◆ The Watcher grades every offensive run

Turn every box into measurable skill.

A local-first flight recorder for offensive-security practice. It records the engagement and grades it like a debrief — across MITRE ATT&CK, the Unified Kill Chain, and CWE. Not just did they root it, but how well, and what to fix next run.

Get it on GitHub
the-watcher.app/report/abducted
Graded against MITRE ATT&CK® Unified Kill Chain CWE
Runs on Hack The Box TryHackMe OffSec Immersive
◆ How it works

Record. Grade. One lesson. It rides along the whole run, grades every move across three frameworks, and hands back the single highest-value fix — before your next box.

Your run, captured — live. Every command, its output and the gaps between them, read as a kill chain while the box is still open. No eBPF, ptrace, or kernel hooks.

the-watcher.app / live ops

Nothing gets missed.

Every command, its output, and the gaps between — one continuous userspace capture.

No kernel hooks.

A userspace PTY — not eBPF or ptrace. The run never leaves your host.

A score you can defend. Every move mapped to MITRE ATT&CK®, the Unified Kill Chain and CWE, then weighted into one explainable rubric — coverage, breadth, efficiency, methodology and focus.

the-watcher.app / the grade

Three frameworks, one map.

Every move mapped to MITRE ATT&CK, the Unified Kill Chain and CWE.

A number you can defend.

Weighted into an explainable rubric — coverage, breadth, efficiency, methodology, focus.

The one thing to fix next run. A deterministic diff against the optimal line your own findings unlocked — where you were ahead, off-path, or pivoted late — distilled to a single deep-linked lesson.

the-watcher.app / the ghost

You vs. the optimal line.

A deterministic diff against the best path your own findings unlocked.

One deep-linked lesson.

Off-path wins, skips and late pivots — distilled to the single fix that matters.

Watch yourself get better. Every graded run stacks into one longitudinal view — grade, coverage and methodology trending across boxes, not a single debrief you forget by next week.

the-watcher.app / progress

Grade over time.

Every graded run stacks into one longitudinal trend, box by box.

Every run, kept.

A graded history you can reopen and compare — a number that moves, not "I did a box."

Replay the whole run. Scrub the entire engagement on a DVR synced to the timeline — every command, its output and the tools you leaned on, exactly as it happened.

the-watcher.app / replay

Scrub the whole run.

A DVR synced to the timeline — jump to any command and watch it unfold.

Every tool, counted.

The loadout you reached for, and how often — nothing paraphrased.

◆ Features

Everything it covers.

One local pass over the whole engagement — captured, graded across three frameworks, and handed back as coaching. No account, no telemetry, no cloud.

Capture

Userspace PTY recorder

Every command, its output and the gaps between them — no eBPF, ptrace, or kernel hooks.

Live

Live Ops, mid-run

Kill-chain progression, a stealth-burn meter and a next-move nudge while the box is still open.

Frameworks

ATT&CK · UKC · CWE

Every move mapped to MITRE ATT&CK®, the Unified Kill Chain and CWE on one timeline.

Grade

An explainable rubric

Coverage, technique breadth, efficiency, methodology and focus — every number weighted and defensible.

OpSec

Stealth scoring

How loud each tool is versus the lab baseline, and the single loudest moment of the run.

Ghost

You vs. the optimal line

A deterministic diff against the line your own findings unlocked — ahead, off-path win, or late pivot, step by step. With no write-up, it still flags the openings your run proves it missed.

Privesc

Attack-path engine

Reads the enumeration and flags the faster root you walked past — a confirmed path, no write-up required.

Coaching

Lighthouse phase audit

A score per MITRE phase with the objectives reached and the highest-impact next moves.

Payoff

The one lesson

The single highest-value fix for next run — deep-linked to the exact step where it mattered.

For the bench, and the people who run it

Built for operators.
Trusted by the CISO.

Operators get a debrief sharp enough to change the next run. Leadership gets an auditable measure of methodology that moves across the team — and the assurance that no engagement data ever leaves the host.

A real run, replayed
Watch a real runHTB · Abducted

Your run, replayed

the one lesson
◆ The Ghost

You vs. the line you should have taken.

A deterministic diff between what you did and the optimal line your own findings unlocked at each step — where you moved ahead, went off-script and won, or sat on an opening and pivoted too late.

4×beat the line
8mlost to one pivot
0write-ups needed
No write-up? It still runs

The openings your own run proves you missed.

With no intended path to diff against, the Ghost falls back to what the run itself can prove — never a guess.

loot · unused

Found, never used.

A credential surfaced in the loot, and no later step ever tried to authenticate with it.

surfaced → never used
access · unchecked

Opened, never checked.

An anonymous listing succeeded, and the run moved on without auditing what it exposed.

listing ok → never audited
path · slow line

A faster way was there.

A confirmed shorter path to root was observable before the longer route was finished.

confirmed → slower route taken
◆ What you'd do differently

The one thing to fix next run.

Every debrief ends on one lesson, not a recap. Everything the run turned up gets ranked, and only the highest-value change comes back — deep-linked to the exact step.

The one lesson

The way to root opened at step 11. You took it at step 16.

A five-step late pivot — eight minutes the optimal line never spent. When a new privilege shows up, test it before you keep enumerating.
▸ Replay step 168 min backGhost · late pivot
◆ The report · OSCP & CPTS

The debrief writes your report.

One command turns a graded run into an OSCP/CPTS-style report draft — every finding with its severity, evidence, reproduction and remediation, built from the run's own record. Deterministic and offline; a local model only sharpens the wording, never the facts.

01Findings from your own evidenceCVEs, privilege-escalation paths and weakness classes the run actually exploited — never invented.
02Reproduction from the real logEvery finding's steps are the exact commands you ran, pulled straight from the capture.
03Deterministic, model optionalThe whole draft builds offline; a local model only polishes the prose, never the facts.
04Redaction-safe by defaultCredentials and flags are masked, and the header warns before you share an unredacted draft.
$ npm run report→ report.md

Stop finishing boxes.
Start debriefing them.

Most tools confirm you rooted the box. The Watcher tells you whether you were any good at it — and exactly what to fix next run. Deterministic, on your machine, yours alone.

Runs on HTB · TryHackMe · OffSec · Immersive Labs · local CTF — no account, no telemetry, no cloud