About

Knowledge infrastructure for
ethical hackers.

Nimbus Vault makes sure you never lose track of what you have tested, what you have missed, or which technique applies to the target in front of you.

Origin

From scattered notes to structured intelligence.

Security knowledge management has stayed remarkably primitive. Most hunters still run on personal notes, bookmarked write-ups, and memory — while the tooling industry raced toward letting AI do the thinking for you. Nimbus Vault makes a different bet: deterministic, structured, human-authored knowledge that surfaces contextually, when and where you need it.

It starts with the CAVET taxonomy — five component types that describe both targets and techniques in the same language, making every match systematic instead of accidental.

This is the part most tools skip: CAVET does not just store notes — it breaks every target and every technique into the same five components (Technology, Functionality, Vector, Gadget, Quirk), so the Nexus Engine can match what you already know against what is in front of you, instead of you trying to remember it.

Methodology

Contextual Hacking.

A structured approach to active reconnaissance and vulnerability exploitation built on a core insight: every vulnerability depends on context. Rather than hunting for specific bugs, you map the target's architecture and let the viable attack paths emerge.

In practice, this means breaking a target down the same way CAVET breaks it down: what technologies is it running, what functionality is exposed, what input vectors exist, what gadgets are available to chain, and what quirks does this specific instance have. A vulnerability rarely comes from one of these alone.

TechnologyFrameworks, languages, platforms
FunctionalityFeatures like File Upload, OAuth
VectorInput vectors, entry points
GadgetPrimitives available to chain
QuirkObservable behaviours

This is the same reasoning Nimbus Vault encodes into playbooks: not "check for X vulnerability," but "here is the architecture, here is what applies to it."

Read the full methodology on Medium for the original write-up and worked examples.

Principles

How we build.

Augmentation, not automation.AI is trying to replace the hunter's judgment. Nimbus Vault is built to sharpen it instead.
Your methodology stays yours.Nimbus surfaces what applies. It does not tell you how to hunt.
Built from the field, not the whiteboard.Every design decision in CAVET and the Nexus Engine traces back to a real target, not a hypothetical one.

Credits

The team.

Raphael (entit_y)Founder, product & hunting designSelf-taught security researcher. Built the CAVET taxonomy out of his own bug bounty work and wrote Contextual Hacking.
G
Gideon (TheTobiGit)EngineerBuilds Nimbus Vault. Turns CAVET and the Nexus Engine from concept into working product.github.com/TheTobiGit

Want to know when we launch?