The Loadout

The Arsenal

The tools I reach for daily, grouped by discipline. "Level" is a rough self-rating — Daily means muscle memory, Familiar means I know it but don't live in it.

Offensive

Burp Suite

Daily

Primary tool for web app testing — proxying, repeater, and intruder for manual exploitation.

Nmap

Daily

First step on almost every engagement — service/version detection and initial attack surface mapping.

Metasploit

Proficient

Exploitation framework for validating known vulnerabilities and post-exploitation modules.

Hydra

Familiar

Credential brute-forcing against common services when scope allows.

Blue Team

Wireshark

Daily

Packet-level traffic analysis for both offense (recon) and defense (incident investigation).

ELK Stack

Proficient

Log ingestion and correlation for building out detections and triage dashboards.

Maltego

Proficient

Entity correlation for OSINT — mapping relationships between people, domains, and infrastructure.

Nessus

Familiar

Vulnerability scanning for baseline coverage before manual testing.

Dev

Nuxt / Vue

Daily

This site — and most tool dashboards I build — run on Nuxt.

Python

Daily

Automation, custom recon scripts, and the backbone of most tooling I write.

Docker

Proficient

Reproducible environments for both engagements and local dev.

FastAPI

Proficient

Backend framework of choice when a project needs a real API layer.

Waking the temple guardians...0%