01
Hacker Almanac
A field reference across nine hacker disciplines, hardware, RF spectrum, telephony, networking, physical security, forensics, cryptography, subculture, and tradecraft, with working bench tools built in: a hex inspector, CIDR calculator, DTMF and hash workbenches, an Enigma simulator, and a one-time-pad generator. Field Instrument 041.
Open → · Source
02
Registrar
A provenance certificate generator that signs documents with ECDSA so their authenticity can be independently verified against a public key.
Open → · Source
03
Bitwright
A DuckyScript workbench: write, lint, and narrate payloads, then compile to a classic inject.bin, a Flipper BadUSB script, or plain DuckyScript, and read an existing inject.bin back to source. For authorized testing and security education.
Open → · Source
04
Casebook
A sealed casefile for security engagements: capture scope, rules of engagement, and a timestamped findings log, then sign the whole record with ECDSA so it cannot be altered after sealing.
Open → · Source
05
Bulwark
A self-contained field kit for network forensics and vulnerability triage: MAC parsing and OUI lookup, CVSS 3.1 and 4.0 scoring with shareable vectors, and encode, decode, and hash tools.
Open → · Source
06
Rampart
A modular field kit for authorized physical security assessments. Eleven instruments share one chassis, from lock and credential references to walking surveys and RF exposure rating to a client report compiler, all weighted toward documentation and remediation.
Open → · Source
07
Picket
A wireless security audit watch console for the browser. Picket stands watch over the WiFi and BLE emissions of a place and calls out what an audit cares about: open and weak networks, evil-twin candidates, hidden SSIDs, and trackable or self-identifying Bluetooth devices.
Open → · Source
08
Observatory
A plain-language website security survey for small business owners. Enter your web address and Observatory explains, in words a non-technical owner understands, what an outsider can see, why each finding matters to the business, and who fixes it.
Open →
09
Dragnet
An offline packet capture reader. Drop a .pcap or .pcapng on the page and get conversations, a protocol breakdown, a timing ladder, and a plain-language account of what the traffic was doing. Nothing is uploaded, nothing is installed, one HTML file. Dragnet is the wired counterpart to Picket: Picket watches the air live and renders verdicts on what it hears, Dragnet reads a file after the fact and reconstructs the story.
Open →
10
Relay
A local-first API and webhook testing instrument. Build requests, inspect responses, receive webhook events, replay traffic, validate behavior, and produce test evidence. Built to feel like an engineering test bench rather than a generic developer console.
Open →
11
Signaltrace
A local-first industrial-network inspection and documentation instrument for Modbus, BACnet, and LonWorks evidence. An authorized user can capture or import traffic, decode protocol records, reconstruct conversations, map observed relationships, compare a current condition against baselines and design documentation, preserve investigation evidence, and assemble repeatable commissioning or troubleshooting reports.
Open →
12
Touchstone
A benchtop embedded and IoT security assessment conductor. One researcher, one connected device, authorization through coordinated disclosure. Touchstone is the test plan you work through, the bench it tells you to set up, the lab notebook you keep while working, the findings it collects, and the disclosure package it hands the vendor.
Open →
13
Roundsman
Roundsman records an assessment. It performs nothing, it certifies nothing, and it carries no payloads, no exploits, and no wordlists. Every verdict in it is a human observation that you typed in. It exists because the dentist, the machine shop, and the water district all have the same problem: the person who can pick the back door and the person who can read the firewall rules are two different people, and nobody writes down the hallway between them.
Open →
Nothing matches that. Try a shorter word.