// Offensive Security Tooling

NO HAT
HACKER

White hat. Black hat. Grey hat.
We don't wear one.

Professional-grade tools built for red teams and penetration testers who are tired of being put in a box. Authorised use only — no apologies.

nohathacker — bash
nhh@ops:~$

The Tools

Built on Debian. Tested on Kali. Deployed on jump boxes.
macOS is for victims with excessive money. Windows is for victims with defective reasoning. We build for operators.

// the sidekick series

One static binary per engagement type. Drop it on the jump box and go.

● AVAILABLE NOW

Email Pentest Sidekick

EPS · v1.0.0 · Debian/Kali · x86-64

The most complete email security assessment framework in existence. DMARC-pass attack automation, dark web credential hunting, SPF chain analysis, SMTP spray and forensic header analysis — one static binary, zero dependencies.

  • DMARC-pass spoofing via stolen M365/Gmail credentials
  • Tor-routed dark web & HIBP credential search
  • SMTP AUTH spray — Ignis 1M wordlists bundled
  • SPF walk · domain permutations · open relay hunter
  • Professional HTML/PDF pentest report
  • GUI + CLI · 3FA login · 30-min session auth
▲ RELEASE CANDIDATE

CodingSidekick

CSK · Claude Code, Extended · Linux · macOS

Imagine Claude Code hit the gym — then decided to take every PED known to science all at once, somehow didn’t die, and through sheer dark magic fused with 300+ tools. Multi-agent orchestration, persistent cross-session memory, automated security review, and an MCP tool library that makes the stock version look like Notepad.

  • Multi-agent task orchestration — delegate and parallelise
  • Persistent cross-session memory & project context
  • 300+ integrated MCP tools out of the box
  • Automated security review & vulnerability pipeline
  • Extended code analysis, refactoring and audit agents
  • GUI + CLI · runs on top of Claude Code
▲ RELEASE CANDIDATE

NHH Crack Server

NCS · Bootable ISO · NVIDIA CUDA 12 + AMD ROCm 6

Plug in a USB pen drive, boot, and your machine becomes a dedicated cracking node in under two minutes. Tor hidden service + WireGuard mesh auto-configure on first boot — no keyboard, no screen needed after that. 80% CPU/GPU goes to hashcat; the rest keeps Tor and WireGuard alive.

  • Zero-config ISO — boot from pen drive, cracking server starts automatically
  • NVIDIA CUDA 12 + AMD ROCm 6 GPU drivers pre-installed
  • Tor hidden service + WireGuard mesh — no open ports, invisible to internet
  • hashcat, John the Ripper, Hydra, Medusa, Aircrack-ng, wfuzz bundled
  • cgroups v2 resource slices — 80% CPU/GPU dedicated to cracking
  • Integrates with all NHH Sidekick GUI tools via WireGuard API
● AVAILABLE NOW
👁

HawkEye

HEY · Debian/Kali · x86-64 · Live NVD + MITRE

Vulnerability intelligence platform: scan to report in one native GUI. Nmap NSE + HawkEye internal scanner enriched with live NVD CVE data, MITRE ATT&CK mapping, 9,000+ nuclei template engine natively executed, Metasploit module suggestions and attack scenario builder.

  • Dual scanner — Nmap NSE + HawkEye internal (zero external deps)
  • 9,000+ Nuclei-compatible MIT templates executed natively
  • Live NVD API v2 CVE enrichment — CVSS, CPE, references
  • MITRE ATT&CK auto-mapping across all 14 tactics
  • Metasploit module suggestions + attack scenario builder
  • Phase 4 professional HTML report with donut chart + ATT&CK table
⬡ BETA
🔬

DFIR Pentester Sidekick

DPS · Debian/Kali · x86-64

Digital forensics and incident response — three analysis engines in one binary. Windows event log triage, memory forensics, and PCAP/network forensics. From raw evidence to IOC list and incident timeline in minutes.

  • EVTX triage — attack timeline + MITRE ATT&CK mapping
  • Lateral movement chain reconstruction
  • Memory forensics via Volatility 3 wrapper
  • PCAP analysis — C2 detection + credential extraction
  • IOC hunting with OSINT enrichment
  • GUI + CLI · professional IR report output
🔗 github/DFIR_Pentester_Sidekick
⬡ BETA
🔑

CredDump Pentester Sidekick

CDS · Debian/Kali · x86-64

Windows credential extraction without the guesswork. Detects privilege paths, AV/EDR state, and LSASS protections — then selects the optimal extraction technique automatically.

  • Auto-detects privilege level, PPL, Credential Guard, EDR
  • LSASS — multiple extraction paths ranked by stealth
  • NTDS.dit via VSS shadow copy or remote DC dump
  • LAPS v1/v2 password extraction
  • SAM, LSA secrets, DPAPI master keys
  • GUI + CLI · auto-routes hashes to crackers
🔗 github/CredDump_Pentester_Sidekick
⬡ BETA
🌐

InfraScan Pentester Sidekick

IPS · Debian/Kali · x86-64

Network infrastructure pentesting — fingerprint, compromise, pivot, hop VLANs. Auto-fingerprints vendor and firmware, tests default credentials and known CVEs, enumerates VLANs and attempts 802.1Q double-tag hopping.

  • Vendor auto-fingerprint — Cisco, Juniper, Fortinet, Palo Alto +more
  • Default credential spray per device type
  • Known CVE probing — RCE, auth bypass, info-disclosure
  • VLAN enumeration + 802.1Q double-tag hopping
  • Network crawl — routing table, ARP, MAC, neighbors
  • GUI + CLI · network topology map output
🔗 github/InfraScan_Pentester_Sidekick
⬡ BETA
🏰

AD Pentester Sidekick

APS · Debian/Kali · x86-64

Active Directory attack chain automation — from zero access to domain compromise. Automates the full AD kill chain so you spend engagement time on findings, not stringing together eight different Python scripts.

  • Kerbrute user enum — no lockout risk
  • Kerberoasting + AS-REP roasting — hash extraction
  • BloodHound-compatible attack path analysis
  • Pass-the-Hash/Ticket · Over-Pass-the-Hash
  • ACL/DACL abuse · shadow credentials
  • DCSync → domain compromise · GUI + CLI
🔗 github/AD_Pentester_Sidekick
⬡ BETA
🌐

WebVuln Pentester Sidekick

WPS · Debian/Kali · x86-64

Full-spectrum web application security assessment. Automated discovery and exploitation of injection, logic, and authentication flaws — from recon to proof-of-concept in one binary.

  • SQL injection — blind, error-based, time-based
  • XSS, SSTI, SSRF, XXE, IDOR automated chains
  • JWT attack suite — alg:none, key confusion, brute
  • Auth bypass — OAuth abuse, SAML confusion
  • Intercepting proxy with automated attack playbooks
  • GUI + CLI · PoC + evidence report output
🔗 github/WebVuln_Pentester_Sidekick
⬡ BETA

Cloud Pentester Sidekick

CPS · Debian/Kali · x86-64

AWS, Azure and GCP pentesting in one binary. IAM enumeration, privilege escalation paths, exposed storage discovery, serverless attacks and container escapes — cross-cloud credential harvesting built in.

  • IAM enumeration & privilege escalation paths
  • S3/Blob/GCS exposure scanner
  • Serverless function abuse & event injection
  • Container escape — ECS, EKS, AKS, GKE
  • Cross-cloud credential harvesting & lateral movement
  • GUI + CLI · cloud attack graph output
🔗 github/Cloud_Pentester_Sidekick
⬡ BETA
🔐

TunnelKit Pentester Sidekick

TPS · Debian/Kali · x86-64

VPN and tunnel security assessment. Tests WireGuard, OpenVPN, IPSec and SSH tunnels for misconfigurations, credential exposure, split-tunnel bypass and traffic interception vectors.

  • WireGuard & OpenVPN misconfiguration detection
  • Split-tunnel bypass & traffic leakage testing
  • IPSec weak cipher & PSK brute forcing
  • SSH tunnel pivoting & credential extraction
  • VPN credential spray per known providers
  • GUI + CLI · tunnel map + finding report
🔗 github/TunnelKit_Pentester_Sidekick
⬡ BETA
📡

WiFi Pentester Sidekick

WFP · Debian/Kali · x86-64

Wireless security assessment from scanning to exploitation. WPA2/WPA3 handshake capture, PMKID attacks, evil twin automation and enterprise 802.1X/EAP downgrade attacks — from a single adapter.

  • WPA2/WPA3 handshake capture & PMKID attack
  • Evil twin with captive portal credential capture
  • Deauth & disassociation attack automation
  • 802.1X/EAP downgrade & MSCHAPv2 capture
  • Rogue AP detection & client targeting
  • GUI + CLI · wireless survey + attack report
🔗 github/WiFi_Pentester_Sidekick
⬡ BETA
👑

PrivEsc Pentester Sidekick

PPS · Debian/Kali · x86-64

Privilege escalation automation for Windows and Linux. Discovers and chains misconfigurations, exploitable services, weak file permissions, token abuse and kernel vulnerabilities — then walks you through the exploit path.

  • Windows: token impersonation, unquoted services, AlwaysInstallElevated
  • Linux: SUID/GUID abuse, sudo misconfig, writable paths
  • Scheduled task & cron job exploitation
  • Kernel exploit suggestion & auto-staging
  • LOLBIN chaining & living-off-the-land paths
  • GUI + CLI · privilege chain visualiser
🔗 github/PrivEsc_Pentester_Sidekick
⬡ BETA
📋

ComplianceAuditor Pentester Sidekick

CAPS · Debian/Kali · x86-64

Automated compliance gap analysis across PCI-DSS, ISO 27001, SOC 2 and GDPR. Evidence collection, control mapping and gap report generation — in one engagement binary.

  • PCI-DSS, ISO 27001, SOC 2, GDPR frameworks
  • Automated control evidence collection
  • Gap identification & remediation priority scoring
  • Network & host configuration auditing
  • Auditor-ready evidence pack + executive summary
  • GUI + CLI · multi-framework delta comparison
🔗 github/ComplianceAuditor_Pentester_Sidekick
⬡ BETA
📱

MFA Pentester Sidekick

MPS · Debian/Kali · x86-64

So your pentesting just checks for an MFA present… how professional! 90% of MFA is wanna-be stuff — test it properly, and the Sidekick helps you do just that.

  • Real-time OTP relay — transparent man-in-the-middle phishing proxy
  • Push notification fatigue & bombing automation
  • TOTP/HOTP secret extraction from authenticator backups
  • SMS OTP interception & SIM swap recon workflow
  • Account recovery bypass & fallback channel abuse
  • GUI + CLI · SSO token capture & session hijack
🔗 github/mfa_pentester_sidekick
⬡ BETA
🖐

InvisiRAT for Pentesters

IRAT · Debian/Kali · x86-64

Two-stage stealthy remote access for red team engagements. Rust dropper embedded in PDF, JPEG or ZIP carriers writes an XOR-obfuscated Python agent on execution. Supports Metasploit Meterpreter. Every binary forensically watermarked to its operator license.

  • PDF, JPEG, ZIP polyglot carrier embedding
  • XOR-encrypted Python agent — per-build randomised bytecode
  • Meterpreter payload via msfvenom integration
  • Forensic watermark — every binary traceable to operator
  • VirusTotal & no-distribute scanner guidance built-in
  • OSINT: Censys/Shodan C2 infrastructure discovery
// other tools

Beyond pentesting — tools for the rest of the operator workflow.

⬡ BETA
🚗

FlipperCarCommander

FCC · Flipper Zero companion

Automotive security research companion for Flipper Zero. Rolling code capture and replay, key fob cloning, garage protocol decoding and CAN bus injection.

  • Rolling code analysis & replay attack
  • RF key fob capture and cloning
  • CAN bus frame injection
⬡ BETA

AngieManager

AM · Angie web server GUI

Visual management layer for the Angie web server. Config editor, certificate lifecycle, upstream pool builder and live traffic analytics — no YAML wrestling.

  • Visual Angie config editor
  • TLS certificate lifecycle
  • Load balancer & upstream pool builder
// hacking hardware

Physical attack tools for the operator who needs to be there without being there.

● AVAILABLE NOW
📡

Tiny Deauther

TDA · Hardware · Battery-powered · WiFi + Mobile app

A thumb-sized, battery-powered WiFi deauthentication device designed to be hidden on-site. Connects over the local WiFi or companion app and deauths the target network until ordered to stop or the battery runs out.

  • Hidden placement — concealable, no power cable required
  • Continuous 802.11 deauth attack until stopped
  • WiFi control panel + iOS/Android companion app
  • Targeted (per-MAC) or broadcast deauth modes
  • Display Edition (OLED) or Stealth Edition — both €99 + shipping
Order → €99 + shipping
⬡ BETA
🖱

Bad Mouse

BMO · Hardware · USB · RF · Bluetooth

A fully functional USB mouse with a hidden HID attack brain inside. Deploy keystroke scripts, exfiltrate data and run command sequences remotely via web panel or mobile app — it just looks like a mouse.

  • Wired USB · Wireless RF · Bluetooth variants
  • Remote control via web panel or mobile app
  • HID script injection at hardware speed
  • Data extraction — files, credentials, config
○ IN DEVELOPMENT

Bad Keyboard

BKB · Hardware · USB HID attack platform

Same principle as Bad Mouse — in a keyboard. Type normally, trigger attacks remotely. HID-speed script injection and data exfiltration, controlled from a web panel or mobile app.

  • Fully functional keyboard — undetectable to OS
  • Remote trigger via web panel or mobile app
  • Script library: PowerShell droppers, reverse shells, harvesters
  • Data exfiltration over embedded wireless link
○ IN DEVELOPMENT
📶

Bad WiFi

BWF · Hardware · Rogue WiFi implant

A rogue WiFi implant that hides inside the target network. Plant it during physical access — remote foothold from outside the perimeter, pivot tunnel into internal network, no return visit required.

  • Hides on LAN — no obvious indicators
  • Wireless foothold accessible from outside the perimeter
  • Internal network pivot tunnel
  • PoE or USB powered
⬡ BETA
🏴

WiFi Frontgun

WFG · Hardware · Remote WiFi attack unit

Directional, remote-managed WiFi attack unit. Point it at the target from the street, fingerprint the victim network, inject a tailored evil twin from afar — never entering the premises.

  • Passive WiFi fingerprint — SSID, security type, client count
  • Remote evil twin injection with captive portal credential capture
  • Directional high-gain antenna for range
  • Web panel + mobile app control
⬡ BETA
🐊

Flipper Key Injector

FKI · Hardware + Software · Flipper Zero platform

Wireless keyboard injection for the Flipper Zero. Firmware + companion module extend the Flipper’s BadUSB capability with remote wireless triggering — inject payloads from across the room, controlled by mobile app or web panel.

  • Wireless payload trigger — no sitting at the target keyboard
  • DuckyScript-compatible — your scripts work immediately
  • Professional payload library, kept current
  • Licensed + watermarked per operator

The Manifesto

We don't put a hat on it. The white hat defends, the black hat attacks, the grey hat does both with a lawyer on speed dial. We do whatever the engagement calls for — because the goal is to find the hole before someone else does.

Our tools are built for operators who are doing real work on real engagements. Not for marketing decks. Not for compliance checkbox exercises. For the people who actually test things.

The stack is Rust. The platform is Debian/Kali. The binary is static. If it doesn't run on a fresh Kali install with zero setup, it doesn't ship.

macOS is for victims with excessive money.
Windows is for victims with defective reasoning.
We build for operators.

These tools are designed by a juvenile hacker — now a security consultant working the industry for over 34 years. Each and every one of them was designed for pentesting and security auditing purposes, and has drawn blood in the field. As CVEs get patched and progress moves on, we will always do our best to keep the tools current. We use them ourselves.

If we ever EOS a tool, we immediately cancel all active subscription renewals and convert every existing licence to God Mode — an unrestricted, perpetual licence with no further charges. You keep the tool. You keep using it. Updates stop, but the binary doesn't. We are not in the business of pulling the rug.

Start with EPS → Customer Portal
// pricing

Plans & Pricing

Monthly and annual plans for solo operators and small teams.
Hardware priced separately.

View Pricing →