-command ligolo-ng tunnel setup |
All tools are built for authorized security testing and educational purposes.