About
Knowledge infrastructure for
ethical hackers.
Nimbus Vault makes sure you never lose track of what you have tested, what you have missed, or which technique applies to the target in front of you.
Origin
From scattered notes to structured intelligence.
The problem was simple: every target had unique characteristics — technologies, functionalities, quirks — and there was no reliable way to track them. You could not know what you had tested, what you had missed, or whether a technique you learned months ago applied to the target in front of you.
Nimbus Vault was built to solve this. It started with the CAVET taxonomy — five component types that describe both targets and techniques in the same language, making every match systematic instead of accidental.
This is the part most tools skip: CAVET does not just store notes — it breaks every target and every technique into the same five components (Technology, Functionality, Vector, Gadget, Quirk), so the Nexus Engine can match what you already know against what is in front of you, instead of you trying to remember it.
Methodology
Contextual Hacking.
A structured approach to active reconnaissance and vulnerability exploitation built on a core insight: every vulnerability depends on context. Rather than hunting for specific bugs, you map the target's architecture and let the viable attack paths emerge.
In practice, this means breaking a target down the same way CAVET breaks it down: what technologies is it running, what functionality is exposed, what input vectors exist, what gadgets are available to chain, and what quirks does this specific instance have. A vulnerability rarely comes from one of these alone.
This is the same reasoning Nimbus Vault encodes into playbooks: not "check for X vulnerability," but "here is the architecture, here is what applies to it."
Read the full methodology on Medium for the original write-up and worked examples.
Principles
How we build.
Credits
The team.

Want to know when we launch?