Skip to content
View cognis-digital's full-sized avatar

Block or report cognis-digital

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cognis-digital/README.md

A private engineering practice — innovating on behalf of the American citizen

397 self-hostable, MCP-native tools · 87 stars · flagship c2detect (⭐33)

👋 Who we are

Cognis Digital (Wyoming, USA) is a private engineering practice. We work quietly, by referral, on the hardest problems in security and autonomy — and we publish the tools that come out of that work as open source, so the operators and analysts who need them can self-host them, air-gapped, with no vendor in the loop.

We don't run ads and we don't cold-sell. The work is the marketing: single-purpose, self-hostable, MCP-native tools that reach where mainstream and SaaS security stop — firmware, ICS/OT, RF, C2, DFIR, OSINT, and compliance-as-code. Every tool ships a CLI, machine-readable JSON/SARIF output, and an MCP server so your agents can scan, audit, and remediate autonomously.

🇺🇸 USA-only, mission-first. We build on behalf of the American citizen — the defenders, the operators, and the small teams holding the line.

⚡ Start here — hard-target tools that reach where SaaS doesn't

Firmware · ICS/OT · RF · C2 · DFIR · OSINT · compliance-as-code. Every tool is single-purpose, self-hostable, and emits machine-readable JSON/SARIF. Counts below are live from the GitHub API.

🔴 Threat detection, C2 & DFIR

Tool What it does
c2detect ⭐33 C2 server fingerprinter — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel
packpeek ⭐2 Static packer/loader fingerprinter (C) — UPX/ASPack/Themida/MPRESS/VMProtect + entropy; emits YARA + SARIF. JSON out, CI-tested.
yararun ⭐1 Run simple YARA-style string/regex rules over a directory

🔧 Firmware · hardware · ICS/OT · RF

Tool What it does
otaverify ⭐1 Validate OTA update packages end-to-end: signature chains, rollback protection, anti-downgrade counters, and delta-patch integrity.
blescope ⭐1 Sniff and decode BLE GATT traffic, fingerprint device profiles, and assert on insecure pairing/characteristics in CI against a capture.
keyhound ⭐1 Scan firmware blobs and filesystem dumps for hardcoded private keys, API tokens, default creds, and weak RSA/ECC material.
modlure ⭐1 Spin up a high-interaction Modbus/DNP3 ICS honeypot that logs attacker register reads/writes as structured JSON.
bootwarden ⭐1 Audit UEFI firmware dumps for missing Secure Boot keys, unsigned modules, S3 boot-script vulns, and known SMM threats.
sbomb ⭐1 Generate a CycloneDX SBOM directly from an unpacked firmware root filesystem and flag components with known CVEs and EOL kernels.

🪖 Defense · national security · geoint

Tool What it does
awesome-drone-warfare-osint ⭐3 Citation-grade OSINT dataset: 8,300+ foreign components across 195+ drone & missile platforms, with cited effectiveness/EW/counter-UAS statistics. MIT (code) / CC BY 4.0 (data).
adsbwatch ⭐2 Analyze an ADS-B feed/CSV for anomalies: callsign spoofing, squawk 7500/7600/7700, and unusual loiter patterns.
spoofwatch ⭐1 Detect & map GPS/GNSS jamming & spoofing from ADS-B/AIS position feeds — zero-dependency, offline. Cognis Digital.
scryer ⭐1 Multi-domain ISR sensor fusion for counternarcotics (non-kinetic) — EO/IR+radar+AIS+ADS-B track fusion, dark-contact cross-cue, coverage cost modeling, GeoJSON. Self-hosted, verified metrics.
frontline-drones ⭐1 Descriptive, citation-grade catalog of frontline & commercial drones + the open autonomy ecosystem (PX4/ArduPilot/MAVLink) and NVIDIA's open Hugging Face robotics/perception models. MIT (code) / CC BY 4.0 (data).

🛰️ OSINT & all-source intelligence

Tool What it does
cryptotrace ⭐2 Free-tier blockchain investigator — ETH/BTC clustering + sanctions xref
maritimeint ⭐2 AIS vessel tracking & sanctions-evasion anomaly detection
personagraph ⭐1 Identity resolution dossier — username/email/phone cross-platform

📋 Compliance-as-code & GRC

Tool What it does
comint-osquery ⭐2 DISA STIG-aligned osquery configs + RMF mapper
compliance-atlas ⭐2 Condensed, cross-walked reference for SOC2, ISO 27001, NIST CSF/800-53/800-171, CMMC, GDPR, CCPA, HIPAA, PCI DSS, EU AI Act
grcforge ⭐1 GRC control crosswalk engine (NIST 800-53 / CIS / SOC 2) + gap analysis
oscalkit ⭐1 OSCAL compliance-as-code — validate, convert & diff control coverage for catalogs, profiles, component definitions & SSPs
stigsentry ⭐1 DISA STIG checker + NIST 800-53 RMF mapper + POAM emitter
deidproof ⭐1 Re-identification risk assessment that computes k-anonymity, l-diversity, and HIPAA Safe Harbor compliance on a dataset.

📱 Mobile & application security

Tool What it does
rootsentry ⭐1 Mobile runtime-integrity detection: root/jailbreak/emulator/hook/tamper indicators with a scored posture verdict (RASP-style, zero deps).
apkprobe ⭐1 Android APK static security analyzer — MASTG-aligned, from-scratch binary-AXML decoder, zero dependencies.

🤖 Agent, MCP & AI security

Tool What it does
codegraph-mcp ⭐7 No-train, on-prem code knowledge graph served to AI agents over MCP, with a hash-chained audit row for every read.
uncensored-fleet ⭐2 Deploy a local multi-model LLM fleet (llama.cpp) with an agent harness, hermes memory, and a one-command CLI
spendwatch ⭐1 Multi-provider LLM usage, cost & rate-limit meter with budget guards — Anthropic/OpenAI/OpenRouter/local, TUI + MCP + CI exit codes. Zero-dependency.

🌱 Frontier — newly shipped, help them grow

Our newest work, where the stars haven't caught up to the engineering yet. If one earns a place in your stack, a ⭐ tells us to push it further.

Tool What it does
repolens Deterministic, token-budgeted, AST-aware repository context packs for LLM agents — with a hash-chained provenance row for every read. Zero-dependency CLI + MCP.
garrison Self-hosted cyber-ops training range & curriculum — role tracks, offline auto-grading, readiness scoring. SDK + one-line install. Cognis Digital.
obol A file-based, chain-agnostic payment protocol for autonomous agents.
hazardwatch Self-updating public-safety hazard monitor — USGS quakes + NASA fires/storms + NWS alerts, one map. Keyless, offline, auto-refreshing. Cognis Digital.
spoofwatch ⭐1 Detect & map GPS/GNSS jamming & spoofing from ADS-B/AIS position feeds — zero-dependency, offline. Cognis Digital.
plumewatch Detect & track smoke plumes in satellite/aerial/photo imagery — classical CV, zero-dependency, offline. Cognis Digital.
taskloom Deterministic, auditable multi-agent orchestration — register tools, run a fixed or rule-driven plan, get a fully-traced reproducible result. Zero deps, offline.
fixpoint Empirically characterizing convergence of the AI code generate-verify-repair loop: converge / stall / oscillate / exhaust. Deterministic CI study + data-only 43-task benchmark.

Renamed to single-word brands (old links now redirect here): uefiscanbootwarden · keyhuntkeyhound · modpotmodlure — among others in the rebrand.

⚙️ Usage — catalog to running tool

The tools live in the Cognis Neural Suite. Going from catalog to a running tool:

  1. Pick a tool — browse the full catalog or the featured tables above.
  2. Install it — most tools ship a CLI on PyPI under the cognis- prefix (see the tool's README for its exact package name):
    pip install cognis-mcpharden
  3. Run it — machine-readable by default (JSON/SARIF):
    mcpharden scan . --format sarif --out report.sarif
  4. Point your agents at it — every tool ships an MCP server, so Claude Desktop / Cursor / Cognis.Studio can drive it autonomously (run the tool's mcp command).
  5. Automate in CI — gate builds on findings and upload SARIF to code scanning:
    - run: pip install cognis-mcpharden
    - run: mcpharden scan . --format sarif --out report.sarif --fail-on high
    - uses: github/codeql-action/upload-sarif@v3
      with: { sarif_file: report.sarif }

⚡ Recent upgrades

The suite got a major capability + quality pass — additive across the catalog:

  • Real intelligence feeds, edge/air-gap ready — 35 keyless sources (CISA KEV, EPSS, OSV, NVD, MITRE ATT&CK STIX, NIST OSCAL 800-53, abuse.ch C2/IOC, OFAC, GDELT, OpenSky, USGS, Wikimedia) wired into the tools via a stdlib fetch→cache→offline→snapshot module.
  • 262,351-vulnerability offline DB bundled into the vulnerability scanners — real OSV records (CVE/GHSA aliases, CVSS, affected packages) queryable with zero network.
  • Standards exports everywhere — SARIF (code-scanning), STIX 2.1, OSCAL, Sigma + Suricata, GeoJSON/KML, CSV across the suite.
  • Deeper detection — C2 campaign correlation, MCP fleet-posture + supply-chain (OWASP Agentic Top-10 2026), maritime track-interaction (CPA/TCPA), and more — each with expanded test suites and candid docs.
  • Passive + authorization-gated active scanning and polyglot ports rolling out across the scanners.

Every tool stays single-purpose, self-hostable, MCP-native, and defensively-scoped.

🌐 Languages across the suite

Polyglot by design. The suite is Python-first but ports outward so a tool exists in the language of your deployment target — mainframe to mobile, kernel to contract. ● live in-repo today, ○ rolling out.

● Shipping now Python TypeScript JavaScript Go Rust C%23 Ruby Lua C COBOL Perl Shell PowerShell

📱 Mobile — languages & frameworks Swift Kotlin Java Objective-C Dart Flutter React Native

⛓️ Smart-contract / Web3 — across EVM · Base · Arbitrum · Blast · Polygon · Solana · Algorand · XRPL · TON · Aptos · Sui · Starknet Solidity Vyper Move Cairo Rust Clarity

Every port keeps the suite contract: a CLI, structured output (JSON/SARIF), and an MCP server.

👤 Founder & engineering stack

Led by Christopher Hyatt — Software & AI Engineer, founder of Cognis Digital, smart-contract auditor (Entersoft, intern→lead), and federal cybersecurity SME. 🛰️ Hack-A-Sat 7th worldwide / 3,600+ teams · Top 1% TryHackMe · Eagle Scout · CompTIA Security+ · CISSP Prep · AWS DevOps.

Languages · Python · TypeScript/JavaScript · Solidity · Rust · Go · Move · Cairo · Vyper · SQL · Bash AI / Agents · self-hosted LLMs · RAG · evals & guardrails · MCP · Claude Agent SDK · LangGraph · CrewAI · AutoGen · LangChain · LlamaIndex · Ollama · vLLM · llama.cpp Security & Web3 · smart-contract audit · formal verification · pentesting · Foundry · Slither · Echidna · Mythril · Burp Suite · Nmap · Kali · SIEM/Splunk · NIST 800-53 · MITRE ATT&CK Intelligence · OSINT · SIGINT · GEOINT · HUMINT · ADINT  |  PQC · post-quantum crypto

Engagements are private and by referral. Development partnerships via DevPairer.

🤝 Get involved

Star the tools you use — it's the signal that tells us which frontier work to push further · 🛠️ Contribute under the collaboration-pull model (see any repo's CONTRIBUTING.md) · 🏢 Commercial use → licensing@cognis.digital

Interoperability

cognis-digital composes across the Cognis suite — JSON in/out and a shared OpenAI-compatible /v1 backbone. See INTEROP.md for the suite map, composition patterns, and reference stacks.

Integrations

Forward findings to STIX/MISP/Sigma/Splunk/Elastic/Slack/webhooks via cognis-connect. See INTEGRATIONS.md.

Featured tables, star counts, and headline numbers on this page are regenerated from the GitHub API daily by scripts/update_profile.py — so they never drift from reality.

Pinned Loading

  1. deepcheck deepcheck Public

    Lightweight synthetic-media detector with C2PA validation

    Python

  2. fedramplens fedramplens Public

    FedRAMP boundary visualizer & OSCAL-format SSP/POAM generator

    Python 1

  3. geolens geolens Public

    Image geolocation toolkit — EXIF, sun-shadow, OCR, reverse-search

    Python

  4. ossaudit ossaudit Public

    OSS license compliance auditor — AGPL contamination + NOTICE generation

    Python

  5. privacyshell privacyshell Public

    Hardened browser profile generator — Firefox / LibreWolf / Brave

    Python

  6. ragshield ragshield Public

    RAG corpus poisoning detector — embedding anomalies, backdoor triggers

    Python