Skip to content
StrikeOps
Methodology & Arsenal

A curated arsenal and a proven methodology

Every offensive security engagement launches on a curated offensive arsenal and a proven methodology: deep tooling, per-scope playbooks and the tradecraft to use them, delivered into your own isolated environment.

140+

Curated tools

A deep, battle-tested toolset, kept current for you — not a stale, cobbled-together toolchain.

Full

Kill-chain coverage

From reconnaissance through to exfiltration, mapped to MITRE ATT&CK.

Every

Scope type covered

A proven playbook for external, internal, web, cloud, mobile, wireless, physical and social work.

4-tier

Action gating

Every tool risk-classified, with operator approval where it counts. Human-in-the-loop, always.

Across the kill chain

Coverage from first recon to demonstrated impact

The arsenal spans the whole offensive kill chain, so no phase of a real attack goes untested — and every step is captured for the client report.

    01

    Reconnaissance

    Map the attack surface — external footprint, assets, identities and exposure — before a single packet in anger.

    02

    Initial access

    Find and prove the way in, from exposed services and weak edges to phishing footholds.

    03

    Execution

    Run payloads and tradecraft safely, with output captured straight into the engagement record.

    04

    Persistence

    Establish and document footholds the way a real adversary would, so nothing is missed.

    05

    Privilege escalation

    Escalate on the host and across the domain — credential paths and misconfigurations alike.

    06

    Lateral movement

    Pivot across the network toward the crown jewels, tracked target by target.

    07

    Exfiltration & impact

    Demonstrate impact on target data — controlled, evidenced, and never destructive.

Coverage maps to MITRE ATT&CK automatically, so clients see exactly what was tested — not a wall of raw output.

Guardrails

Every action is gated, by design

Nothing runs on autopilot where it matters. Each tool is risk-classified, and the more consequential the action, the higher the bar before it fires. Human-in-the-loop, always.

Ungated

Read-only and passive. Runs freely.

Operator approval

Propose → wait → execute → document. A human says go.

Credential-gated

Credential attacks — spray, crack, relay — held behind explicit approval.

Destructive-gated

State-changing or data-touching actions clear the highest bar of all.

Playbooks

A proven playbook for every scope type

The methodology isn't generic. Each scope type carries its own baseline playbook, so the process is consistent no matter which operator runs the work.

  • External
  • Internal
  • Web app
  • Mobile
  • Cloud
  • Wireless
  • Physical
  • Social & phishing
Delivered ready-to-run

Hit the ground running, on infrastructure you control

The stack and the method arrive where the work happens — scoped, isolated and current — so operators start testing on day one.

Scope-filtered per engagement

A web-app job gets the recon and web toolset; a cloud job gets the cloud and identity toolset. Operators see exactly what the scope calls for, and nothing it doesn't.

Inside your own environment

The stack is delivered into your firm's isolated environment and runs on infrastructure you control — never a shared proxy, never co-mingled with another firm.

Maintained and current, for you

The toolset is curated and kept fresh centrally, so new engagements pick up the latest without your team babysitting a toolchain.

Tradecraft that travels with it

The know-how to wield the stack is taught in the Learning Center, so a new operator ramps to confident in weeks, not months.

See the arsenal put to work on your own engagements

Book a demo
Get started

Ready to run your offensive security operations on StrikeOps?

We're licensing StrikeOps to offensive security firms now. Talk to our team or start straight away.

Open for business, licensing to offensive security firms now.

Book a demo