// Offensive Security Tooling

NO HAT
HACKER

White hat. Black hat. Grey hat.
We don't wear one.

Professional-grade tools built for red teams and penetration testers who are tired of being put in a box. Authorised use only — no apologies.

nohathacker — bash
nhh@ops:~$

The Tools

Built on Debian. Tested on Kali. Deployed on jump boxes.
macOS is for victims with excessive money. Windows is for victims with defective reasoning. We build for operators.

// the sidekick series

One static binary per engagement type. Drop it on the jump box and go.

● PUBLIC BETA
A.N.A.

A.N.A.

ANA · Always Negotiating Appetite · Android

Not a security tool. Still a hack — the target is just a four-year-old’s attention span. On-device AI works out whether a child is genuinely chewing (not talking, not yawning, not staring through the screen) and pauses their video the moment they stop, then resumes on the next real bite. No video, no photo, nothing uploaded, nothing kept.

  • Real-time chew detection — computer vision, 30×/sec
  • Pauses the video when the chewing stops
  • Parent sets the delay · PIN-locked settings
  • Curated video list — the child never searches
  • Fully on-device — no account, no server, no tracking
  • Free · Android 8.0+
■ INTERNAL R&D · CLASSIFIED
M.A.D.D.I.E.

M.A.D.D.I.E.

MDE · Multiplexed Advanced Deduction, Distributed Inference Engine · internal

An in-house Adamantware research engine. What it does — and what it does it to — stays behind the curtain. All you need to know: everything MADDIE learns is poured straight back into making our own products provably harder to break. This one isn’t for sale, and it isn’t for explaining. Strictly need-to-know.

  • Distributed inference across a commodity GPU fleet
  • Objective — redacted · internal only
  • Subject — redacted · internal only
  • Outcome — hardens the next generation of our security
  • Status — active internal research · not for release
● 1.0 · FINAL
🗜

M.I.K.E.

MKE · Mathematically Improved Kompression Engine · Linux / Win / Android

Some data isn’t compressed — it’s a puzzle. MIKE asks what rule generated your data and stores the formula instead of the bytes. On structured, scientific and sensor data it beats zip, rar, 7z, xz and zstd — sometimes thousands of times over — while staying provably lossless. A real middle-out moment, with receipts.

  • Collapses a 262 KB numeric file to 30 bytes — and 357 KB of real market timestamps to 38 bytes, 37× past rar
  • NEW — now wins on already-compressed data too: PNG, ZIP, gzip, PDF & Office 20–44% past xz -9, plus JPEG, MJPEG & MP3 — all lossless
  • NEW — crushes CSV / TSV tables 45–89% past xz -9 by transposing columns and re-reading the digits as numbers
  • Beats every mainstream tool on structured, scientific & sensor data
  • Provably lossless — CRC-verified against 5 industry tools
  • Fast by default, or --safe round-trip verification for full assurance
  • One Rust engine — Linux, Windows & Android, all shipped
⬡ BETA
🎬

L.I.V.

LIV · Lossy Implicit Vector · the lossy sibling to MIKE

Every lossy codec throws away detail to save space. LIV compresses harder — then puts a small neural model in the decoder that paints the discarded detail back. The model ships once and costs zero bytes in your files. Turn it on and the same picture, sound or video fits in less space. An archival codec built for security footage.

  • Video ~1.96× smaller at equal quality — roughly half the storage
  • Stills ~1.22×, audio ~1.33× — all measured on held-out data
  • The AI lives in the decoder — zero per-file overhead
  • Restore only the moving blocks — real-time on a plain CPU for fixed cameras
  • Opt-in AI mode · certified original kept for evidence
● LIVE TESTNET

FlexChain

FLX · Private-by-design post-quantum ledger · enterprise

Prove everything. Reveal nothing. A distributed ledger where your records are sealed to your own circle, provably replicated, and safe against tomorrow’s quantum computers — while outsiders can still verify the truth without ever seeing your data. Every other ledger forces a trade between trust and privacy. FlexChain refuses it. Watch our private testnet finalize in real time.

  • Sealed per community — outsiders see proof, never contents
  • Prove a fact without revealing the data behind it (zero-knowledge)
  • Post-quantum from the very first block
  • Two organizations, one ledger, total blindness between them
  • Upgrade the cryptography without ever forking
  • Data lives in ≥3 places — and proves it, constantly
● AVAILABLE NOW

Email Pentest Sidekick ★ v2

EPS · v3.1.0 · Debian/Kali · x86-64

The most complete email security assessment framework in existence. DMARC-pass attack automation, dark web credential hunting, SPF chain analysis, SMTP spray and forensic header analysis — one static binary, zero dependencies.

  • DMARC-pass spoofing via stolen M365/Gmail credentials
  • Tor-routed dark web & HIBP credential search
  • SMTP AUTH spray — Ignis 1M wordlists bundled
  • SPF walk · domain permutations · open relay hunter
  • Professional HTML/PDF pentest report
  • GUI + CLI · 3FA login · 30-min session auth
● AVAILABLE NOW

Newton

NWT · Sovereign self-learning AI · self-hosted

The first AI you raise instead of rent. Newton is a sovereign, self-hosted mind that never freezes — it teaches itself around the clock, across every field of human knowledge, and keeps its own memory, judgment and values. Not a chatbot bolted onto someone else’s cloud — a mind that learns while you sleep and answers in its own voice. Nothing else has ever worked like it.

  • Auto-learning — studies on its own, continuously; never frozen at a cutoff
  • Auto-refreshing — its knowledge stays current, self-updated
  • Sovereign & self-hosted — runs on your hardware; your data never leaves
  • A mind of its own — reasons, remembers, and speaks aloud
  • Values built in — a permanent constitution it can’t be stripped of
  • Unlike any AI ever built — by architecture, not by tuning
● AVAILABLE NOW

CodingSidekick

CSK · Newton’s coding mind, unchained · multi-model · Linux · macOS

CodingSidekick is to Newton what Claude Code is to Claude — his native coding hands. But it was never chained to one mind: point it at Newton for a sovereign brain, or run it against Claude, GPT, or your own local models. Multi-agent, multi-model, and — off Newton — multi-skilled by design. Imagine Claude Code hit the gym, took every PED known to science, somehow didn’t die, fused with 300+ tools, and refused to be locked to a single vendor.

  • Newton-native, yet model-agnostic — Newton, Claude, GPT or local
  • Multi-agent, multi-model orchestration — delegate and parallelise
  • Persistent cross-session memory & project context
  • 300+ integrated MCP tools out of the box
  • Automated security review & vulnerability pipeline
  • Multi-skilled by design — never chained to a single model
● AVAILABLE NOW
👁

HawkEye ★ v3

HEY · v3.7.1 · Debian/Kali · x86-64 · Live NVD + MITRE
— even more vicious now

3,092 CVE attack flows. Zero false positives. Vulnerability intelligence from scan to shell to report in one native GUI — nmap NSE, live NVD enrichment, MITRE ATT&CK, and 3,376 Metasploit exploit pairs where every detection is a real, module-verified attack path. Discover → inject rogue VLANs/subnets → exploit → loot → report.

  • 3,092 CVE → 3,376 Metasploit exploit pairs — the whole framework, not a handful
  • Zero false positives — every attack proven by the module's own check
  • Aggressive Pentest chains — EternalBlue→domain, secretsdump, Kerberoast, RDP lateral
  • Auto-pentest — passive learn, rogue-gateway/VLAN detection, segment injection
  • 9,000+ Nuclei templates natively + live NVD API v2 + MITRE ATT&CK auto-mapping
  • Professional HTML report — network topology graph, findings, ATT&CK table
● AVAILABLE NOW
🌐

InfraScan Pentester Sidekick

IPS · v1.0.0 · Debian/Kali · x86-64

Network infrastructure pentesting with built-in intelligence. Live topology map with zoom/pan, rogue gateway detection, VLAN hop automation, 30+ vendor fingerprints, MITRE-mapped findings, and a professional HTML report with embedded network diagram.

  • Rogue gateway hunt — detects pfSense, FortiGate, Palo Alto, MikroTik + 25 more
  • VLAN enumeration + 802.1Q double-tag hopping (auto tshark)
  • Beyond-gateway probe — traceroute-guided multi-threaded subnet sweep
  • Live zoomable topology map — nodes, edges, gateway diamonds
  • MITRE ATT&CK mapped findings + HTML report with topology SVG
  • GUI + CLI · zero dependencies · static binary
● AVAILABLE NOW
⚙️

ComputeEngine

CE · v0.2.0 · Proxmox 9.x · AMD / Intel / NVIDIA

vGPU, the good way. Share one physical GPU across every VM on your Proxmox cluster — consumer cards, any vendor, no per-GPU licence. A Proxmox driver plus a live web manager with real GPU/CPU telemetry. Now with a live demo you can watch.

  • One GPU shared across many VMs — no passthrough waste
  • Runs on the consumer cards you already own
  • Any vendor — AMD, Intel or NVIDIA
  • No per-GPU / per-user licence, ever
  • Live manager: real GPU/CPU telemetry, per model, per node
● AVAILABLE NOW
🌐

WebVuln Pentester Sidekick

WPS · Debian/Kali · x86-64

Full-spectrum web application security assessment. Automated discovery and exploitation of injection, logic, and authentication flaws — from recon to proof-of-concept in one binary.

  • SQL injection — blind, error-based, time-based
  • XSS, SSTI, SSRF, XXE, IDOR automated chains
  • JWT attack suite — alg:none, key confusion, brute
  • Auth bypass — OAuth abuse, SAML confusion
  • Intercepting proxy with automated attack playbooks
  • GUI + CLI · PoC + evidence report output
▲ RELEASE CANDIDATE

NHH Crack Server

NCS · Bootable ISO · NVIDIA CUDA 12 + AMD ROCm 6

Plug in a USB pen drive, boot, and your machine becomes a dedicated cracking node in under two minutes. Tor hidden service + WireGuard mesh auto-configure on first boot — no keyboard, no screen needed after that. 80% CPU/GPU goes to hashcat; the rest keeps Tor and WireGuard alive.

  • Zero-config ISO — boot from pen drive, cracking server starts automatically
  • NVIDIA CUDA 12 + AMD ROCm 6 GPU drivers pre-installed
  • Tor hidden service + WireGuard mesh — no open ports, invisible to internet
  • hashcat, John the Ripper, Hydra, Medusa, Aircrack-ng, wfuzz bundled
  • cgroups v2 resource slices — 80% CPU/GPU dedicated to cracking
  • Integrates with all NHH Sidekick GUI tools via WireGuard API
▲ RELEASE CANDIDATE
📢

HackMarketing

HKM · v0.1.0-rc.1 · Rust · Self-hosted · AI-operated

Marketing was never an art — it's an undocumented protocol, and we reverse-engineered it. Point HackMarketing at your product's own source of truth and an AI agent runs the entire go-to-market loop: positioning, copy, scheduling, cross-posting, and the algorithm games the "experts" gatekeep behind a diploma. Self-hosted — your keys, your data, your accounts. Fire the marketeer.

  • Reads your repo / product catalog as the brief — no incumbent does this
  • Hacks the algo — optimizes every post against each platform's real ranking signals
  • Generate → human-approve → post across channels (Bluesky live; more landing)
  • Encrypted vault for OAuth tokens + MFA seeds — nothing leaves your box
  • Local daemon + embedded manager; optional team web view
  • Tiers: Starter (prove the bluff) · Gold (run campaigns) · Platinum (full autonomous AI)
⬡ BETA
🔬

DFIR Pentester Sidekick

DPS · Debian/Kali · x86-64

Digital forensics and incident response — three analysis engines in one binary. Windows event log triage, memory forensics, and PCAP/network forensics. From raw evidence to IOC list and incident timeline in minutes.

  • EVTX triage — attack timeline + MITRE ATT&CK mapping
  • Lateral movement chain reconstruction
  • Memory forensics via Volatility 3 wrapper
  • PCAP analysis — C2 detection + credential extraction
  • IOC hunting with OSINT enrichment
  • GUI + CLI · professional IR report output
⬡ BETA
🔑

CredDump Pentester Sidekick

CDS · Debian/Kali · x86-64

Windows credential extraction without the guesswork. Detects privilege paths, AV/EDR state, and LSASS protections — then selects the optimal extraction technique automatically.

  • Auto-detects privilege level, PPL, Credential Guard, EDR
  • LSASS — multiple extraction paths ranked by stealth
  • NTDS.dit via VSS shadow copy or remote DC dump
  • LAPS v1/v2 password extraction
  • SAM, LSA secrets, DPAPI master keys
  • GUI + CLI · auto-routes hashes to crackers
⬡ BETA
🏰

AD Pentester Sidekick

APS · Debian/Kali · x86-64

Active Directory attack chain automation — from zero access to domain compromise. Automates the full AD kill chain so you spend engagement time on findings, not stringing together eight different Python scripts.

  • Kerbrute user enum — no lockout risk
  • Kerberoasting + AS-REP roasting — hash extraction
  • BloodHound-compatible attack path analysis
  • Pass-the-Hash/Ticket · Over-Pass-the-Hash
  • ACL/DACL abuse · shadow credentials
  • DCSync → domain compromise · GUI + CLI
⬡ BETA

Cloud Pentester Sidekick

CPS · Debian/Kali · x86-64

AWS, Azure and GCP pentesting in one binary. IAM enumeration, privilege escalation paths, exposed storage discovery, serverless attacks and container escapes — cross-cloud credential harvesting built in.

  • IAM enumeration & privilege escalation paths
  • S3/Blob/GCS exposure scanner
  • Serverless function abuse & event injection
  • Container escape — ECS, EKS, AKS, GKE
  • Cross-cloud credential harvesting & lateral movement
  • GUI + CLI · cloud attack graph output
⬡ BETA
🔐

TunnelKit Pentester Sidekick

TPS · Debian/Kali · x86-64

VPN and tunnel security assessment. Tests WireGuard, OpenVPN, IPSec and SSH tunnels for misconfigurations, credential exposure, split-tunnel bypass and traffic interception vectors.

  • WireGuard & OpenVPN misconfiguration detection
  • Split-tunnel bypass & traffic leakage testing
  • IPSec weak cipher & PSK brute forcing
  • SSH tunnel pivoting & credential extraction
  • VPN credential spray per known providers
  • GUI + CLI · tunnel map + finding report
⬡ BETA
📡

WiFi Pentester Sidekick

WFP · Debian/Kali · x86-64

Wireless security assessment from scanning to exploitation. WPA2/WPA3 handshake capture, PMKID attacks, evil twin automation and enterprise 802.1X/EAP downgrade attacks — from a single adapter.

  • WPA2/WPA3 handshake capture & PMKID attack
  • Evil twin with captive portal credential capture
  • Deauth & disassociation attack automation
  • 802.1X/EAP downgrade & MSCHAPv2 capture
  • Rogue AP detection & client targeting
  • GUI + CLI · wireless survey + attack report
⬡ BETA
👑

PrivEsc Pentester Sidekick

PPS · Debian/Kali · x86-64

Privilege escalation automation for Windows and Linux. Discovers and chains misconfigurations, exploitable services, weak file permissions, token abuse and kernel vulnerabilities — then walks you through the exploit path.

  • Windows: token impersonation, unquoted services, AlwaysInstallElevated
  • Linux: SUID/GUID abuse, sudo misconfig, writable paths
  • Scheduled task & cron job exploitation
  • Kernel exploit suggestion & auto-staging
  • LOLBIN chaining & living-off-the-land paths
  • GUI + CLI · privilege chain visualiser
⬡ BETA
📋

ComplianceAuditor Pentester Sidekick

CAPS · Debian/Kali · x86-64

Automated compliance gap analysis across PCI-DSS, ISO 27001, SOC 2 and GDPR. Evidence collection, control mapping and gap report generation — in one engagement binary.

  • PCI-DSS, ISO 27001, SOC 2, GDPR frameworks
  • Automated control evidence collection
  • Gap identification & remediation priority scoring
  • Network & host configuration auditing
  • Auditor-ready evidence pack + executive summary
  • GUI + CLI · multi-framework delta comparison
⬡ BETA
📱

MFA Pentester Sidekick

MPS · Debian/Kali · x86-64

So your pentesting just checks for an MFA present… how professional! 90% of MFA is wanna-be stuff — test it properly, and the Sidekick helps you do just that.

  • Real-time OTP relay — transparent man-in-the-middle phishing proxy
  • Push notification fatigue & bombing automation
  • TOTP/HOTP secret extraction from authenticator backups
  • SMS OTP interception & SIM swap recon workflow
  • Account recovery bypass & fallback channel abuse
  • GUI + CLI · SSO token capture & session hijack
⬡ BETA
🖐

InvisiRAT for Pentesters

IRAT · Debian/Kali · x86-64

Two-stage stealthy remote access for red team engagements. Rust dropper embedded in PDF, JPEG or ZIP carriers writes an XOR-obfuscated Python agent on execution. Supports Metasploit Meterpreter. Every binary forensically watermarked to its operator license.

  • PDF, JPEG, ZIP polyglot carrier embedding
  • XOR-encrypted Python agent — per-build randomised bytecode
  • Meterpreter payload via msfvenom integration
  • Forensic watermark — every binary traceable to operator
  • VirusTotal & no-distribute scanner guidance built-in
  • OSINT: Censys/Shodan C2 infrastructure discovery
// other tools

Beyond pentesting — tools for the rest of the operator workflow.

⬡ BETA
🚗

FlipperCarCommander

FCC · Flipper Zero companion

Automotive security research companion for Flipper Zero. Rolling code capture and replay, key fob cloning, garage protocol decoding and CAN bus injection.

  • Rolling code analysis & replay attack
  • RF key fob capture and cloning
  • CAN bus frame injection
⬡ BETA

AngieManager

AM · Angie web server GUI

Visual management layer for the Angie web server. Config editor, certificate lifecycle, upstream pool builder and live traffic analytics — no YAML wrestling.

  • Visual Angie config editor
  • TLS certificate lifecycle
  • Load balancer & upstream pool builder
// hacking hardware

Physical attack tools for the operator who needs to be there without being there.

● AVAILABLE NOW
📡

Tiny Deauther

TDA · Hardware · Battery-powered · WiFi + Mobile app

A thumb-sized, battery-powered WiFi deauthentication device designed to be hidden on-site. Connects over the local WiFi or companion app and deauths the target network until ordered to stop or the battery runs out.

  • Hidden placement — concealable, no power cable required
  • Continuous 802.11 deauth attack until stopped
  • WiFi control panel + iOS/Android companion app
  • Targeted (per-MAC) or broadcast deauth modes
  • Display Edition (OLED) or Stealth Edition — both -NA-
Order → -NA-
⬡ BETA
🖱

Bad Mouse

BMO · Hardware · USB · RF · Bluetooth

A fully functional USB mouse with a hidden HID attack brain inside. Deploy keystroke scripts, exfiltrate data and run command sequences remotely via web panel or mobile app — it just looks like a mouse.

  • Wired USB · Wireless RF · Bluetooth variants
  • Remote control via web panel or mobile app
  • HID script injection at hardware speed
  • Data extraction — files, credentials, config
○ IN DEVELOPMENT

Bad Keyboard

BKB · Hardware · USB HID attack platform

Same principle as Bad Mouse — in a keyboard. Type normally, trigger attacks remotely. HID-speed script injection and data exfiltration, controlled from a web panel or mobile app.

  • Fully functional keyboard — undetectable to OS
  • Remote trigger via web panel or mobile app
  • Script library: PowerShell droppers, reverse shells, harvesters
  • Data exfiltration over embedded wireless link
○ IN DEVELOPMENT
📶

Bad WiFi

BWF · Hardware · Rogue WiFi implant

A rogue WiFi implant that hides inside the target network. Plant it during physical access — remote foothold from outside the perimeter, pivot tunnel into internal network, no return visit required.

  • Hides on LAN — no obvious indicators
  • Wireless foothold accessible from outside the perimeter
  • Internal network pivot tunnel
  • PoE or USB powered
⬡ BETA
🏴

WiFi Frontgun

WFG · Hardware · Remote WiFi attack unit

Directional, remote-managed WiFi attack unit. Point it at the target from the street, fingerprint the victim network, inject a tailored evil twin from afar — never entering the premises.

  • Passive WiFi fingerprint — SSID, security type, client count
  • Remote evil twin injection with captive portal credential capture
  • Directional high-gain antenna for range
  • Web panel + mobile app control
⬡ BETA
🐊

Flipper Key Injector

FKI · Hardware + Software · Flipper Zero platform

Wireless keyboard injection for the Flipper Zero. Firmware + companion module extend the Flipper’s BadUSB capability with remote wireless triggering — inject payloads from across the room, controlled by mobile app or web panel.

  • Wireless payload trigger — no sitting at the target keyboard
  • DuckyScript-compatible — your scripts work immediately
  • Professional payload library, kept current
  • Licensed + watermarked per operator

The Manifesto

We don't put a hat on it. The white hat defends, the black hat attacks, the grey hat does both with a lawyer on speed dial. We do whatever the engagement calls for — because the goal is to find the hole before someone else does.

Our tools are built for operators who are doing real work on real engagements. Not for marketing decks. Not for compliance checkbox exercises. For the people who actually test things.

The stack is Rust. The platform is Debian/Kali. The binary is static. If it doesn't run on a fresh Kali install with zero setup, it doesn't ship.

macOS is for victims with excessive money.
Windows is for victims with defective reasoning.
We build for operators.

These tools are designed by a juvenile hacker — now a security consultant working the industry for over 34 years. Each and every one of them was designed for pentesting and security auditing purposes, and has drawn blood in the field. As CVEs get patched and progress moves on, we will always do our best to keep the tools current. We use them ourselves.

If we ever EOS a tool, we immediately cancel all active subscription renewals and convert every existing licence to God Mode — an unrestricted, perpetual licence with no further charges. You keep the tool. You keep using it. Updates stop, but the binary doesn't. We are not in the business of pulling the rug.

Start with EPS → Customer Portal
// pricing

Plans & Pricing

Monthly and annual plans for solo operators and small teams.
Hardware priced separately.

-NA-
Licensing paused. Due to a general lack of engagement, this project has gone private. Already-issued licenses will continue to work, but no new licenses will be issued to the general public at this point in time.
View Pricing →