Skip to content

Armour Infosec

Armour Infosec

Offensive security engineering, real-world adversary simulation, and hands-on cyber security education.

Website LinkedIn X YouTube Email

Focus Base Disclosure


About

Armour Infosec is a cyber security company and training institute focused on offensive security — finding what real attackers would find, before they do. We pair professional security assessment services with a hands-on education program that turns learners into practitioners.

Note

This GitHub organization is the engineering-facing home of Armour Infosec: security tooling, research notes, lab material, and learning resources for developers, security engineers, students, and the wider community.

Mission

Strengthen the security posture of organizations through rigorous, adversary-focused testing — and grow the next generation of skilled security practitioners through practical, lab-driven training.

Vision

A security community where offensive expertise and defensive engineering are shared openly, so that secure systems are the default rather than the exception.

Core Values

Value What it means in practice
Hands-on first Skills are built in the lab, not the slide deck.
Responsible disclosure Findings are reported ethically and handled with care.
Depth over breadth Deep, verifiable results instead of automated noise.
Open knowledge We publish learning material and share what we learn.
Standards-driven Work maps to recognized frameworks and methodologies.

What We Do

We operate across two connected practices: security services and security education.

Security Services

  • 🎯 Penetration Testing — Web application, API, mobile, network, cloud, and AI/ML targets
  • 🥷 Red Team Operations — Goal-oriented adversary simulation
  • 🔍 Vulnerability Assessment — Prioritized, exploitation-validated findings
  • 🏢 Active Directory Security — Enterprise attack path analysis and hardening
  • 🧾 Security Auditing — Configuration and control review against standards
  • 🕵️ Digital Forensics & Incident Response — Investigation and containment support

Security Education

A structured curriculum spanning beginner fundamentals to advanced offensive tradecraft — every module is built around practical labs and real tooling.


Expertise

Domain Focus Areas
Web & API Security OWASP Top 10, OWASP API Security Top 10, REST / GraphQL / SOAP, JWT abuse
Mobile Security Android & iOS testing, OWASP MASVS / MASTG
AI/ML Security LLM and ML attack surfaces, OWASP LLM Top 10, OWASP ML Top 10
Active Directory & Windows Kerberos attacks, BloodHound analysis, Group Policy, PowerShell
Network & Wireless Infrastructure testing, WEP/WPA/WPA2/WPA3, KARMA attacks
Cloud Security Cloud configuration and workload assessment
Systems & Hardening Linux server hardening, Windows Server, Apache, Samba, SSH, IPTables
Secure Development Secure PHP development, secure WordPress administration, Python for security

Training Programs

Practical, lab-driven courses across the offensive security lifecycle.

Program Level
Certified Ethical Hacking & Penetration Testing Beginner
Python for Security Professionals Beginner
Linux Administration & Server Hardening Beginner
Enterprise Windows Infrastructure Security Beginner
Secure WordPress Administration Beginner
Secure PHP Development Beginner
API Security & Advanced API Exploitation Intermediate
Wireless Security & WiFi Penetration Testing Intermediate
Advanced Web Application Security Testing Advanced
Mobile Application Penetration Testing Advanced
Active Directory Security & Enterprise Attacks Advanced
AI/ML Penetration Testing Advanced

Tip

New to offensive security? Start with Certified Ethical Hacking & Penetration Testing and Linux Administration & Server Hardening, then progress into the advanced web, mobile, and Active Directory tracks.


Open Source

This organization hosts and curates repositories that support both our practice and our community. Repositories generally fall into these categories:

Category Description
🛠️ Security Tooling Utilities and scripts that support assessment workflows
🧪 Labs & Practice Targets Intentionally vulnerable environments for hands-on learning
📚 Learning Resources Notes, checklists, and study material for security topics
🤖 Automation Helpers for reconnaissance, reporting, and repetitive tasks
🧷 Hardening Guides Reference configurations for servers and infrastructure

Important

Browse the Repositories tab to see what is currently public. Each repository documents its own scope, usage, and status in its README.


Featured Technologies

Python Bash Linux Kali Linux PowerShell PHP WordPress Windows Server GraphQL Android


Security Standards & Methodologies

Our assessment and training work maps to recognized industry standards.

Category Standards & Frameworks
Web / API OWASP Top 10, OWASP API Security Top 10
Mobile OWASP MASVS, OWASP MASTG
AI / ML OWASP LLM Top 10, OWASP ML Top 10
Compliance & Governance ISO 27001, ISO 9001:2015, SOC 2, PCI DSS

Engineering Principles

  • Security by Design — Threat modeling and hardening from the start, not bolted on.
  • Exploitation-Validated — Findings are proven, not just flagged by a scanner.
  • Automation First — Repeatable workflows over manual repetition.
  • Documentation Driven — Clear, reproducible notes for every finding and lab.
  • Responsible Disclosure — Vulnerabilities are handled ethically and privately.
  • Continuous Improvement — Tradecraft evolves with the threat landscape.

Community

We welcome developers, students, researchers, and security engineers.

  • 🐛 Report an issue — Open an issue on the relevant repository.
  • 🔀 Submit a pull request — Fork, branch, and propose changes; follow each repo's contributing notes.
  • 💬 Start a discussion — Use a repository's Discussions or Issues to ask and share.
  • 🎓 Learn with us — Use our public labs and resources to build hands-on skills.

Warning

Please practice offensive techniques only against systems you own or are explicitly authorized to test. Report security vulnerabilities responsibly and privately rather than in public issues.


Resources

Resource Link
🌐 Website https://www.armourinfosec.com
📞 Contact https://www.armourinfosec.com/contact/
💼 LinkedIn https://www.linkedin.com/company/armourinfosec
🐦 X (Twitter) https://x.com/ArmourInfosec
▶️ YouTube https://www.youtube.com/c/TheHackersWorld
📘 Facebook https://www.facebook.com/armourinfosec
✉️ Email info@armourinfosec.com
📱 Phone +91 99777 47168
📍 Location 674, Sudama Dwar, Narendra Tiwari Marg, Sudama Nagar, Indore, Madhya Pradesh 452009, India

License

Each repository in this organization includes its own LICENSE file. Unless a repository states otherwise, refer to that file for the terms governing its use. If a repository has no license, all rights are reserved by default.


Built and maintained by Armour Infosec — offensive security, done responsibly.

Popular repositories Loading

  1. Enterprise-Windows-Infrastructure-Security Enterprise-Windows-Infrastructure-Security Public

    An Obsidian-based knowledge base for Windows Server administration and defensive hardening.

    43 24

  2. Linux-Administration-and-Server-Hardening Linux-Administration-and-Server-Hardening Public

    Lab-driven, dual-distro (CentOS Stream 10 / Debian 12) Linux Administration & Server Hardening course — 29 modules, 20 labs, 10 enterprise projects, RHCSA/LFCS-aligned.

    28 14

  3. Wireless-Security-and-WiFi-Penetration-Testing Wireless-Security-and-WiFi-Penetration-Testing Public

    Open, hands-on study notes on wireless security & Wi-Fi penetration testing (802.11, WEP/WPA/WPA2/WPA3, aircrack-ng). CC BY 4.0.

    17 8

  4. .github .github Public

    Armour Infosec organization profile

    3

Repositories

Showing 4 of 4 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…