Skip to main content

Open-Source Tools

Utilities built for real assessment work.

Ridgeback tools are built to solve practical workflow problems for penetration testers, vulnerability managers, and security operators. They are MIT-licensed and available on GitHub.

Auxiliary banner CLI Utilities

Auxiliary

Auxiliary is a collection of dependency-free Python utilities for reconnaissance, list processing, firewall management, and local operational tasks during security assessments.

Tools are available through a unified auxiliary <tool> CLI or individual commands with aux- prefixes.

Use Auxiliary when you need to:
  • Clean up targets, IPs, credentials, or tool output quickly
  • Run small assessment helpers without extra dependencies
  • Standardize repeatable local operator tasks
  • DNS tools and domain controller discovery
  • IP extraction and target list normalization
  • Gobuster output conversion
  • Nessus scope and utility workflows
  • Firewall management with dry-run and backups
  • Credential splitting, chunking, and other file processing helpers
  • Dependency-free scripting and automation support
pipx install git+https://github.com/ridgebackinfosec/auxiliary.git
Second Eye banner HTTP Proxy

Second Eye

Second Eye is a scope-gated HTTP/HTTPS recording proxy for offensive security operators who want structured capture around a specific target.

It runs alongside a browser, curl, Burp Suite, ZAP, or other tooling to record in-scope traffic and produce AI-consumable analysis notes without inspecting unrelated traffic.

Use Second Eye when you need to:
  • Capture target-specific HTTP flows during manual testing
  • Chain through Burp or ZAP while preserving a separate analysis trail
  • Package request and response context for trusted AI-assisted review
  • Scope-gated TLS termination based on target domains and regexes
  • Blind relay for out-of-scope traffic
  • Capture windows with labeled output directories
  • Raw HAR, structured manifest, and narrative ANALYSIS.md output
  • Loopback-only proxy and control socket
  • Linux-focused v1 operator workflow
pipx install git+https://github.com/ridgebackinfosec/second-eye.git

Want to see the tools in context?

Watch the Cerno webcast or browse recordings for practical offensive security walkthroughs and related field notes.

Watch Recordings

Contribute

Found a bug, have a feature idea, or want to submit a pull request? Community feedback helps make these tools better for real workflows.