◆ Free & open source · runs on your machine

You rooted the box.
Now get better at it.

owlsh records your run and grades it like a debrief — what you nailed, where you bled time, and the one thing to fix next box. On your machine, no account, no cloud.

Get it on GitHub
owlsh.app/report/abducted
Graded against MITRE ATT&CK® Unified Kill Chain CWE
Runs on Hack The Box TryHackMe OffSec Immersive
◆ How it works

Record. Grade. One lesson. It rides along the whole run, grades every move across three frameworks, and hands back the single highest-value fix, before your next box.

01Record

Your run, captured live. Every command, its output and the pauses in between, read as a kill chain while the box is still open. No eBPF, ptrace or kernel hooks.

owlsh.app / live ops

Nothing gets missed.

Every command, its output, and the gaps between, one continuous userspace capture.

No kernel hooks.

A userspace PTY, not eBPF or ptrace. The run never leaves your host.

02Grade

A score you can defend. Every move mapped to MITRE ATT&CK®, the Unified Kill Chain and CWE. They roll up into one rubric you can read line by line: coverage, breadth, efficiency, methodology, focus.

owlsh.app / the grade

Three frameworks, one map.

Every move mapped to MITRE ATT&CK, the Unified Kill Chain and CWE.

A number you can defend.

Weighted into an explainable rubric, coverage, breadth, efficiency, methodology, focus.

03Lesson

The one thing to fix next run. A deterministic diff against the optimal line your own findings unlocked. It shows where you were ahead, where you went off-path, and where you pivoted late, then boils it down to a single deep-linked lesson.

owlsh.app / the ghost

You vs. the optimal line.

A deterministic diff against the best path your own findings unlocked.

One deep-linked lesson.

Off-path wins, skips and late pivots, distilled to the single fix that matters.

owlsh — tmuxnew · live widget
~ $ owlsh --about

A coach beside your shell,
not a walkthrough.

Keep it in a pane next to your terminal. It mirrors your run as you work and remembers the threads you've left loose. It never hands you the next move.

[owlsh] 0:shell 1:widget*
# mirrors your run · phase, time, stealth and findings, as each command lands
# remembers your loose ends · an unused credential, a path you never revisited
# hints are opt-in, and they cost you · each pull lowers your independence score
# three sizes · small for a glance, medium for the run, large for finds and pace · [s] cycles
~ $ npm run widget -- --report session.json --size small
# in a terminal pane (over SSH or in Pwnbox), or as a floating always-on-top window in the desktop app
For the bench, and the people who run it

Built for operators.
Trusted by the CISO.

Operators get a debrief sharp enough to change the next run. Leadership gets an auditable measure of methodology that moves across the team. And no engagement data ever leaves the host.

A real run, replayed
Watch a real runHTB · Abducted

Your run, replayed

the one lesson
◆ Capture sources

A terminal is one way in. Not the only one.

Four ways in, one engine out. Drop a file or run the CLI — every run is tagged by source and graded against the same ladder, write-up or not.

TerminalPTY agentLive keystrokes. No eBPF, ptrace or kernel hooks.
Claude CodeAgent transcriptA run an agent drove — think-time and all.
HTTP proxyHAR importBurp, ZAP, mitmproxy or a browser export.
Sysmon · EDRHost telemetryGrade a run you only have logs for.
One engine The same debrief, tagged by source Graded against the same methodology ladder — ATT&CK, the kill chain and CWE — whether or not there's a write-up to diff against.
◆ The report · OSCP & CPTS

The debrief writes your report.

Every graded run becomes an OSCP/CPTS-style report: an executive summary a CISO can read, a severity-ranked findings table, then evidence and reproduction straight from your own log. Export it as Markdown or a client-ready PDF. Deterministic and offline.

01A summary the CISO can readOutcome, risk and the attack path in plain language, plus what was done phase by phase. No commands.
02Findings from your own evidenceA severity-ranked table, then each finding's evidence and reproduction pulled straight from the capture.
03Markdown or client-ready PDFPaste it into your exam template, or download a clean paper-styled PDF in one click.
04Deterministic and redaction-safeBuilds offline; credentials and flags are masked, and it warns before you share an unredacted draft.
$ npm run report→ report.md · PDF
Download a sample reportAbducted · HTB Medium · graded C · redacted PDF

Stop finishing boxes.
Start debriefing them.

Most tools confirm you rooted the box. owlsh tells you whether you were any good at it, and exactly what to fix next run. Deterministic, on your machine, yours alone.

Get it on GitHub
Runs on HTB · TryHackMe · OffSec · Immersive Labs · local CTF, no account, no telemetry, no cloud