// Offensive Security Tooling

NO HAT
HACKER

White hat. Black hat. Grey hat.
We don't wear one.

Professional-grade tools built for red teams and penetration testers who are tired of being put in a box. Authorised use only — no apologies.

nohathacker — bash
nhh@ops:~$

The Tools

Built on Debian. Tested on Kali. Deployed on jump boxes.
macOS is for victims with excessive money. Windows is for victims with defective reasoning. We build for operators.

// cybersecurity

Threat detection, attack automation, and engagement tooling — one binary per mission.

// hawk series

Detection, threat intelligence, and skill audit — the hunter's toolkit.

● AVAILABLE NOW
👁

HawkEye ★ v3

HEY · v3.7.1 · Debian/Kali · x86-64 · Live NVD + MITRE
— even more vicious now

3,092 CVE attack flows. Zero false positives. Vulnerability intelligence from scan to shell to report in one native GUI — nmap NSE, live NVD enrichment, MITRE ATT&CK, and 3,376 Metasploit exploit pairs where every detection is a real, module-verified attack path. Discover → inject rogue VLANs/subnets → exploit → loot → report.

  • 3,092 CVE → 3,376 Metasploit exploit pairs — the whole framework, not a handful
  • Zero false positives — every attack proven by the module's own check
  • Aggressive Pentest chains — EternalBlue→domain, secretsdump, Kerberoast, RDP lateral
  • Auto-pentest — passive learn, rogue-gateway/VLAN detection, segment injection
  • 9,000+ Nuclei templates natively + live NVD API v2 + MITRE ATT&CK auto-mapping
  • Professional HTML report — network topology graph, findings, ATT&CK table
● LICENSING PAUSED
✉️

MailHawk

MLH · v1.0 · Debian/Kali · x86-64 · IMAP / Gmail / MS Graph
— your mailbox threat-hunter

Hunts the phishing that already landed. MailHawk connects to a live inbox and finds sender-auth spoofing, homograph & dnstwist lookalikes, disguised links and weaponised attachments — then harvests the actors' IOCs and taps a shared threat-intel feed. Every finding explainable, scored 0–100, MITRE ATT&CK + CAPEC typed. Existing licenses remain valid. No new licenses are being issued at this time.

  • Sender authentication — SPF/DKIM/DMARC, display-name & authority spoofing
  • Lookalike domains — homograph skeletons, punycode, dnstwist + live resolution
  • Link & attachment forensics — anchor/href mismatch, macros, HTML smuggling
  • Campaign signatures — fake-recruiter (DPRK-style), BEC/wire-fraud, cred-harvest
  • Deduplicating IOC ledger + RDAP/AbuseIPDB/VirusTotal/Shodan enrichment
  • Shared threat feed — the network catches an actor once, warns everyone
● AVAILABLE NOW
🛡️

SkillHawk

SKH · v0.1.0 · Debian/Kali · x86-64 · Fully offline
— the bouncer for your agent's skills

The install-gate for AI agent skills & MCP servers. Before a skill ever runs, SkillHawk pulls the bundle apart and hunts what's hiding — remote-bootstrap loaders, secret-exfiltration flows, weaponised dependencies, prompt-injected instructions — then returns one verdict: SAFE or DO NOT INSTALL, explainable to the exact file:line. Six detection layers, zero cloud, single static binary.

  • 460-pattern corpus + tree-sitter AST — real syntax trees, not grep
  • Data-flow taint engine — catches secrets→network & network→exec exfiltration
  • YARA-X malware rules + live OSV.dev dependency-CVE lookup
  • Rug-pull ledger — screams when a clean skill mutates on update
  • MCP install-gate mode — your agent auto-vets before it installs
  • Sovereign · runs air-gapped · terminal / JSON / SARIF output
// sidekick series

One static binary per engagement type. Drop it on the jump box and go.

● AVAILABLE NOW

Email Pentest Sidekick ★ v2

EPS · v3.1.0 · Debian/Kali · x86-64

The most complete email security assessment framework in existence. DMARC-pass attack automation, dark web credential hunting, SPF chain analysis, SMTP spray and forensic header analysis — one static binary, zero dependencies.

  • DMARC-pass spoofing via stolen M365/Gmail credentials
  • Tor-routed dark web & HIBP credential search
  • SMTP AUTH spray — Ignis 1M wordlists bundled
  • SPF walk · domain permutations · open relay hunter
  • Professional HTML/PDF pentest report
  • GUI + CLI · 3FA login · 30-min session auth
● AVAILABLE NOW
🌐

InfraScan Pentester Sidekick

IPS · v1.0.0 · Debian/Kali · x86-64

Network infrastructure pentesting with built-in intelligence. Live topology map with zoom/pan, rogue gateway detection, VLAN hop automation, 30+ vendor fingerprints, MITRE-mapped findings, and a professional HTML report with embedded network diagram.

  • Rogue gateway hunt — detects pfSense, FortiGate, Palo Alto, MikroTik + 25 more
  • VLAN enumeration + 802.1Q double-tag hopping (auto tshark)
  • Beyond-gateway probe — traceroute-guided multi-threaded subnet sweep
  • Live zoomable topology map — nodes, edges, gateway diamonds
  • MITRE ATT&CK mapped findings + HTML report with topology SVG
  • GUI + CLI · zero dependencies · static binary
● AVAILABLE NOW
🌐

WebVuln Pentester Sidekick

WPS · Debian/Kali · x86-64

Full-spectrum web application security assessment. Automated discovery and exploitation of injection, logic, and authentication flaws — from recon to proof-of-concept in one binary.

  • SQL injection — blind, error-based, time-based
  • XSS, SSTI, SSRF, XXE, IDOR automated chains
  • JWT attack suite — alg:none, key confusion, brute
  • Auth bypass — OAuth abuse, SAML confusion
  • Intercepting proxy with automated attack playbooks
  • GUI + CLI · PoC + evidence report output
⬡ BETA
🔬

DFIR Pentester Sidekick

DPS · Debian/Kali · x86-64

Digital forensics and incident response — three analysis engines in one binary. Windows event log triage, memory forensics, and PCAP/network forensics. From raw evidence to IOC list and incident timeline in minutes.

  • EVTX triage — attack timeline + MITRE ATT&CK mapping
  • Lateral movement chain reconstruction
  • Memory forensics via Volatility 3 wrapper
  • PCAP analysis — C2 detection + credential extraction
  • IOC hunting with OSINT enrichment
  • GUI + CLI · professional IR report output
⬡ BETA
🔑

CredDump Pentester Sidekick

CDS · Debian/Kali · x86-64

Windows credential extraction without the guesswork. Detects privilege paths, AV/EDR state, and LSASS protections — then selects the optimal extraction technique automatically.

  • Auto-detects privilege level, PPL, Credential Guard, EDR
  • LSASS — multiple extraction paths ranked by stealth
  • NTDS.dit via VSS shadow copy or remote DC dump
  • LAPS v1/v2 password extraction
  • SAM, LSA secrets, DPAPI master keys
  • GUI + CLI · auto-routes hashes to crackers
⬡ BETA
🏰

AD Pentester Sidekick

APS · Debian/Kali · x86-64

Active Directory attack chain automation — from zero access to domain compromise. Automates the full AD kill chain so you spend engagement time on findings, not stringing together eight different Python scripts.

  • Kerbrute user enum — no lockout risk
  • Kerberoasting + AS-REP roasting — hash extraction
  • BloodHound-compatible attack path analysis
  • Pass-the-Hash/Ticket · Over-Pass-the-Hash
  • ACL/DACL abuse · shadow credentials
  • DCSync → domain compromise · GUI + CLI
⬡ BETA

Cloud Pentester Sidekick

CPS · Debian/Kali · x86-64

AWS, Azure and GCP pentesting in one binary. IAM enumeration, privilege escalation paths, exposed storage discovery, serverless attacks and container escapes — cross-cloud credential harvesting built in.

  • IAM enumeration & privilege escalation paths
  • S3/Blob/GCS exposure scanner
  • Serverless function abuse & event injection
  • Container escape — ECS, EKS, AKS, GKE
  • Cross-cloud credential harvesting & lateral movement
  • GUI + CLI · cloud attack graph output
⬡ BETA
🔐

TunnelKit Pentester Sidekick

TPS · Debian/Kali · x86-64

VPN and tunnel security assessment. Tests WireGuard, OpenVPN, IPSec and SSH tunnels for misconfigurations, credential exposure, split-tunnel bypass and traffic interception vectors.

  • WireGuard & OpenVPN misconfiguration detection
  • Split-tunnel bypass & traffic leakage testing
  • IPSec weak cipher & PSK brute forcing
  • SSH tunnel pivoting & credential extraction
  • VPN credential spray per known providers
  • GUI + CLI · tunnel map + finding report
⬡ BETA
📡

WiFi Pentester Sidekick (Standard)

WFP · Standard · Debian/Kali · x86-64

Wireless security assessment from scanning to exploitation. WPA2/WPA3 handshake capture, PMKID attacks, evil twin automation and enterprise 802.1X/EAP downgrade attacks — from a single adapter.

  • WPA2/WPA3 handshake capture & PMKID attack
  • Evil twin with captive portal credential capture
  • Deauth & disassociation attack automation
  • 802.1X/EAP downgrade & MSCHAPv2 capture
  • Rogue AP detection & client targeting
  • GUI + CLI · wireless survey + attack report
⬡ BETA
👑

PrivEsc Pentester Sidekick

PPS · Debian/Kali · x86-64

Privilege escalation automation for Windows and Linux. Discovers and chains misconfigurations, exploitable services, weak file permissions, token abuse and kernel vulnerabilities — then walks you through the exploit path.

  • Windows: token impersonation, unquoted services, AlwaysInstallElevated
  • Linux: SUID/GUID abuse, sudo misconfig, writable paths
  • Scheduled task & cron job exploitation
  • Kernel exploit suggestion & auto-staging
  • LOLBIN chaining & living-off-the-land paths
  • GUI + CLI · privilege chain visualiser
● AVAILABLE NOW
📋

ComplianceAuditor Pentester Sidekick ★ v1

CAPS · v1.0.0 · Debian/Kali · x86-64

Automated compliance gap analysis across 11 frameworks in one engagement binary. NIST CSF, ISO 27001, PCI-DSS, GDPR, HIPAA, ISO 22301, ISO 31000, ISO 9001, ISO 45001, COBIT, TOGAF, and PMBOK. Evidence collection, control mapping and gap report generation. Framework-agnostic architecture extensible to any standard.

  • 11 frameworks: NIST CSF, ISO 27001, PCI-DSS, GDPR, HIPAA, ISO 22301, ISO 31000, ISO 9001, ISO 45001, COBIT, TOGAF, PMBOK
  • Automated control evidence collection
  • Gap identification & remediation priority scoring
  • Network & host configuration auditing
  • Auditor-ready evidence pack + executive summary
  • GUI + CLI · multi-framework delta comparison · extensible framework plugin system
⬡ BETA
📱

MFA Pentester Sidekick

MPS · Debian/Kali · x86-64

So your pentesting just checks for an MFA present… how professional! 90% of MFA is wanna-be stuff — test it properly, and the Sidekick helps you do just that.

  • Real-time OTP relay — transparent man-in-the-middle phishing proxy
  • Push notification fatigue & bombing automation
  • TOTP/HOTP secret extraction from authenticator backups
  • SMS OTP interception & SIM swap recon workflow
  • Account recovery bypass & fallback channel abuse
  • GUI + CLI · SSO token capture & session hijack
● AVAILABLE NOW
📈

CrunchMachine Pentester Sidekick

CMS · v1.0.0 · Debian/Kali · x86-64

Offensive data processing and analysis engine for pentesters. Ingest, parse, and extract intelligence from large datasets — logs, captures, configs, and stolen data. Automated correlation, deduplication, and intelligence enrichment all in one static binary.

  • Multi-format ingestion — logs, PCAP, JSON, CSV, raw files
  • Automated parsing — firewall, proxy, IDS, Windows Event Logs, Syslog
  • Dataset correlation — find cross-dataset patterns and links
  • Credential extraction — harvest usernames, passwords, tokens from all sources
  • Timeline reconstruction — events correlated to a single timeline
  • GUI + CLI · professional data processing report output
// infrastructure

Codecs, compute and chain — the plumbing everything else runs on.

■ INTERNAL R&D · CLASSIFIED
M.A.D.D.I.E.

M.A.D.D.I.E.

MDE · Distributed Inference Engine · internal

An in-house Adamantware research engine for distributed inference across commodity GPU fleets. What it does — and what it does it to — stays behind the curtain. All you need to know: everything MADDIE learns is poured straight back into making our own products provably harder to break. Strictly need-to-know.

  • Distributed inference across commodity GPU fleet
  • Multi-model orchestration and optimization
  • Objective — redacted · internal only
  • Subject — redacted · internal only
  • Outcome — hardens the next generation of our security & performance
  • Status — active internal research · not for release
● 1.0 · FINAL
🗜

M.I.K.E.

MKE · Mathematically Improved Kompression Engine · Linux / Win / Android

Some data isn’t compressed — it’s a puzzle. MIKE asks what rule generated your data and stores the formula instead of the bytes. On structured, scientific and sensor data it beats zip, rar, 7z, xz and zstd — sometimes thousands of times over — while staying provably lossless. A real middle-out moment, with receipts.

  • Collapses a 262 KB numeric file to 30 bytes — and 357 KB of real market timestamps to 38 bytes, 37× past rar
  • NEW — now wins on already-compressed data too: PNG, ZIP, gzip, PDF & Office 20–44% past xz -9, plus JPEG, MJPEG & MP3 — all lossless
  • NEW — crushes CSV / TSV tables 45–89% past xz -9 by transposing columns and re-reading the digits as numbers
  • Beats every mainstream tool on structured, scientific & sensor data
  • Provably lossless — CRC-verified against 5 industry tools
  • Fast by default, or --safe round-trip verification for full assurance
  • One Rust engine — Linux, Windows & Android, all shipped
⬡ BETA
🎬

L.I.V.

LIV · Lossy Implicit Vector · the lossy sibling to MIKE

Every lossy codec throws away detail to save space. LIV compresses harder — then puts a small neural model in the decoder that paints the discarded detail back. The model ships once and costs zero bytes in your files. Turn it on and the same picture, sound or video fits in less space. An archival codec built for security footage.

  • Video ~1.96× smaller at equal quality — roughly half the storage
  • Stills ~1.22×, audio ~1.33× — all measured on held-out data
  • The AI lives in the decoder — zero per-file overhead
  • Restore only the moving blocks — real-time on a plain CPU for fixed cameras
  • Opt-in AI mode · certified original kept for evidence
● AVAILABLE NOW
⚙️

ComputeEngine

CE · v0.2.0 · Proxmox 9.x · AMD / Intel / NVIDIA

vGPU, the good way. Share one physical GPU across every VM on your Proxmox cluster — consumer cards, any vendor, no per-GPU licence. A Proxmox driver plus a live web manager with real GPU/CPU telemetry. Now with a live demo you can watch.

  • One GPU shared across many VMs — no passthrough waste
  • Runs on the consumer cards you already own
  • Any vendor — AMD, Intel or NVIDIA
  • No per-GPU / per-user licence, ever
  • Live manager: real GPU/CPU telemetry, per model, per node
● AVAILABLE NOW
🌐

TIPTOP

TPT · v0.2.0 · Linux performance tuning · x86-64

Evidence-driven Linux tuner. Profiles hardware and live load, derives kernel settings from measurements, journals every change, and can revert you exactly to where you started. Every knob has a reason; every reason cites the measurement that proves it.

  • Profiles hardware and workload: scans CPU, memory, I/O, governors, frequency scaling, C-states
  • Evidence-driven tuning: changes only what measurements justify; all reasons cited
  • Journalled + revertible: full rollback to original state; watchdog auto-reverts on crash
  • Binary search debugging: `tpt bisect` finds which change caused a regression
  • A/B verification: toggle a setting under live load and measure both arms
  • Fleet survey: scan multiple boxes and report disagreements; standardise your estate
● AVAILABLE NOW
🔑

CypherTalk

CYP · Enterprise secure chat · Android · File transfer

Enterprise-grade secure communication built on Bumblebee’s serverless architecture but hardened for business. End-to-end encrypted messaging, secure file transfer for teams, and zero-trust authentication. Kotlin + Firebase backend with military-grade encryption and compliance audit trails.

  • E2E encryption: messages and files encrypted client-side; server never sees plaintext
  • Secure file transfer: large files, batch transfers, retention policies
  • Team collaboration: group chats, channels, role-based access control
  • Compliance audit: full message/file audit trail, GDPR-ready retention
  • Zero-trust auth: device binding, session pinning, anomaly detection
  • Serverless infrastructure: Firebase backend, auto-scaling, no ops overhead
// blockchain

Distributed ledgers with privacy and proof built in.

● LIVE TESTNET

FlexChain

FLX · Private-by-design post-quantum ledger · enterprise

Prove everything. Reveal nothing. A distributed ledger where your records are sealed to your own circle, provably replicated, and safe against tomorrow’s quantum computers — while outsiders can still verify the truth without ever seeing your data. Every other ledger forces a trade between trust and privacy. FlexChain refuses it. Watch our private testnet finalize in real time.

  • Sealed per community — outsiders see proof, never contents
  • Prove a fact without revealing the data behind it (zero-knowledge)
  • Post-quantum from the very first block
  • Two organizations, one ledger, total blindness between them
  • Upgrade the cryptography without ever forking
  • Data lives in ≥3 places — and proves it, constantly
// artificial intelligence

Sovereign, self-hosted intelligence — from cognitive hives to threat hunters to skill auditors. (See also: SkillHawk in Cybersecurity for AI-focused security auditing)

● PUBLIC BETA
A.N.A.

A.N.A.

ANA · Always Negotiating Appetite · Android

Not a security tool. Still a hack — the target is just a four-year-old’s attention span. On-device AI works out whether a child is genuinely chewing (not talking, not yawning, not staring through the screen) and pauses their video the moment they stop, then resumes on the next real bite. No video, no photo, nothing uploaded, nothing kept.

  • Real-time chew detection — computer vision, 30×/sec
  • Pauses the video when the chewing stops
  • Parent sets the delay · PIN-locked settings
  • Curated video list — the child never searches
  • Fully on-device — no account, no server, no tracking
  • Free · Android 8.0+
● AVAILABLE NOW

Newton

NWT · Sovereign self-learning AI · self-hosted

The first AI you raise instead of rent. Newton is a sovereign, self-hosted mind that never freezes — it teaches itself around the clock, across every field of human knowledge, and keeps its own memory, judgment and values. Not a chatbot bolted onto someone else’s cloud — a mind that learns while you sleep and answers in its own voice. Nothing else has ever worked like it.

  • Auto-learning — studies on its own, continuously; never frozen at a cutoff
  • Auto-refreshing — its knowledge stays current, self-updated
  • Sovereign & self-hosted — runs on your hardware; your data never leaves
  • A mind of its own — reasons, remembers, and speaks aloud
  • Values built in — a permanent constitution it can’t be stripped of
  • Unlike any AI ever built — by architecture, not by tuning
● AVAILABLE NOW

CodingSidekick ★ v2

CSK · v2.1.0 · Newton-native, model-agnostic · Linux / macOS

The sovereign coding workbench — runs natively on Newton or multi-model across Claude, GPT, and local LLMs. Multi-agent orchestration, MCP tool mesh, persistent memory across sessions, and an automated security review pipeline that catches what static analysis misses. 300+ integrated tools. Never chained to a single brain or vendor.

  • Newton-native or model-agnostic: pick your brain — Newton, Claude, GPT-4o, or local Qwen/Mistral
  • Multi-agent orchestration: spawn parallel agents, coordinate complex tasks, share persistent memory
  • MCP tool mesh: 300+ integrated tools (git, Docker, LSP, web, databases) routed by capability
  • Session memory + project context: cross-session recall, design decisions, implementation history
  • Automated security pipeline: SkillHawk MCP audit, SAST, dependency CVE, taint analysis
  • Code review + refactoring: simplification, efficiency, test coverage; apply fixes in-place
▲ RELEASE CANDIDATE
📢

HackMarketing

HKM · v0.1.0-rc.1 · Rust · Self-hosted · AI-operated

Marketing was never an art — it's an undocumented protocol, and we reverse-engineered it. Point HackMarketing at your product's own source of truth and an AI agent runs the entire go-to-market loop: positioning, copy, scheduling, cross-posting, and the algorithm games the "experts" gatekeep behind a diploma. Self-hosted — your keys, your data, your accounts. Fire the marketeer.

  • Reads your repo / product catalog as the brief — no incumbent does this
  • Hacks the algo — optimizes every post against each platform's real ranking signals
  • Generate → human-approve → post across channels (Bluesky live; more landing)
  • Encrypted vault for OAuth tokens + MFA seeds — nothing leaves your box
  • Local daemon + embedded manager; optional team web view
  • Tiers: Starter (prove the bluff) · Gold (run campaigns) · Platinum (full autonomous AI)
● AVAILABLE NOW
🌐

Demerzel

DEM · GPU parity engine · inference acceleration

Unified GPU-accelerated inference across AMD and NVIDIA. One model graph, native performance on both vendors — beats llama.cpp on prefill (138% AMD, 114% NVIDIA) and token generation (103% AMD). No vendor-specific optimisations, no handwritten kernels, one truth.

  • 138% of llama.cpp on AMD (prefill) + 103% (token generation)
  • 114% of llama.cpp on NVIDIA (prefill)
  • Single unified model graph — no per-vendor forks
  • AMD RDNA (RX 7000) and NVIDIA consumer/server cards
  • Streaming token output for real-time responses
  • Integrated into Newton and CodingSidekick
// other tools

Beyond pentesting — tools for the rest of the operator workflow.

// hacking hardware

Physical attack tools for the operator who needs to be there without being there.

● AVAILABLE NOW
📡

Tiny Deauther

TDA · Hardware · Battery-powered · WiFi + Mobile app

A thumb-sized, battery-powered WiFi deauthentication device designed to be hidden on-site. Connects over the local WiFi or companion app and deauths the target network until ordered to stop or the battery runs out.

  • Hidden placement — concealable, no power cable required
  • Continuous 802.11 deauth attack until stopped
  • WiFi control panel + iOS/Android companion app
  • Targeted (per-MAC) or broadcast deauth modes
  • Display Edition (OLED) or Stealth Edition — both -NA-
Order → -NA-
⬡ BETA
🖱

Bad Mouse

BMO · Hardware · USB · RF · Bluetooth

A fully functional USB mouse with a hidden HID attack brain inside. Deploy keystroke scripts, exfiltrate data and run command sequences remotely via web panel or mobile app — it just looks like a mouse.

  • Wired USB · Wireless RF · Bluetooth variants
  • Remote control via web panel or mobile app
  • HID script injection at hardware speed
  • Data extraction — files, credentials, config
○ IN DEVELOPMENT

Bad Keyboard

BKB · Hardware · USB HID attack platform

Same principle as Bad Mouse — in a keyboard. Type normally, trigger attacks remotely. HID-speed script injection and data exfiltration, controlled from a web panel or mobile app.

  • Fully functional keyboard — undetectable to OS
  • Remote trigger via web panel or mobile app
  • Script library: PowerShell droppers, reverse shells, harvesters
  • Data exfiltration over embedded wireless link
○ IN DEVELOPMENT
📶

Bad WiFi

BWF · Hardware · Rogue WiFi implant

A rogue WiFi implant that hides inside the target network. Plant it during physical access — remote foothold from outside the perimeter, pivot tunnel into internal network, no return visit required.

  • Hides on LAN — no obvious indicators
  • Wireless foothold accessible from outside the perimeter
  • Internal network pivot tunnel
  • PoE or USB powered
⬡ BETA
🏴

WiFi Frontgun

WFG · Hardware · Remote WiFi attack unit

Directional, remote-managed WiFi attack unit. Point it at the target from the street, fingerprint the victim network, inject a tailored evil twin from afar — never entering the premises.

  • Passive WiFi fingerprint — SSID, security type, client count
  • Remote evil twin injection with captive portal credential capture
  • Directional high-gain antenna for range
  • Web panel + mobile app control
⬡ BETA
🐊

Flipper Key Injector

FKI · Hardware + Software · Flipper Zero platform

Wireless keyboard injection for the Flipper Zero. Firmware + companion module extend the Flipper’s BadUSB capability with remote wireless triggering — inject payloads from across the room, controlled by mobile app or web panel.

  • Wireless payload trigger — no sitting at the target keyboard
  • DuckyScript-compatible — your scripts work immediately
  • Professional payload library, kept current
  • Licensed + watermarked per operator
○ IN DEVELOPMENT
🐊

Flipper Firmware Pack

FFW · Custom firmware · Red team tools · Flipper Zero

Hardened Flipper Zero firmware build with integrated NHH sidekick tools, expanded RF protocol library, advanced badgemath malware samples, and stealth-optimised logging. Drop-in replacement for stock firmware; no bootloader modification needed. Includes the full Bad Mouse / Bad Keyboard payload library.

  • Integrated NHH Sidekick protocols — EPS, HawkEye, MailHawk signatures
  • Expanded RF coverage — automotive rolling codes, sub-GHz, BLE, NFC
  • Stealth logging — operational security, no device-side artifacts
  • Bad Mouse / Bad Keyboard firmware + payload stager
  • One-click firmware flash via USB or wireless link
  • Custom branding — operator watermark, exfil watermark

The Manifesto

We don't put a hat on it. The white hat defends, the black hat attacks, the grey hat does both with a lawyer on speed dial. We do whatever the engagement calls for — because the goal is to find the hole before someone else does.

Our tools are built for operators who are doing real work on real engagements. Not for marketing decks. Not for compliance checkbox exercises. For the people who actually test things.

The stack is Rust. The platform is Debian/Kali. The binary is static. If it doesn't run on a fresh Kali install with zero setup, it doesn't ship.

macOS is for victims with excessive money.
Windows is for victims with defective reasoning.
We build for operators.

These tools are designed by a juvenile hacker — now a security consultant working the industry for over 34 years. Each and every one of them was designed for pentesting and security auditing purposes, and has drawn blood in the field. As CVEs get patched and progress moves on, we will always do our best to keep the tools current. We use them ourselves.

If we ever EOS a tool, we immediately cancel all active subscription renewals and convert every existing licence to God Mode — an unrestricted, perpetual licence with no further charges. You keep the tool. You keep using it. Updates stop, but the binary doesn't. We are not in the business of pulling the rug.

Start with EPS → Customer Portal
// pricing

Plans & Pricing

Monthly and annual plans for solo operators and small teams.
Hardware priced separately.

-NA-
Licensing paused. Due to a general lack of engagement, this project has gone private. Already-issued licenses will continue to work, but no new licenses will be issued to the general public at this point in time.
View Pricing →