Offensive security engineering, real-world adversary simulation, and hands-on cyber security education.
Armour Infosec is a cyber security company and training institute focused on offensive security — finding what real attackers would find, before they do. We pair professional security assessment services with a hands-on education program that turns learners into practitioners.
Note
This GitHub organization is the engineering-facing home of Armour Infosec: security tooling, research notes, lab material, and learning resources for developers, security engineers, students, and the wider community.
Strengthen the security posture of organizations through rigorous, adversary-focused testing — and grow the next generation of skilled security practitioners through practical, lab-driven training.
A security community where offensive expertise and defensive engineering are shared openly, so that secure systems are the default rather than the exception.
| Value | What it means in practice |
|---|---|
| Hands-on first | Skills are built in the lab, not the slide deck. |
| Responsible disclosure | Findings are reported ethically and handled with care. |
| Depth over breadth | Deep, verifiable results instead of automated noise. |
| Open knowledge | We publish learning material and share what we learn. |
| Standards-driven | Work maps to recognized frameworks and methodologies. |
We operate across two connected practices: security services and security education.
- 🎯 Penetration Testing — Web application, API, mobile, network, cloud, and AI/ML targets
- 🥷 Red Team Operations — Goal-oriented adversary simulation
- 🔍 Vulnerability Assessment — Prioritized, exploitation-validated findings
- 🏢 Active Directory Security — Enterprise attack path analysis and hardening
- 🧾 Security Auditing — Configuration and control review against standards
- 🕵️ Digital Forensics & Incident Response — Investigation and containment support
A structured curriculum spanning beginner fundamentals to advanced offensive tradecraft — every module is built around practical labs and real tooling.
| Domain | Focus Areas |
|---|---|
| Web & API Security | OWASP Top 10, OWASP API Security Top 10, REST / GraphQL / SOAP, JWT abuse |
| Mobile Security | Android & iOS testing, OWASP MASVS / MASTG |
| AI/ML Security | LLM and ML attack surfaces, OWASP LLM Top 10, OWASP ML Top 10 |
| Active Directory & Windows | Kerberos attacks, BloodHound analysis, Group Policy, PowerShell |
| Network & Wireless | Infrastructure testing, WEP/WPA/WPA2/WPA3, KARMA attacks |
| Cloud Security | Cloud configuration and workload assessment |
| Systems & Hardening | Linux server hardening, Windows Server, Apache, Samba, SSH, IPTables |
| Secure Development | Secure PHP development, secure WordPress administration, Python for security |
Practical, lab-driven courses across the offensive security lifecycle.
| Program | Level |
|---|---|
| Certified Ethical Hacking & Penetration Testing | Beginner |
| Python for Security Professionals | Beginner |
| Linux Administration & Server Hardening | Beginner |
| Enterprise Windows Infrastructure Security | Beginner |
| Secure WordPress Administration | Beginner |
| Secure PHP Development | Beginner |
| API Security & Advanced API Exploitation | Intermediate |
| Wireless Security & WiFi Penetration Testing | Intermediate |
| Advanced Web Application Security Testing | Advanced |
| Mobile Application Penetration Testing | Advanced |
| Active Directory Security & Enterprise Attacks | Advanced |
| AI/ML Penetration Testing | Advanced |
Tip
New to offensive security? Start with Certified Ethical Hacking & Penetration Testing and Linux Administration & Server Hardening, then progress into the advanced web, mobile, and Active Directory tracks.
This organization hosts and curates repositories that support both our practice and our community. Repositories generally fall into these categories:
| Category | Description |
|---|---|
| 🛠️ Security Tooling | Utilities and scripts that support assessment workflows |
| 🧪 Labs & Practice Targets | Intentionally vulnerable environments for hands-on learning |
| 📚 Learning Resources | Notes, checklists, and study material for security topics |
| 🤖 Automation | Helpers for reconnaissance, reporting, and repetitive tasks |
| 🧷 Hardening Guides | Reference configurations for servers and infrastructure |
Important
Browse the Repositories tab to see what is currently public. Each repository documents its own scope, usage, and status in its README.
Our assessment and training work maps to recognized industry standards.
| Category | Standards & Frameworks |
|---|---|
| Web / API | OWASP Top 10, OWASP API Security Top 10 |
| Mobile | OWASP MASVS, OWASP MASTG |
| AI / ML | OWASP LLM Top 10, OWASP ML Top 10 |
| Compliance & Governance | ISO 27001, ISO 9001:2015, SOC 2, PCI DSS |
- Security by Design — Threat modeling and hardening from the start, not bolted on.
- Exploitation-Validated — Findings are proven, not just flagged by a scanner.
- Automation First — Repeatable workflows over manual repetition.
- Documentation Driven — Clear, reproducible notes for every finding and lab.
- Responsible Disclosure — Vulnerabilities are handled ethically and privately.
- Continuous Improvement — Tradecraft evolves with the threat landscape.
We welcome developers, students, researchers, and security engineers.
- 🐛 Report an issue — Open an issue on the relevant repository.
- 🔀 Submit a pull request — Fork, branch, and propose changes; follow each repo's contributing notes.
- 💬 Start a discussion — Use a repository's Discussions or Issues to ask and share.
- 🎓 Learn with us — Use our public labs and resources to build hands-on skills.
Warning
Please practice offensive techniques only against systems you own or are explicitly authorized to test. Report security vulnerabilities responsibly and privately rather than in public issues.
| Resource | Link |
|---|---|
| 🌐 Website | https://www.armourinfosec.com |
| 📞 Contact | https://www.armourinfosec.com/contact/ |
| https://www.linkedin.com/company/armourinfosec | |
| 🐦 X (Twitter) | https://x.com/ArmourInfosec |
| https://www.youtube.com/c/TheHackersWorld | |
| https://www.facebook.com/armourinfosec | |
| info@armourinfosec.com | |
| 📱 Phone | +91 99777 47168 |
| 📍 Location | 674, Sudama Dwar, Narendra Tiwari Marg, Sudama Nagar, Indore, Madhya Pradesh 452009, India |
Each repository in this organization includes its own LICENSE file. Unless a repository states otherwise, refer to that file for the terms governing its use. If a repository has no license, all rights are reserved by default.
Built and maintained by Armour Infosec — offensive security, done responsibly.