Offensive security

Offensive
by design.

tstck builds advanced offensive tooling for red teams, pentesters and security researchers — and runs the engagements that put it to work. Built to go deeper, expose weaknesses, and break through the layers.

  • Offensive tooling
  • Red team engagements
  • Open source & restricted release
What we do

Two disciplines,
one way of thinking.

The tools we build come out of the engagements we run, and the engagements go further because of the tools. Each one sharpens the other.

01 / Tooling

Offensive tooling

Scanners, exploitation frameworks, patch-diffing and cracking utilities. Some of it is open source and published under GPL‑3.0. Other work is closed source, available exclusively to governments and law enforcement agencies.

See the tools
02 / Engagements

Red teaming

From first foothold to final objective. We run engagements built around how capable adversaries think, move, and pursue their objectives — combining deep technical analysis with our own offensive tooling.

How we operate
The arsenal

Tools built to go deeper.

Three published tools, each aimed at a layer most scanners stop short of — the plugin, the patch, the password. Plus the work we do not publish.

No public listing

Restricted Tooling

Not public

Not published. Not for sale. Some of what we build is never released publicly. Access is limited to government and law enforcement agencies, subject to vetting, jurisdiction and a written agreement.

Closed source Government & law enforcement Vetted access
Access & eligibility
A modular WordPress stack rendered in graphite, with a red signal path cutting through its plugin layer.

HackWP

Open source

One bad plugin. Total compromise. A WordPress exploitation framework for authorized testing — 334 exploit modules, a stack-fingerprinting scanner and a terminal cockpit for chaining them from auth to payload.

Python GPL-3.0 334 modules
Details
Two slabs of code facing each other in the dark, one changed line lit red and traced across the gap.

PatchDiffer

Open source

Find the fix. Find the bug. Patch diffing for vulnerability research: feed it two releases and it isolates what actually changed, filters out the noise and hands you a reviewable repo of both states.

Python GPL-3.0 CLI
Details
A row of combination dials in the dark, a red beam locking one character on each wheel into place.

Aswap

Open source

When swapping characters is a must. A multi-threaded candidate generator for rule-based cracking, covering the partial character substitutions hashcat and John cannot express without a rule explosion.

C++ GPL-3.0 11.3M candidates / 0.07s
Details
Red teaming

From first foothold
to final objective.

We look at how weaknesses connect. An exposed service can become a foothold. A misplaced permission can unlock greater access. A trusted connection can open the next layer.

We follow those opportunities toward agreed objectives, challenging your organisation’s ability to detect, investigate and respond as the attack develops.

We find the way through. You gain the insight to close it.

An isometric landscape of graphite platforms and server blocks, a single red path routing between them toward a glowing objective.
334
Exploit modules in HackWP
GPL‑3.0
Our published tooling, built in the open
Scoped
Every engagement, authorised in writing
Get in touch

Find out how far
an attacker could get.

Tell us what matters most in your environment. We will come back with a scope, a realistic set of objectives and a plan for getting there.

Contact

Three ways in.

Engagements

Red team engagements, scoping questions and timelines. Tell us what you want tested and what success looks like.

contact@tstck.io

Tooling & issues

Bugs, feature requests and contributions for our published tools go through the repositories, where the work happens in the open.

github.com/etragardh