iqbal//soc

Projects

Tooling I have built for my own work. Two of these exist because the repetitive part of an investigation should not need a human.

Scope: these are personal research tools. They operate against sanctioned training platforms or explicitly authorised scopes only, and every engagement-producing agent enforces scope before it acts.

Security agents

ProjectWhat it is
phantom-htb Autonomous Hack The Box agent built on Claude Code. Recursive pentest loops: enumerate, hypothesise, exploit, record. A lab for testing how far an agent can get with a real methodology behind it.
redops Offensive security agent for Claude Code with multiple personas — methodology and reporting for authorised engagements.
specter Focused variant of the above, aimed at training-platform work and structured write-ups.

Tools

ProjectWhat it is
godmode · live Multi-model AI console in the browser: race the same prompt across models, compare outputs, bring your own API key. Client-side only — no keys touch a server of mine.

Why build these

Two reasons. First, the boring one: the enrichment, correlation and write-up steps that eat an analyst's shift are exactly the steps an agent should be doing, and the only way to know where that breaks is to build it and run it. Second, the useful one: an agent that produces a structured, evidence-labelled report from a lab target is a fast, cheap way to test whether my own triage logic is consistent when nobody is watching.

More on the detection side as rules get written — see notes.