Cognis Digital (Wyoming, USA) is a private engineering practice. We work quietly, by referral, on the hardest problems in security and autonomy — and we publish the tools that come out of that work as open source, so the operators and analysts who need them can self-host them, air-gapped, with no vendor in the loop.
We don't run ads and we don't cold-sell. The work is the marketing: single-purpose, self-hostable, MCP-native tools that reach where mainstream and SaaS security stop — firmware, ICS/OT, RF, C2, DFIR, OSINT, and compliance-as-code. Every tool ships a CLI, machine-readable JSON/SARIF output, and an MCP server so your agents can scan, audit, and remediate autonomously.
🇺🇸 USA-only, mission-first. We build on behalf of the American citizen — the defenders, the operators, and the small teams holding the line.
Firmware · ICS/OT · RF · C2 · DFIR · OSINT · compliance-as-code. Every tool is single-purpose, self-hostable, and emits machine-readable JSON/SARIF. Counts below are live from the GitHub API.
| Tool | What it does |
|---|---|
| c2detect ⭐33 | C2 server fingerprinter — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel |
| packpeek ⭐2 | Static packer/loader fingerprinter (C) — UPX/ASPack/Themida/MPRESS/VMProtect + entropy; emits YARA + SARIF. JSON out, CI-tested. |
| yararun ⭐1 | Run simple YARA-style string/regex rules over a directory |
| Tool | What it does |
|---|---|
| otaverify ⭐1 | Validate OTA update packages end-to-end: signature chains, rollback protection, anti-downgrade counters, and delta-patch integrity. |
| blescope ⭐1 | Sniff and decode BLE GATT traffic, fingerprint device profiles, and assert on insecure pairing/characteristics in CI against a capture. |
| keyhound ⭐1 | Scan firmware blobs and filesystem dumps for hardcoded private keys, API tokens, default creds, and weak RSA/ECC material. |
| modlure ⭐1 | Spin up a high-interaction Modbus/DNP3 ICS honeypot that logs attacker register reads/writes as structured JSON. |
| bootwarden ⭐1 | Audit UEFI firmware dumps for missing Secure Boot keys, unsigned modules, S3 boot-script vulns, and known SMM threats. |
| sbomb ⭐1 | Generate a CycloneDX SBOM directly from an unpacked firmware root filesystem and flag components with known CVEs and EOL kernels. |
| Tool | What it does |
|---|---|
| awesome-drone-warfare-osint ⭐3 | Citation-grade OSINT dataset: 8,300+ foreign components across 195+ drone & missile platforms, with cited effectiveness/EW/counter-UAS statistics. MIT (code) / CC BY 4.0 (data). |
| adsbwatch ⭐2 | Analyze an ADS-B feed/CSV for anomalies: callsign spoofing, squawk 7500/7600/7700, and unusual loiter patterns. |
| spoofwatch ⭐1 | Detect & map GPS/GNSS jamming & spoofing from ADS-B/AIS position feeds — zero-dependency, offline. Cognis Digital. |
| scryer ⭐1 | Multi-domain ISR sensor fusion for counternarcotics (non-kinetic) — EO/IR+radar+AIS+ADS-B track fusion, dark-contact cross-cue, coverage cost modeling, GeoJSON. Self-hosted, verified metrics. |
| frontline-drones ⭐1 | Descriptive, citation-grade catalog of frontline & commercial drones + the open autonomy ecosystem (PX4/ArduPilot/MAVLink) and NVIDIA's open Hugging Face robotics/perception models. MIT (code) / CC BY 4.0 (data). |
| Tool | What it does |
|---|---|
| cryptotrace ⭐2 | Free-tier blockchain investigator — ETH/BTC clustering + sanctions xref |
| maritimeint ⭐2 | AIS vessel tracking & sanctions-evasion anomaly detection |
| personagraph ⭐1 | Identity resolution dossier — username/email/phone cross-platform |
| Tool | What it does |
|---|---|
| comint-osquery ⭐2 | DISA STIG-aligned osquery configs + RMF mapper |
| compliance-atlas ⭐2 | Condensed, cross-walked reference for SOC2, ISO 27001, NIST CSF/800-53/800-171, CMMC, GDPR, CCPA, HIPAA, PCI DSS, EU AI Act |
| grcforge ⭐1 | GRC control crosswalk engine (NIST 800-53 / CIS / SOC 2) + gap analysis |
| oscalkit ⭐1 | OSCAL compliance-as-code — validate, convert & diff control coverage for catalogs, profiles, component definitions & SSPs |
| stigsentry ⭐1 | DISA STIG checker + NIST 800-53 RMF mapper + POAM emitter |
| deidproof ⭐1 | Re-identification risk assessment that computes k-anonymity, l-diversity, and HIPAA Safe Harbor compliance on a dataset. |
| Tool | What it does |
|---|---|
| rootsentry ⭐1 | Mobile runtime-integrity detection: root/jailbreak/emulator/hook/tamper indicators with a scored posture verdict (RASP-style, zero deps). |
| apkprobe ⭐1 | Android APK static security analyzer — MASTG-aligned, from-scratch binary-AXML decoder, zero dependencies. |
| Tool | What it does |
|---|---|
| codegraph-mcp ⭐7 | No-train, on-prem code knowledge graph served to AI agents over MCP, with a hash-chained audit row for every read. |
| uncensored-fleet ⭐2 | Deploy a local multi-model LLM fleet (llama.cpp) with an agent harness, hermes memory, and a one-command CLI |
| spendwatch ⭐1 | Multi-provider LLM usage, cost & rate-limit meter with budget guards — Anthropic/OpenAI/OpenRouter/local, TUI + MCP + CI exit codes. Zero-dependency. |
Our newest work, where the stars haven't caught up to the engineering yet. If one earns a place in your stack, a ⭐ tells us to push it further.
| Tool | What it does |
|---|---|
| repolens | Deterministic, token-budgeted, AST-aware repository context packs for LLM agents — with a hash-chained provenance row for every read. Zero-dependency CLI + MCP. |
| garrison | Self-hosted cyber-ops training range & curriculum — role tracks, offline auto-grading, readiness scoring. SDK + one-line install. Cognis Digital. |
| obol | A file-based, chain-agnostic payment protocol for autonomous agents. |
| hazardwatch | Self-updating public-safety hazard monitor — USGS quakes + NASA fires/storms + NWS alerts, one map. Keyless, offline, auto-refreshing. Cognis Digital. |
| spoofwatch ⭐1 | Detect & map GPS/GNSS jamming & spoofing from ADS-B/AIS position feeds — zero-dependency, offline. Cognis Digital. |
| plumewatch | Detect & track smoke plumes in satellite/aerial/photo imagery — classical CV, zero-dependency, offline. Cognis Digital. |
| taskloom | Deterministic, auditable multi-agent orchestration — register tools, run a fixed or rule-driven plan, get a fully-traced reproducible result. Zero deps, offline. |
| fixpoint | Empirically characterizing convergence of the AI code generate-verify-repair loop: converge / stall / oscillate / exhaust. Deterministic CI study + data-only 43-task benchmark. |
Renamed to single-word brands (old links now redirect here):
uefiscan→ bootwarden ·keyhunt→ keyhound ·modpot→ modlure — among others in the rebrand.
The tools live in the Cognis Neural Suite. Going from catalog to a running tool:
- Pick a tool — browse the full catalog or the featured tables above.
- Install it — most tools ship a CLI on PyPI under the
cognis-prefix (see the tool's README for its exact package name):pip install cognis-mcpharden
- Run it — machine-readable by default (JSON/SARIF):
mcpharden scan . --format sarif --out report.sarif - Point your agents at it — every tool ships an MCP server, so Claude Desktop / Cursor / Cognis.Studio can drive it autonomously (run the tool's
mcpcommand). - Automate in CI — gate builds on findings and upload SARIF to code scanning:
- run: pip install cognis-mcpharden - run: mcpharden scan . --format sarif --out report.sarif --fail-on high - uses: github/codeql-action/upload-sarif@v3 with: { sarif_file: report.sarif }
The suite got a major capability + quality pass — additive across the catalog:
- Real intelligence feeds, edge/air-gap ready — 35 keyless sources (CISA KEV, EPSS, OSV, NVD, MITRE ATT&CK STIX, NIST OSCAL 800-53, abuse.ch C2/IOC, OFAC, GDELT, OpenSky, USGS, Wikimedia) wired into the tools via a stdlib fetch→cache→offline→snapshot module.
- 262,351-vulnerability offline DB bundled into the vulnerability scanners — real OSV records (CVE/GHSA aliases, CVSS, affected packages) queryable with zero network.
- Standards exports everywhere — SARIF (code-scanning), STIX 2.1, OSCAL, Sigma + Suricata, GeoJSON/KML, CSV across the suite.
- Deeper detection — C2 campaign correlation, MCP fleet-posture + supply-chain (OWASP Agentic Top-10 2026), maritime track-interaction (CPA/TCPA), and more — each with expanded test suites and candid docs.
- Passive + authorization-gated active scanning and polyglot ports rolling out across the scanners.
Every tool stays single-purpose, self-hostable, MCP-native, and defensively-scoped.
Polyglot by design. The suite is Python-first but ports outward so a tool exists in the language of your deployment target — mainframe to mobile, kernel to contract. ● live in-repo today, ○ rolling out.
📱 Mobile — languages & frameworks
⛓️ Smart-contract / Web3 — across EVM · Base · Arbitrum · Blast · Polygon · Solana · Algorand · XRPL · TON · Aptos · Sui · Starknet
Every port keeps the suite contract: a CLI, structured output (JSON/SARIF), and an MCP server.
Led by Christopher Hyatt — Software & AI Engineer, founder of Cognis Digital, smart-contract auditor (Entersoft, intern→lead), and federal cybersecurity SME. 🛰️ Hack-A-Sat 7th worldwide / 3,600+ teams · Top 1% TryHackMe · Eagle Scout · CompTIA Security+ · CISSP Prep · AWS DevOps.
Languages · Python · TypeScript/JavaScript · Solidity · Rust · Go · Move · Cairo · Vyper · SQL · Bash AI / Agents · self-hosted LLMs · RAG · evals & guardrails · MCP · Claude Agent SDK · LangGraph · CrewAI · AutoGen · LangChain · LlamaIndex · Ollama · vLLM · llama.cpp Security & Web3 · smart-contract audit · formal verification · pentesting · Foundry · Slither · Echidna · Mythril · Burp Suite · Nmap · Kali · SIEM/Splunk · NIST 800-53 · MITRE ATT&CK Intelligence · OSINT · SIGINT · GEOINT · HUMINT · ADINT | PQC · post-quantum crypto
Engagements are private and by referral. Development partnerships via DevPairer.
⭐ Star the tools you use — it's the signal that tells us which frontier work to push further · 🛠️ Contribute under the collaboration-pull model (see any repo's CONTRIBUTING.md) · 🏢 Commercial use → licensing@cognis.digital
cognis-digital composes across the Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
Forward findings to STIX/MISP/Sigma/Splunk/Elastic/Slack/webhooks via
cognis-connect. See INTEGRATIONS.md.
Featured tables, star counts, and headline numbers on this page are regenerated from the GitHub API daily by scripts/update_profile.py — so they never drift from reality.



