status: livelocation: london, onuptime-monitor: 30+ servicesbuild: 2026-07-15
Armory — Restricted

Kali MCP

Restricted
CIDR allowlistDestructive-action confirmationAudit log

A Model Context Protocol server exposing 24 Kali pentest tools over SSH, so an AI agent can drive offensive-security tooling with guardrails instead of a bare shell. This is the concrete artifact behind "AI x offensive security" — not a demo, a server that runs.

Tools exposed
24
Transport
MCP over SSH
Access control
CIDR allowlist
Destructive actions
Confirmation required
Logging
Audit DB, every call
aioffsecmcp
Bay 01

Threat-Intel-V3

Live

A six-stage collection pipeline (collect, normalize, enrich, score, dedupe, publish) that pulls from CISA KEV and NVD, scores CVEs with EPSS instead of raw CVSS severity, and publishes short per-niche digests instead of one unread firehose. Runs as a production service behind the homelab’s forward-auth.

Pipeline stages
6
Sources
CISA KEV + NVD
Scoring
EPSS, not raw CVSS
Auth
Homelab forward-auth
blue-teamthreat-intelsecurity-engineering
Read the write-up →
Bay 02

Home SOC

Live

A single-operator SOC built on a homelab budget: log collection and normalization, a SIEM, detections written and version-controlled as Sigma rules, hypothesis-driven threat hunting instead of alert-chasing, and SOAR playbooks that automate the 80% of response that doesn’t need a human. Documented end to end in the Blue Team Homelab series.

SIEM
Self-hosted
Detections
Sigma, version-controlled
Hunting model
Hypothesis-driven
Response
SOAR playbooks
blue-teamsocdetection-engineering
Read the write-up →
Bay 03

AI Homelab at Scale

Live

30+ self-hosted services across a 2-node Proxmox cluster, run solo: SSO-gated by default via forward-auth, one source of truth for monitoring, and systemd memory-guard discipline that exists because an unguarded service once OOM-crashed the VM. The Start Your AI Homelab series documents how to build the foundations; the two-years-in field note covers what actually broke.

Services
30+
Cluster
2-node Proxmox
Auth
SSO forward-auth by default
Ops discipline
systemd memory guards
homelabproxmoxsre
Read the write-up →
Bay 04

Real-Time Bot Fleet

Live

A fleet of always-on bots and data pipelines operated for a private online community — webhook ingestion, scheduled pulls from rate-limited third-party APIs, and alerting with dedupe logic, kept running under real users who notice within minutes when something breaks. The point isn't what the bots say; it's that they say it 24/7 without a pager team behind them.

Ingestion
Webhooks + scheduled pulls
Surface
Chat bots + alert feeds
Users
Live private community
automationbotsreal-time-data