Offensive security · automation
A layered automation toolkit for authorized penetration testing and OSCP-style labs. It takes an engagement end to end across three stages: recon and collection, decision support, and evidence and reporting, all tied together by a searchable note vault.
Every Kali-side script honors a single environment variable, $TOOLKIT_ROOT, for its working tree, so each tool reads and writes a consistent layout as an engagement progresses through the three layers.
Recon and enumeration that fan out across targets and write structured output under the shared working tree.
Tools that read the collection output, rank what to do next, classify exploit outcomes, and track live access.
Capture of flags and loot, proof auditing, and an evidence ledger that rolls up into report-ready material.
| Area | Scripts |
|---|---|
| Setup & workspace | tools_setup.sh, startr.sh, workflow.sh |
| Recon & collection | recon.sh, webenum.sh, servr.sh, adr.sh, sprayr.sh, crackr.sh |
| Access & movement | pivotr.sh, lootr.sh / lootr.ps1, escalatr.sh |
| Decision support | orient.sh, stuckr.sh, targetcheckr.sh, watchdog.sh, livefetch.sh, exploitfixr.sh |
| Evidence & reporting | evidencr.sh, proofr.sh |
An Obsidian vault of methodology checklists, technique cheatsheets, tool references, and report templates that the tools and apps cross-reference.
# install recon/enum helper tools (no sudo needed for --check) ./tools_setup.sh --check # set the working tree (defaults to ~/toolkit) export TOOLKIT_ROOT="$HOME/toolkit" # run the reference apps cd exploitdb && ./run.sh # http://127.0.0.1:5000 cd vquery && ./run.sh
Full documentation, the component reference, and setup notes live in the repository README.