/Rules of Engagement Builder
Create a bounded, safety-first pentest scope document locally before testing.
Local processing
This tool processes your input in your browser.
Command Palette
Search for a command to run...
Document
# Rules of Engagement Client: Client / Organization Testing window: 2026-09-01 22:00 — 2026-09-02 06:00 UTC Emergency contact: security@example.com ## In scope - example.com - 10.10.0.0/16 ## Out of scope - Production databases - Third-party SaaS ## Safety controls - Obtain written authorization before testing. - No denial-of-service, destructive, persistence or data exfiltration activity. - Stop immediately on service instability or sensitive-data exposure. - Record timestamps, source addresses, evidence and cleanup actions. - Report critical findings through the emergency contact.
Related Tools
HTTP Request Builder
Build, inspect, modify and export HTTP requests locally without sending them.
Payload Encoder
Encode and transform security testing payloads locally using a processing pipeline.
Web Payload Lab
Explore and transform common web security payloads in a local educational sandbox.
Reverse Shell Reference
Reference and study common shell techniques used in authorized security labs and CTFs.