|
Riptide Collaborative browser terminal & playbook workspace for red teams |
Aquifer Linux post-exploitation framework with kernel namespace isolation |
|
Siphon Lightweight C2 — ECDH P-256 forward secrecy, AES-256-GCM, uTLS fingerprinting |
Rapids Modular credential spraying — 28 protocol modules with pass-the-hash |
| Tool | What It Does | Language |
|---|---|---|
| Aquifer | Linux post-exploitation framework with kernel namespace isolation and polymorphic beacons | |
| Siphon | Lightweight C2 framework — ECDH P-256 forward secrecy, AES-256-GCM, uTLS fingerprinting | |
| Spillway | Reverse/bind FUSE filesystem mount over TLS 1.3 | |
| Undertow | Statically-linked SSH server — reverse shells, SFTP, port forwarding |
| Tool | What It Does | Language |
|---|---|---|
| Riptide | Collaborative browser terminal & playbook workspace for red teams | |
| Runoff | Extract AD attack paths & quick wins from BloodHound CE | |
| Maelstrom | NetExec wrapper — 35+ AD enumeration modules in a single command | |
| Rapids | Modular credential spraying — 28 protocol modules with pass-the-hash | |
| Seep | Windows privilege escalation enumeration — 16 checks, 97 tools, MITRE ATT&CK mapping | |
| Whirlpool | Privilege escalation reasoning engine — parses LinPEAS/WinPEAS output |
| Tool | What It Does | Language |
|---|---|---|
| Deluge | Nmap & RustScan output parser with color-coded reports and multi-format export | |
| Surge | Offline-first command reference with fuzzy search & variable substitution | |
| Fathom | Lightning-fast offline man pages browser with TLDR summaries |
| Tool | What It Does | Language |
|---|---|---|
| LigoloSupport | One-command ligolo-ng tunnel setup | |
| Frontmatter-Variables | VS Code extension for markdown variable substitution |
All tools are built for authorized security testing and educational purposes.