Combat-ready tools, documented end to end.
Open-source offensive security tools, built and documented for operators. Each tool has full documentation, install guides, and walkthroughs.
Web & OSINT
- anansi — attack surface intelligence from the terminal
- nzinga — authorized OSINT collection and correlation
Network & Directory
- toha3ee — local and network security assessment
- shaka — Windows and Active Directory assessment
- mansa — authorized wireless security assessment
Binary & Fuzzing
- aksum — binary assessment and reverse engineering
- kush — offline malware sample analysis
- sekhmet — baseline-aware fuzzing and vulnerability discovery
Mobile
- jabari — Android device assessment
- amanirenas — offline iOS and Android app assessment
Infrastructure
- imhotep — offline cloud snapshot analysis
- sundiata — identity and access assessment for Active Directory
- timbuktu — incident response and digital forensics
Shared
- qyvora-common — the contract and conformance suite every QYVORA framework is built against