Offensive security · automation

offsec-toolkit

A layered automation toolkit for authorized penetration testing and OSCP-style labs. It takes an engagement end to end across three stages: recon and collection, decision support, and evidence and reporting, all tied together by a searchable note vault.

View on GitHub → Quick start
21 scripts Bash & PowerShell 2 Flask reference apps Obsidian note vault MIT licensed
For authorized use only. These tools are for penetration testing, security research, and lab environments (such as OSCP practice) where you have explicit permission to test. Use them only against systems you own or are authorized to assess.

How it is organized

Every Kali-side script honors a single environment variable, $TOOLKIT_ROOT, for its working tree, so each tool reads and writes a consistent layout as an engagement progresses through the three layers.

Layer 1

Collection

Recon and enumeration that fan out across targets and write structured output under the shared working tree.

Layer 2

Decision support

Tools that read the collection output, rank what to do next, classify exploit outcomes, and track live access.

Layer 3

Evidence & reporting

Capture of flags and loot, proof auditing, and an evidence ledger that rolls up into report-ready material.

Components

AreaScripts
Setup & workspacetools_setup.sh, startr.sh, workflow.sh
Recon & collectionrecon.sh, webenum.sh, servr.sh, adr.sh, sprayr.sh, crackr.sh
Access & movementpivotr.sh, lootr.sh / lootr.ps1, escalatr.sh
Decision supportorient.sh, stuckr.sh, targetcheckr.sh, watchdog.sh, livefetch.sh, exploitfixr.sh
Evidence & reportingevidencr.sh, proofr.sh

Reference apps

Note vault

An Obsidian vault of methodology checklists, technique cheatsheets, tool references, and report templates that the tools and apps cross-reference.

Quick start

# install recon/enum helper tools (no sudo needed for --check)
./tools_setup.sh --check

# set the working tree (defaults to ~/toolkit)
export TOOLKIT_ROOT="$HOME/toolkit"

# run the reference apps
cd exploitdb && ./run.sh      # http://127.0.0.1:5000
cd vquery   && ./run.sh

Full documentation, the component reference, and setup notes live in the repository README.