SYS/CAPABILITY-MATRIX ยท 04OFFENSE / DEFENSE / BUILD
Tools are leverage / method is the weapon

Tactical
arsenal.

A capability system spanning application security, cloud warfare, security operations, reverse engineering, and automation.

DOMAINS4 OPERATING CELLS
PRINCIPLETOOL-AGNOSTIC

Coverage without
the clutter.

OFFENSECLOUDBUILDDEFENSE
A / OFFENSE

Offensive Security

  • Burp Suite Pro
  • Metasploit
  • Sqlmap / Nikto
  • BeEF / Hydra
  • John the Ripper
  • Nmap
B / DEFENSE

Security Operations

  • Splunk SIEM
  • Snort IDS/IPS
  • Wireshark
  • Nessus
  • BloodHound
  • OSINT
C / INFRA

Cloud & DevOps

  • AWS IAM/VPC/S3
  • Docker
  • Kali / Ubuntu
  • RHEL
  • Bash
  • Git / GitHub
D / BUILD

Engineering

  • Python
  • SQL
  • C++
  • JavaScript
  • React
  • Flask

Tools change.
Principles survive.

RECON

Build context

Map attack surface, identities, assets, and trust assumptions.

EXPLOIT

Prove impact

Use focused tests to demonstrate a real security consequence.

DETECT

Instrument failure

Create visibility around the path an attacker actually used.

HARDEN

Close the class

Fix the system pattern, not only the individual symptom.

Working
inventory.

Burp Suite ProfessionalMetasploit FrameworkNmapBloodHoundWiresharkSplunkSnortNessusAWS IAMAWS VPCAWS S3DockerKali LinuxUbuntuRHELPythonBashSQLJavaScriptFlaskReactGit

Ask the
shell.

Open Shell Mode and run arsenal for a compact capability report, or change the interface signal with theme amber and theme ice.