Combat-ready tools, documented end to end.

Open-source offensive security tools, built and documented for operators. Each tool has full documentation, install guides, and walkthroughs.

Web & OSINT

  • anansi — attack surface intelligence from the terminal
  • nzinga — authorized OSINT collection and correlation

Network & Directory

  • toha3ee — local and network security assessment
  • shaka — Windows and Active Directory assessment
  • mansa — authorized wireless security assessment

Binary & Fuzzing

  • aksum — binary assessment and reverse engineering
  • kush — offline malware sample analysis
  • sekhmet — baseline-aware fuzzing and vulnerability discovery

Mobile

  • jabari — Android device assessment
  • amanirenas — offline iOS and Android app assessment

Infrastructure

  • imhotep — offline cloud snapshot analysis
  • sundiata — identity and access assessment for Active Directory
  • timbuktu — incident response and digital forensics

Shared

  • qyvora-common — the contract and conformance suite every QYVORA framework is built against