Home About Articles Contact
systems nominal · node heric.bz
{ }

Projects & Tools

Code, research & tooling.

Most of my work ships as private engagement deliverables, but the public side lives here: open-source utilities, recon and reporting automation, and the video work where I break down how systems actually fail. The repositories and channel below are the canonical, always-current sources.

sources

Where the Work Lives

Read the research →
GIT

GitHub

Open-source tooling and experiments — recon helpers, automation scripts and the occasional proof of concept. The profile is kept current, so it is the authoritative list rather than a snapshot duplicated here.

github.com/itsmemonge →
VID

YouTube

Walkthroughs and explainers on offensive security, OSINT and digital investigation — the same techniques used in engagements, broken down so they are reproducible and easy to follow.

youtube.com/@MongeAI →
focus

What I Build

Full overview →
REC

Recon Automation

Scripts in Node.js and Python that collect, normalise and correlate open-source signals — turning scattered public data into structured leads for an investigation.

MON

Monitoring & Alerting

Lightweight watchers for exposed assets, leaked credentials and infrastructure changes, built to surface what matters without drowning a team in noise.

REP

Reporting Tooling

Utilities that take raw findings and produce clear, reproducible reports — consistent evidence, ranked impact and remediation that a developer can act on.

Engagement-specific tooling and exploit code are not published. Public releases are scoped to be safe and useful to other researchers and defenders. If something here is relevant to your work, reach out — I am happy to talk through how it is used.

next step

Need tooling, or a system tested?

Custom automation for recon and monitoring, a penetration test, or a digital investigation — tell me what you're working on and I'll tell you how I'd approach it.