950+ offensive security commands with detection engineering, MITRE ATT&CK coverage, and SOC triage - fully offline. Fill your target details once, copy ready-to-run commands. Includes an Attack-Path Map, Study mode for exam prep, Detection dashboards with 3,693 structured detections (Splunk, Elastic, Sentinel, Sigma), and a Triage lookup. Covers CPTS, OSCP, CWES, CDSA, and CRTP. Everything you personalize is saved in this browser.
Finding commands
- Search (Ctrl+K) - ranked by relevance, match highlighted, tolerant of typos. Narrow with
field:value: tool:hydra, opsec:loud, platform:windows, cat:enumeration, sub:kerberoasting, type:payload, mitre:T1003, tag:pivoting, access:credentials. Combine freely. (The ? by the search box shows this too.)
- Category tree - Category → Group → Subcategory. Click a group to see everything in it; counts on every node.
- Filters (sidebar) - certification, type, platform, OpSec/noise, access level, protocol, tool. Reset Filters clears everything.
- Favorites ★, Recently Used (last commands you opened), and Collections (your own named sets) - each a sidebar view.
The Command Builder (right panel)
- Target Context bar - set your engagement variables once (IP, user, password, domain, DC, LHOST/LPORT…). They fill every command. "Show all variables" reveals the rest. It's alias-aware: a command written with
<target> or <host> still fills from your single IP value.
- Parameters & Generated Command - fill any command-specific fields; the finished command shows with your values. Unfilled lists variables you still need to set. Copy copies it.
- Attack Chain - multi-step cards are substituted too, with Copy all for the whole sequence, and Script to copy the steps as a runnable bash/PowerShell script (platform-aware) with your target filled in.
- Examples / References - concrete lab examples, and links to the tool's docs + the HTB module (where to review if stuck).
- Recommended Next Commands - the attack-chain flow (grouped: Next steps / Alternatives / Prerequisites / Escalation), plus Reached From (what leads here). Click to jump.
- OpSec badge (silent/quiet/moderate/loud = how detectable) and MITRE ATT&CK chips (link out; searchable).
- My Notes - your own annotation on any card (gotchas, lab tweaks). Saved locally, searchable, marked with ✎.
- Findings button - push this command into Exam Mode's findings log / report.
- Bookmark button - add the card to a Collection (create/delete collections here).
Map, Study & Coverage (top bar)
- Map - an interactive Attack-Path graph around the selected command: what leads here (left) → this → next / escalation (right), edges colored by relationship, an OpSec dot per node. Click a node to re-center, zoom with −/⤢/+, or use Path to: to trace the shortest chain from here to a goal (e.g. Golden Ticket). Export path saves the whole path as a Markdown cheatsheet.
- Study - flashcards (see the name + description, recall the command, then reveal & self-grade Got it / Again) and a quiz ("what's a recommended next step after X?" and "which command does X?"). Scope to All / Favorites / a specific cert. Cards you miss are remembered as Weak areas and resurfaced across sessions (spaced repetition) - drill exactly what you keep getting wrong.
- Coverage - four tabs: MITRE ATT&CK technique counts, By Certification (cards + defense/chain %), Source coverage (per-module tool-coverage %, green/amber/red), and Tools. Click any cell/tool to filter the library to it.
Your data
- Named engagements (the ≡ menu by the context bar) - save the current variable set under a name and switch between targets. Export/import to move a setup between machines.
- Back up ALL my data (same ≡ menu) - exports favorites, notes, engagements, context, collections, recent, and your Study weak-areas to one JSON file. Restore brings it back. Use this so nothing is ever lost.
- Everything personal lives in this browser's local storage - clearing browser data wipes it, so back up.
Exam Mode
The Exam Mode button (top bar) opens a separate "battle station": engagement variables (same vocabulary), a 10-phase methodology playbook, host tracker, findings log, and one-button markdown report export. Send commands to it with the Findings button in the builder.
Tips
- Keyboard: Ctrl+K focus search · ↑/↓ move through results · Enter opens · Esc closes menus.
- Offline: fully self-contained - works on an exam VPN with no internet.
- Print: Ctrl+P prints a clean black-on-white cheatsheet of the current cards - chrome stripped, code boxed, reference URLs spelled out.
- Mobile: the sidebar collapses to a ≡ drawer.