Lost context
Operator decisions, intent, and pivots are rarely captured alongside tool output.
Capture every operator action, link every piece of evidence, and export every engagement as a portable, audit-ready archive — fully offline.
EngageSuite is an offline-first platform built for offensive security teams. From live field operations to long-term archive and analysis, every engagement becomes structured, searchable, and provable.
Not a notes tool. Not a SIEM. A system of record for how engagements actually happen.
$ initializesuite --module EngageLOG
[capture] operator actions: recorded
[evidence] traceability: linked
[mode] offline operation: required
[archive] export/import: building
[timeline] raw + normalized events: building
// If it is not in EngageLOG, it did not happen.
100%
Offline
LOG
Record
OSS
Driven
The Problem
Red team and penetration testing workflows are fragmented. Operators move between terminals, notes, screenshots, C2 tools, and shared drives. By the time reporting begins, the real story is already scattered.
Operator decisions, intent, and pivots are rarely captured alongside tool output.
Third-party verifiers need proof, but daily records are often incomplete or inconsistent.
Teams rebuild narratives manually from scattered artifacts after the work is done.
The Solution
EngageLOG captures activity as it happens — manual logs, imported tool output, evidence, and mission context — into a structured, searchable timeline. Every engagement becomes a complete record that can be exported, verified, and re-imported.
Capture
Record operator actions while the engagement is still happening.
Preserve
Keep original logs while normalizing events into a canonical timeline.
Prove
Link artifacts directly to activity so every claim has context.
Export
Package the complete engagement record for storage, import, and review.
Core Concept
EngageLOG creates a permanent, verifiable record of the engagement — every action, artifact, decision, operator, and target tied together in one operational timeline.
Commands
What was run
Actions
What happened
Artifacts
What proves it
Decisions
Why it mattered
Platform Architecture
EngageSuite is modular, but EngageLOG sits at the center: capturing the factual record that delivery, monitoring, and insight layers depend on.
Plan
Define scope, resources, and objectives
Deliver
Coordinate execution and track work
Log
Capture everything that actually happens
Monitor
Detect issues and surface signals
Insight
Learn from every engagement
What Is Coming
EngageSuite starts with EngageLOG: the offline-first operational system of record for offensive security engagements.
Manage missions, targets, operators, and engagement context in one place without depending on external systems.
Combine manual logs, imported tool output, operator attribution, targets, and evidence into a searchable timeline.
Hash, manage, and link artifacts directly to activity so every finding can be backed by verifiable context.
Import logs from tools like Sliver and normalize them into the engagement timeline without losing raw data.
Run fully disconnected in the field. No cloud dependency, no external SaaS requirement, no data loss.
Export complete engagement records, preserve raw and normalized data, and import into a central MASTER node later.
Before / After
The Product
EngageLOG captures manual logs, imported tool activity, evidence, and exports in one operational timeline. It works offline, preserves raw data, and creates audit-ready outputs by design.
Product Walkthrough
Every screen supports a real operational need: capture, verify, ingest, export, and preserve.
01
Mission awareness at a glance
Engagement leads get immediate visibility into active mission context, KPIs, evidence counts, exports, and quick actions.
02
The operational source of truth
A dense, paginated table view with UTC timestamps, source badges, operator attribution, targets, review state, and evidence references.
03
Fast logging for live operations
Manual log entry sits directly above the timeline, giving operators a fast capture workflow with immediate validation.
04
Integrity and traceability
Upload, hash, manage, and link evidence directly to engagement activity so every claim can be backed by a verifiable artifact.
05
C2 logs without losing raw data
Sliver starts as the MVP ingest source, with additional adapters planned using the same raw-plus-normalized event pipeline.
06
Daily verification and final archive
Generate daily CSV handoffs for third-party verification, then export the complete engagement record as a portable archive.
07
Phase 2 SMB indexing
Index existing engagement SMB shares without replacing operator workflows. Capture metadata, hashes, and links to activity.
Differentiation
EngageLOG is purpose-built for engagement operations, evidence traceability, and offline archive creation.
Open Source
EngageSuite is open-source and designed with real operator workflows in mind. Built by TForce Labs to support teams operating in the field and organizations that require audit-ready engagement records.
Join early access to follow development, test upcoming releases, and help shape the future of engagement operations.