A curated arsenal and a proven methodology
Every offensive security engagement launches on a curated offensive arsenal and a proven methodology: deep tooling, per-scope playbooks and the tradecraft to use them, delivered into your own isolated environment.
140+
Curated tools
A deep, battle-tested toolset, kept current for you — not a stale, cobbled-together toolchain.
Full
Kill-chain coverage
From reconnaissance through to exfiltration, mapped to MITRE ATT&CK.
Every
Scope type covered
A proven playbook for external, internal, web, cloud, mobile, wireless, physical and social work.
4-tier
Action gating
Every tool risk-classified, with operator approval where it counts. Human-in-the-loop, always.
Coverage from first recon to demonstrated impact
The arsenal spans the whole offensive kill chain, so no phase of a real attack goes untested — and every step is captured for the client report.
Reconnaissance
Map the attack surface — external footprint, assets, identities and exposure — before a single packet in anger.
Initial access
Find and prove the way in, from exposed services and weak edges to phishing footholds.
Execution
Run payloads and tradecraft safely, with output captured straight into the engagement record.
Persistence
Establish and document footholds the way a real adversary would, so nothing is missed.
Privilege escalation
Escalate on the host and across the domain — credential paths and misconfigurations alike.
Lateral movement
Pivot across the network toward the crown jewels, tracked target by target.
Exfiltration & impact
Demonstrate impact on target data — controlled, evidenced, and never destructive.
Coverage maps to MITRE ATT&CK automatically, so clients see exactly what was tested — not a wall of raw output.
Every action is gated, by design
Nothing runs on autopilot where it matters. Each tool is risk-classified, and the more consequential the action, the higher the bar before it fires. Human-in-the-loop, always.
Read-only and passive. Runs freely.
Propose → wait → execute → document. A human says go.
Credential attacks — spray, crack, relay — held behind explicit approval.
State-changing or data-touching actions clear the highest bar of all.
A proven playbook for every scope type
The methodology isn't generic. Each scope type carries its own baseline playbook, so the process is consistent no matter which operator runs the work.
- External
- Internal
- Web app
- Mobile
- Cloud
- Wireless
- Physical
- Social & phishing
Hit the ground running, on infrastructure you control
The stack and the method arrive where the work happens — scoped, isolated and current — so operators start testing on day one.
Scope-filtered per engagement
A web-app job gets the recon and web toolset; a cloud job gets the cloud and identity toolset. Operators see exactly what the scope calls for, and nothing it doesn't.
Inside your own environment
The stack is delivered into your firm's isolated environment and runs on infrastructure you control — never a shared proxy, never co-mingled with another firm.
Maintained and current, for you
The toolset is curated and kept fresh centrally, so new engagements pick up the latest without your team babysitting a toolchain.
Tradecraft that travels with it
The know-how to wield the stack is taught in the Learning Center, so a new operator ramps to confident in weeks, not months.
See the arsenal put to work on your own engagements
Book a demoReady to run your offensive security operations on StrikeOps?
We're licensing StrikeOps to offensive security firms now. Talk to our team or start straight away.
Open for business, licensing to offensive security firms now.