root@rochacrypt:~# ls ~/arsenal
recon/ reporting/ blue-team/ utils/366 tools Β· search & filter by category and track Β· works on mobile
A curated catalog of 366 well-known security tools plus my own operational scripts I use to speed up day-to-day work β recon organisation, reporting, blue-team triage and small utilities. Everything here is built for defensive work and authorised testing only.
| Folder | What's inside |
|---|---|
recon/ |
Scanning & enumeration helpers that organise output |
reporting/ |
Turn raw findings into clean deliverables |
blue-team/ |
Read-only triage & log analysis for detection and IR |
utils/ |
Small standalone security utilities |
| Script | Language | Does |
|---|---|---|
recon/nmap-quickscan.sh |
Bash | Structured Nmap sweep β discovery, ports, services, saved per host |
reporting/findings-to-report.py |
Python | Findings JSON β sorted CSV + Markdown table |
blue-team/ir-triage.ps1 |
PowerShell | Read-only Windows host snapshot for incident response |
blue-team/auth-log-triage.py |
Python | Summarise SSH auth logs: failed logins, top IPs & users |
utils/password-policy-check.py |
Python | Validate passwords against a policy + estimate entropy |
Each script is self-contained with a header explaining purpose, requirements and usage. Examples:
# Recon (authorised targets only)
./recon/nmap-quickscan.sh 10.0.0.0/24
# Reporting
python3 reporting/findings-to-report.py findings.json -o report
# Blue team
python3 blue-team/auth-log-triage.py /var/log/auth.log
# Utils
python3 utils/password-policy-check.py --min-length 14These tools are for authorised security testing, defence and education only. Only run them against systems you own or have explicit written permission to test. You are responsible for complying with all applicable laws and agreements. The author accepts no liability for misuse.
The index.html page is a searchable, filterable catalog of 366 tools across 14 categories. To publish it:
- Go to Settings β Pages.
- Under Build and deployment, set Source: Deploy from a branch.
- Choose branch main and folder / (root), then Save.
- After a minute it goes live at https://rochacrypt.github.io/arsenal/.
MIT β see LICENSE. Contributions and suggestions welcome via issues and pull requests.
