Webapp Shortcuts
Alongside installed tools, Oniomarchy adds desktop-launcher shortcuts for security-relevant websites — the same idea as any other app launcher entry, just pointing at a URL instead of a binary. Each one maps to a tactic category, and together they cover every category from Information Gathering through Software Defined Radio.
| Site | Tactic | Notes |
|---|---|---|
| revshells.com | Exploitation Tools | Reverse shell one-liner generator — pairs with the built-in reverse shell listener |
| Shodan | Information Gathering | Internet-connected device search |
| Exploit-DB | Exploitation Tools | Exploit/PoC DB + Google Hacking Database |
| ATT&CK Navigator | Reporting Tools | MITRE ATT&CK tactic/technique matrix, for mapping findings |
| GTFOBins | Post Exploitation | Unix living-off-the-land binaries (privesc/restriction-bypass lookup) |
| LOLBAS | Post Exploitation | Windows living-off-the-land binaries |
| Censys | Information Gathering | Internet asset search |
| VirusTotal | Digital Forensics | File/URL/hash malware scanning |
| Have I Been Pwned | Information Gathering | Breach/credential exposure lookup |
| PimEyes | Information Gathering | Reverse face-search engine (OSINT) |
| SSL Labs | Web Application Analysis | TLS/certificate configuration scanner |
| urlscan.io | Information Gathering | Sandboxed URL/site scanner |
| WiGLE | Wireless Attacks | WiFi network geolocation database |
| any.run | Digital Forensics | Interactive malware sandbox |
| OSINT Framework | Information Gathering | Curated OSINT tool/link directory |
| CyberChef | Reverse Engineering | Data decode/encode/crypto “swiss army knife” |
| KiwiSDR Public Receivers | Software Defined Radio | Browse/tune public KiwiSDR web receivers worldwide |
| SIGIDWiki | Software Defined Radio | Signal Identification Guide — waveform/spectrogram database for identifying unknown RF signals |