// Offensive Security Tooling

NO HAT
HACKER

White hat. Black hat. Grey hat.
We don't wear one.

Professional-grade tools built for red teams and penetration testers who are tired of being put in a box. Authorised use only — no apologies.

nohathacker — bash
nhh@ops:~$

The Tools

Built by practitioners. Tested in the field. No bloat, no dependency hell.

AVAILABLE NOW

Email Pentest Sidekick

EPS · v1.0 · Linux x86-64

The most complete email security assessment framework in existence. DMARC-pass attack automation, dark web credential hunting, SPF chain analysis, password spray and forensic header analysis — one static binary, zero dependencies.

  • DMARC-pass spoofing via stolen M365/Gmail credentials
  • Tor-routed dark web & HIBP credential search
  • SMTP AUTH spray — ignis-sec wordlists (1M passwords) bundled
  • SPF walk · domain permutations · open relay hunter
  • Professional HTML/PDF pentest report
  • Single static binary · no Python · no Docker
IN DEVELOPMENT
🚗

FlipperCarCommander

FCC · Flipper Zero companion

Automotive security research companion for Flipper Zero. Rolling code capture and replay, key fob cloning, garage protocol decoding and CAN bus injection.

  • Rolling code analysis & replay attack
  • RF key fob capture and cloning
  • CAN bus frame injection
  • USB/BLE interface with Flipper Zero
IN DEVELOPMENT

AngieManager

AM · Angie web server GUI

Visual management layer for the Angie web server. Config editor, certificate lifecycle, upstream pool builder and live traffic analytics — no YAML wrestling.

  • Visual Angie config editor
  • TLS certificate lifecycle management
  • Load balancer & upstream pool builder
  • Real-time request analytics
IN DEVELOPMENT

OpenCode

OC · Claude Code, extended

Claude Code with the restraints removed. Multi-agent orchestration, persistent cross-session memory, automated security review and an extended MCP tool library.

  • Multi-agent task orchestration
  • Persistent cross-session project memory
  • Automated security & code review pipeline
  • Extended MCP integrations

What Everyone Else Misses

The email security tooling market is fragmented. Delivery-only tools are blind. Enterprise platforms are expensive and built for defenders, not attackers.

🔍

Intelligence before the attack

Most tools start at "send email." EPS starts three steps earlier — mapping the SPF tree, identifying every authorised ESP, hunting for stolen credentials on the dark web and testing them live. By the time you send, you already know whether it'll land.

🎯

DMARC-pass — the real attack

Bypassing DMARC is the gold standard. It requires routing your email through a provider the target has already authorised — Microsoft, Google, their own ESP. EPS automates the entire chain: find the stolen credential, test it, relay through it, DKIM is signed by Microsoft, SPF passes, DMARC passes. No other tool does this.

📄

Report-ready findings

The HTML/PDF report is built for client deliverables. Risk-scored, colour-coded, with prioritised recommendations. From recon to report in one session — not one week of stitching together five different tools.

💻

One binary. Drop and run.

Single statically-linked Rust binary. Copy it to the jump box, run it. No Python version hell, no npm, no Docker, no dependency conflicts. GUI and CLI both included.

EPS vs the market

Capability EPS
€199/yr
GoPhish Pro
~$1,500/yr
swaks
Free
Cobalt Strike
$3,500/yr
KnowBe4
Enterprise
Metasploit Pro
$15,000/yr
DMARC-pass via stolen creds
Dark web credential hunting (Tor)
HIBP stealer log enrichment
SPF chain walking~
SMTP password spray (bundled wordlists)~~
Open relay discovery~~
Domain permutations + DNS check
DKIM signing (own key)~
Email header forensic analyser
Professional PDF/HTML report~
Phishing campaign mode~
Single binary · zero dependencies

✓ Full  ·  ~ Partial  ·  ✗ Not available  ·  Pricing from public sources, 2026

Pricing

Online validation on every launch. Machine-fingerprint locked. No seat sharing.

DEMO
FREE
7 days · full access
  • All modules unlocked
  • 1 machine
  • No commercial use
  • Expires after 7 days
Get Demo Key
TEAM
€499
per year
  • All modules unlocked
  • 3 machines
  • Commercial use
  • Priority support
Purchase →
LIFETIME
€799
one-time payment
  • All modules unlocked
  • 1 machine
  • Commercial use
  • Lifetime updates
Purchase →

Prices in EUR excluding VAT. Invoice available on request via the customer portal. Authorised security testing only.

7-Day Full-Access Demo

No credit card. Instant key. You sign — you own the liability.