Offensive tooling

Built to go deeper,
expose weaknesses,
break through the layers.

Our published tooling is free software under GPL‑3.0, developed in the open and used in our own engagements. The rest stays closed, and is released only to government and law enforcement agencies under vetting.

01 / Restricted

Restricted Tooling

Not published. Not for sale.

Some of what we build is never released publicly. We do not list these tools, document their capabilities, or describe what they do outside a vetted process.

Access is limited to government and law enforcement agencies, and is subject to vetting, jurisdiction and a written agreement covering lawful use. Enquiries that pass that bar are answered directly. Everything else is declined.

Not public Closed source Vetted access
No public listing
  • Eligibility — government agencies and law enforcement, within jurisdictions we are able to serve.
  • Vetting — identity, authority and intended use are verified before anything is discussed in detail.
  • Agreement — a written contract covering lawful use governs every release, without exception.

No public release. We do not provide trials, demos, pricing or technical detail outside that process, and we do not confirm what the portfolio contains. Requests from outside the eligible categories are declined.

02 / WordPress

HackWP

One bad plugin. Total compromise.

A WordPress exploitation framework for authorized penetration testing — built, in its own words, for people who get paid to break things on purpose. A scanner fingerprints the target’s WordPress stack, and a terminal cockpit lets you select, filter and chain modules against it.

Exploits chain from authentication through privilege escalation to payload delivery, carrying session and credential state between steps.

Open source Python 3.10+ GPL-3.0
A modular WordPress stack rendered in graphite, with a red signal path cutting through its plugin layer.
  • 334 exploit modules covering WordPress plugins, themes and core.
  • Stack fingerprinting scanner that identifies the components actually running on the target.
  • Interactive TUI cockpit with multi-select and live filtering across the full module set.
  • Eight payload types — webshell, reverse shell, bash, file read and more.
  • Exploit chaining from AUTH through PRIVESC to payload delivery, with session and credential state carried through.
  • XSS‑to‑RCE and AUTH‑to‑RCE adapters for demonstrating real impact rather than theoretical findings.

Rules of engagement. HackWP is for authorized testing only — systems you own, or systems you have explicit written permission to test within a defined scope.

03 / Vulnerability research

PatchDiffer

Find the fix. Find the bug.

A release went out and something quietly got patched. PatchDiffer takes two versions of a codebase and isolates what actually changed — a noise-filtered unified patch, the changed files in both their original and patched state, and a local git repo holding both versions as commits for side-by-side review.

Feed it directories, .zip archives, or a wp:<slug> shorthand that pulls both versions straight from wordpress.org.

Open source Python GPL-3.0
Two slabs of code facing each other in the dark, one changed line lit red and traced across the gap.
  • Noise filtering by default — skips images, fonts, media, source maps and minified files, while keeping .css and .js because they carry logic.
  • Structured output — changes.patch, original/, patch/ and a repo/ holding both states as commits.
  • Optional AI triage ranks the changes most likely to be the security fix, each with a probable vulnerability class and a PoC direction.
  • Extension filtering with --only and --ignore-ext, plus full-copy export for grepping or mounting into Docker.
  • Opens straight in VS Code for colour-coded, side-by-side comparison.
# diff two wordpress.org releases
$ pdiff wp:some-plugin 2.4.1 2.4.2

# rank the changes most likely to be the fix
$ pdiff wp:some-plugin 2.4.1 2.4.2 --ai

diff/
├── changes.patch
├── original/
├── patch/
├── repo/          git, both states
└── ai-report.md   with --ai
04 / Password cracking

Aswap

For when swapping characters is a must.

A multi-threaded candidate generator for rule-based password cracking, built around one gap: hashcat and John cannot express partial, combinatorial character substitutions without a rule explosion. l0v3 is simply unreachable from love with the equivalent ruleset.

Aswap reads a wordlist from stdin and emits every combination of the requested swaps up to a given depth, streaming candidates as they are produced so a GPU cracker can consume them while the CPU keeps generating.

Open source C++ GPL-3.0
A row of combination dials in the dark, a red beam locking one character on each wheel into place.
  • Three-character rule syntax — <depth 1-9><find><replace>, so 2e3 branches on the first two es. Invalid depths are rejected, not silently reinterpreted.
  • All combinations, including partial swaps — the gap it exists to close.
  • Every CPU core, with flat memory use regardless of run length: never more than one word’s candidates in flight.
  • 234k words → 11.3M candidates in 0.07s at 8 MB peak RSS.
  • A Python reference implementation defines the semantics, and an equivalence test asserts the C++ build matches it candidate for candidate.
# pipe straight into your cracker
$ cat rockyou.txt | aswap 2o0 2a@ 2e3 \
    | hashcat -a 0 -m 0 hashes.txt

# every partial swap, not just the full one
$ echo "kitties" | aswap 2i! 2e3
kitties  kittie3  kitt!es  kitt!e3
k!tties  k!ttie3  k!tt!es  k!tt!e3
Put it to work

The tools are only
half of it.

We use this tooling in our own red team engagements, against real environments, toward objectives you set.