OPSEC Toolkit

Operational security toolkit. OPSEC scorecard assessment, cover identity builder for sock puppets, and engagement planning tools. All client-side, nothing leaves your browser.

#OPSEC Scorecard

#Pre-Engagement Assessment

Evaluate your engagement's operational security posture across 5 categories: infrastructure, identity, payloads, C2 communications, and operational discipline. Each "No" is a gap that could burn your operation. Export the report as markdown for your engagement records.

OPSEC Assessment Scorecard

0
/100
Not Scored
Answer items below to begin

#Cover Identity Builder

#Sock Puppet Generator

Generate coherent fake identities for operational sock puppets. Names, addresses, emails, occupations, and backstories culturally appropriate for the target country. Includes compartmentalization rules to prevent identity cross-contamination.

Cover Identity Builder

Click "Generate Identity" to create a cover identity. All data is generated client-side.

Compartmentalization & OPSEC Rules

#Tradecraft Reference

#Identity Lifecycle

Phase Actions
Creation Generate identity, create accounts via Tor
Aging 30+ days of organic activity before use
Activation Deploy for operational purpose
Maintenance Consistent timezone, posting patterns
Burn Detect compromise, stop all activity
Disposal Delete accounts, wipe credentials

#Scoring Interpretation

Score Rating Action
80-100 Strong Ready for engagement
60-79 Moderate Address gaps before go-live
40-59 Weak Significant rework needed
0-39 Critical Do not proceed

#Common OPSEC Failures

  • Reusing infrastructure across engagements
  • Uploading payloads to VirusTotal
  • Personal email in tool configurations
  • Direct connection to target without redirectors
  • GPS metadata in screenshots
  • Same payload deployed to multiple targets
  • No kill date on C2 framework
  • Unencrypted team communications

#Also See

#Cyber Aurelien Guidi