Armory — Restricted
Kali MCP
RestrictedCIDR allowlistDestructive-action confirmationAudit log
A Model Context Protocol server exposing 24 Kali pentest tools over SSH, so an AI agent can drive offensive-security tooling with guardrails instead of a bare shell. This is the concrete artifact behind "AI x offensive security" — not a demo, a server that runs.
- Tools exposed
- 24
- Transport
- MCP over SSH
- Access control
- CIDR allowlist
- Destructive actions
- Confirmation required
- Logging
- Audit DB, every call
aioffsecmcp
Bay 01
Threat-Intel-V3
LiveA six-stage collection pipeline (collect, normalize, enrich, score, dedupe, publish) that pulls from CISA KEV and NVD, scores CVEs with EPSS instead of raw CVSS severity, and publishes short per-niche digests instead of one unread firehose. Runs as a production service behind the homelab’s forward-auth.
- Pipeline stages
- 6
- Sources
- CISA KEV + NVD
- Scoring
- EPSS, not raw CVSS
- Auth
- Homelab forward-auth
blue-teamthreat-intelsecurity-engineering
Read the write-up →Bay 02
Home SOC
LiveA single-operator SOC built on a homelab budget: log collection and normalization, a SIEM, detections written and version-controlled as Sigma rules, hypothesis-driven threat hunting instead of alert-chasing, and SOAR playbooks that automate the 80% of response that doesn’t need a human. Documented end to end in the Blue Team Homelab series.
- SIEM
- Self-hosted
- Detections
- Sigma, version-controlled
- Hunting model
- Hypothesis-driven
- Response
- SOAR playbooks
blue-teamsocdetection-engineering
Read the write-up →Bay 03
AI Homelab at Scale
Live30+ self-hosted services across a 2-node Proxmox cluster, run solo: SSO-gated by default via forward-auth, one source of truth for monitoring, and systemd memory-guard discipline that exists because an unguarded service once OOM-crashed the VM. The Start Your AI Homelab series documents how to build the foundations; the two-years-in field note covers what actually broke.
- Services
- 30+
- Cluster
- 2-node Proxmox
- Auth
- SSO forward-auth by default
- Ops discipline
- systemd memory guards
homelabproxmoxsre
Read the write-up →Bay 04
Real-Time Bot Fleet
LiveA fleet of always-on bots and data pipelines operated for a private online community — webhook ingestion, scheduled pulls from rate-limited third-party APIs, and alerting with dedupe logic, kept running under real users who notice within minutes when something breaks. The point isn't what the bots say; it's that they say it 24/7 without a pager team behind them.
- Ingestion
- Webhooks + scheduled pulls
- Surface
- Chat bots + alert feeds
- Users
- Live private community
automationbotsreal-time-data