Built by the people who use them. We make offensive security platforms that give operators an unfair advantage and give leaders the confidence to deploy them.
One platform. 100+ tools. Zero configuration. ONINET is a containerized offensive security workspace — purpose-built for operators, with session recording, engagement management, and the reporting your organisation demands.
Activate your license in seconds with oninet activate. Manage operators, track usage, and control your deployment from the customer portal.
Everything runs locally with oninet pull. Cached for 30 days of offline operation — ideal for air-gapped environments.
oninet run gives you a full desktop environment with 100+ tools, accessible through any browser. Operators are productive immediately.
Need more firepower? sat start bloodhound — satellite containers for BloodHound, Metasploit, and more, running in seconds.
Complete desktop accessible through any browser. No local install, no VPN — operators work from anywhere, IT controls nothing on the endpoint.
Encrypted-at-rest credential storage with shell integration. Secrets entered through the vault are protected and never leak to session recordings.
100+ tools across every domain — recon, Active Directory, cloud, web app. Pre-installed, pre-configured, ready to run.
Resource-heavy tools run in their own containers. Pull what you need, when you need it.
Your workspace persists across restarts. Ops, loot, evidence, and logs — structured and always available.
Every terminal session recorded automatically. Full audit trail for compliance — credentials never captured.
Scoped engagements with structured workspaces. Track operators, timelines, and deliverables — reporting built in, not bolted on.
Customer portal for license management, operator provisioning, and deployment oversight. Control who has access and what they see.
Concurrent operator sessions with shared workspaces. Your team works together — leadership sees the progress.
Create scoped engagements with structured workspaces for ops, loot, evidence, and logs. Track operators, dates, and deliverables in one place.
Replay any session, search across recordings, extract command history. Every terminal interaction captured automatically.
Generate engagement summaries with credential counts, session timelines, satellite usage. Markdown reports ready for your deliverables.
Sync your container clock to a Domain Controller for Kerberos authentication. Continuous background sync with live skew monitoring.
Timestamped, operator-attributed notes attached to the current engagement. Appear automatically in reports — no copy-pasting from terminals.
Log discovered hosts with roles and observations as you find them. Deduplicated by hostname, exported as a structured table in engagement reports.