Skills & tools.

Every engagement is a workflow, and every workflow runs on the right tool. Here is the categorized toolkit behind the work — from initial recon to post-exploitation.

6 tool categories 34 tools searchable + filterable
domains covered

Where these skills apply

Seven security domains, each supported by purpose-built tooling rather than one-size-fits-all utilities.

Penetration Testing

Simulating attacker TTPs across customer environments and validating exploitable weaknesses.

Vulnerability Assessment

Scanning servers and infrastructure, surfacing critical weaknesses with remediation strategies.

Web Application Security

End-to-end evaluation of web applications with detailed remediation reporting.

Mobile App Security

Android and iOS testing through dynamic and static analysis techniques.

API Testing

Penetration tests on APIs — auth, authorization and data-handling flaws.

OSINT

Mapping the exposed footprint of an organization before an engagement begins.

Digital Forensics

Evidence-oriented analysis of systems and artifacts to support investigation.

Active Directory

Mapping identity and trust paths for post-exploitation and lateral movement.

toolkit · interactive

The toolkit, filtered

Search or filter by security domain. Each tool is color-coded to its category.

why it matters

Tools are chosen for the fight, not for show

Each category earns its place by solving a real problem at a specific stage of an assessment — discovery, exploitation, identity mapping, scripting or reporting. That keeps engagements fast, repeatable, and honest.

See where these get used
about the operator

Putting the toolkit to work