Authorized security validation
Portable security tools for field operators.
SmokeMont creates native utilities for authorized teams: validate outbound paths with Egress, review endpoint appearance with Persona, collect incident material with Material, and plan macOS operator runbooks with Vector.
Products
Each SmokeMont app is a native tool with explicit operator action, clear evidence, and no service install workflow.
SmokeMont Egress
Egress validates what can leave a Windows endpoint through controlled, benign probes across common outbound paths.
Path validationRun DNS, HTTPS, WebSocket, UDP/443, HTTP/2 target, HTTP/3-style UDP/443, and SSH-over-443 checks.
Adapter controlUse automatic routing or bind checks to a specific IPv4 adapter for clearer path attribution.
Run evidenceCapture endpoint profile, target, adapter, status, timing, evidence tier, and exportable Markdown/PDF reports.
SmokeMont Material
Material helps responders gather host evidence quickly during authorized triage without installing an agent or changing endpoint configuration.
Local collectionGather system identity, adapters, DNS, gateways, TCP summary, running processes, startup entries, macOS launch items, security posture, and recent log or event signals.
Case contextAttach case name, analyst, location, notes, collection depth, timestamps, and a report identifier to each collection run.
Evidence reportsExport Markdown or print-friendly PDF reports with executive summaries, category sections, review counts, alert counts, and branding.
Material is observational software. It does not remediate, quarantine, terminate processes, delete files, or modify host configuration.
SmokeMont Persona
Persona helps operators answer a practical security question: from local configuration, traffic metadata, and public egress identity, what does this endpoint appear to be?
Profile scoringCompare observed endpoint traits against Corporate Windows Laptop, MacBook Business Person, Android Phone, iPad, and Thin Client profiles.
Posture reviewReview OS family, hostname context, adapters, private IPs, gateways, DNS servers, public IP, network owner, and approximate region.
Evidence reportsExport a PDF report with engagement metadata, fit score, latest-run comparison, generated profile traits, and safety boundaries.
Persona is observational software. It does not spoof, randomize, or mutate host settings; it provides a shared evidence trail for endpoint identity, exposure, and engagement reporting.
SmokeMont Vector
Vector helps authorized Mac operators turn scope, assumptions, validation steps, detection hypotheses, and stop conditions into a reusable runbook before activity begins.
Operator templatesStart from Mac control validation, purple-team tabletop, incident response prep, MDM/EDR readiness, or executive debrief planning templates.
Authorization contextDocument approver, window, engagement ID, stop contact, and communication channel alongside the plan.
Readiness trackingCalculate a readiness state from authorization coverage, included checklist items, status, and unresolved high-risk items.
Reusable projectsSave and reopen editable .smvec project files, then export final Markdown or print-friendly PDF runbooks.
Vector is planning software. It does not scan hosts, collect endpoint data, bypass controls, modify systems, or perform offensive actions.
SmokeMont Methodology
A publishable whitepaper for the SmokeMont operator workflow: plan with Vector, validate with Egress, observe with Persona, collect with Material, then review the evidence and feed lessons back into the next runbook.
PlanDefine authorization, scope, assumptions, expected signals, stop conditions, and readiness before action.
ValidateRun approved benign checks to document outbound network behavior from the endpoint.
ObserveReview endpoint appearance, local posture, and public egress context without mutating host settings.
CollectGather read-only incident-response material only when authorized triage requires local evidence.
Downloads
Current official SmokeMont builds are available below. Always run tools only on systems and networks where you have permission.
Capabilities
Across all SmokeMont tools, SmokeMont emphasizes controlled execution, field portability, and reporting that stands up in technical review.
Controlled Operation
Actions run only after explicit operator input, with visible scope and conservative collection behavior.
Evidence-Driven Output
Reports document selected modes, observed signals, result meaning, timestamps, and operator context.
Portable Deployment
Native Windows and macOS builds support field use on authorized systems without a service install or heavyweight runtime workflow.
Brand Integrity
Official SmokeMont releases use reserved branding so teams can distinguish maintained builds from modified internal versions.
License And Branding
SmokeMont code is licensed under the GNU AGPLv3. The SmokeMont name, logo, icon, and related branding are reserved so users can distinguish official releases from modified builds.