← cd ~/home
The Arsenal
Technical methodologies and toolchains used in daily AppSec operations, SSDLC integration, and security research.
Nmap
RECON // Network Discovery[ + ]
FFuf
RECON // Web Fuzzer[ + ]
Gobuster
RECON // Directory/DNS[ + ]
Wireshark
RECON // Packet Analysis[ + ]
Burp Suite (Community)
EXPLOIT // Web Proxy[ + ]
SQLMap
EXPLOIT // SQL Injection[ + ]
Nuclei
EXPLOIT // Vulnerability Scanner[ + ]
HPE Fortify
APPSEC / SSDLC // SAST[ + ]
DefectDojo
APPSEC / SSDLC // Vulnerability Mgmt[ + ]
GitHub Actions / Pipelines
APPSEC / SSDLC // Automation[ + ]
Hydra
POST-EXPLOIT // Brute Forcer[ + ]
John the Ripper
POST-EXPLOIT // Cracker[ + ]
Linux (Kali/Ubuntu)
OS & ENVIRONMENT // Native Shell[ + ]
Windows
OS & ENVIRONMENT // Client/AD[ + ]
macOS
OS & ENVIRONMENT // Workstation[ + ]
Docker
OS & ENVIRONMENT // Containerization[ + ]
Obsidian
PRODUCTIVITY // Knowledge Mgmt[ + ]
VS Code
PRODUCTIVITY // IDE[ + ]
Google Docs/Sheets
PRODUCTIVITY // Reporting[ + ]
MS Word
PRODUCTIVITY // Reporting[ + ]
