Documentation
Everything Oniomarchy installs, wires up, and gets out of your way about — the toolkit, the privacy layers, and the machine underneath.
Start Here
- What Oniomarchy Is
A beautiful, opinionated Linux workstation for security work — Omarchy's craft, pointed at offense.
- Installing
One script, run on a stock Omarchy system. What it needs, what it does, and what a run looks like.
- Finding Your Way Around
The menu map — where the tools, services, and quick actions live, and how the menu shows each tool's help first.
Privacy & Anonymity
- The Layers
How Oniomarchy thinks about privacy — as independent layers you combine, not a single "anonymous mode".
- Tor & the Network
Route the whole machine or just the browser through Tor — with a kill switch, exit-country choice, and a leak check.
- MAC & Your Hardware
Randomize the hardware address your network card broadcasts, so you're not trackable across networks.
- The Hardened Browser
A Firefox configured to forget everything on exit, hide who you are, and be ready to intercept — sitting alongside your normal browser.
- Secrets & Disk
Protecting data at rest — a password manager for your credentials and encrypted volumes for your loot.
Working the Machine
- Running Services
Toggle the servers you sometimes need — SSH, RDP, database, web, BeEF — with a confirmation before you expose anything.
- Quick Attack Actions
The one-keystroke versions of the rituals that start every engagement — a listener, a file server, and proxy-CA trust.
The Toolkit
Information Gathering
Mapping hosts, services, domains, and people before you touch anything deeper. Most engagements start here.
Vulnerability Analysis
Turning "these services exist" into "these services are weak" — automated scanning for known flaws.
Web Application Analysis
Testing web applications directly — intercepting proxies, injection scanners, and fuzzers.
Password Attacks
Cracking hashes offline and guessing credentials online — plus the wordlists that feed both.
Wireless Attacks
Auditing Wi-Fi — capturing handshakes, cracking keys, and monitoring the airwaves.
Software Defined Radio
Turning cheap radio hardware into a receiver for almost anything on the airwaves.
Reverse Engineering
Taking software apart — disassemblers, decompilers, and the tools for reading what a binary really does.
Exploitation Tools
Turning a discovered weakness into access — frameworks, exploit databases, and payload builders.
Sniffing & Spoofing
Watching and manipulating network traffic — packet capture and man-in-the-middle attacks.
Post Exploitation
What you do once you're in — credential harvesting, lateral movement, and command-and-control.
Digital Forensics
Recovering, examining, and analyzing evidence — memory, disks, files, and the data hidden inside them.
Reporting Tools
Capturing findings and turning them into deliverables — notes, screenshots, and organized results.
Social Engineering Tools
Attacking the human layer — phishing campaigns, credential harvesting, and pretext delivery.
Automotive
Talking to vehicles — reading and writing the CAN bus that runs a modern car.
AI Tools
Security work at the intersection with AI — MCP servers that give agents real tooling, and a scanner for LLMs themselves.
Webapps
The best web-based security tools, installed as first-class app launchers — no browser bookmark hunting.