Skip to content
View Raunaksplanet's full-sized avatar
🐒
Developing Security Tools in Large Ocean of Bug-Bounty
🐒
Developing Security Tools in Large Ocean of Bug-Bounty

Block or report Raunaksplanet

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Raunaksplanet/README.md

Typing SVG

Banner

LinkedIn X GitHub Medium YouTube YesWeHack HackerOne Discord Portfolio Udemy


🧠 About Me

  • πŸ‘€ Raunak Gupta a.k.a. B1scuit
  • πŸ” Freelance Security Researcher & Bug Bounty Hunter
  • 🎯 Specializing in: Android β€’ Web β€’ API β€’ Thick-Client Security
  • πŸ€– Also into: Open-Source β€’ AI β€’ LLMs
  • 🎯 Bug Bounty Hunter on HackerOne & YesWeHack - featured in 18+ Hall of Fames
  • πŸ› οΈ Building open-source security tools for the community
  • πŸ“Ή Running B1scuit Security on YouTube - hacking tutorials & writeups
  • ✍️ Writing on Medium - bug bounty tips, resources & POCs
  • πŸŽ“ Udemy instructor with 8,400+ learners
  • πŸ’¬ Running an active Discord community for security researchers

πŸ† HOF and Bounties

# Company Severity Vulnerability Type
1 Com Olho Critical RCE - platform program (post) - bounty redacted
2 Supabase High BAC and Insecure API (rate limiting and input flaws)
3 Zerodha High Android, Business Logic and Security Misconfigurations
4 Cert-wm.nl High Stored XSS via Unrestricted File Upload
5 Thinkst Canary Medium Mass PII Leak
6 Substack Medium Race Condition - Atomic Increment Manipulation
7 GeeksForGeeks Medium Mass Assignment Vulnerability
8 Wibmo.com Medium IDOR - Email Disclosure
9 EC-Council Medium Email Verification Bypass
10 Inflectra.com Medium Open Redirect and PII Leak via Input Validation Flaw
11 Skillmate.ai Medium Security Bypass and Insecure API
12 Samsung Low Misconfigured AWS S3 Bucket - Data Leak
13 Chess.com Low CWE-657: Insecure Design Violation
14 Arcjet.com Low CWE-657: Insecure Design Violation
15 CK Birla Hospital Low Security Bypass and Insecure API
16 Sir Ganga Ram Hospital Low Security Bypass and Insecure API
17 Max Healthcare Low Security Bypass and Insecure API
18 Brandmuscle Low Security Bypass and Insecure API
19 PayU Acknowledged Responsible Disclosure
20 NBC Bearings Acknowledged Responsible Disclosure
21 Yandex Acknowledged Bounty (post)
22 Private Program - First RCE this year Acknowledged RCE (post)

πŸš€ Featured Projects

πŸ“š Learning & Research

Project Description Stars
My CyberSecurity Store Curated collection of infosec tools, resources & references ⭐
Bug Bounty GitBook Playbook: tools, methodologies, writeups, labs & checklists ⭐
Learn Android Bug Bounty Complete guide to Android application pentesting & bug bounty ⭐
Learn Beyond Web Comprehensive guide to Thick-Client security testing ⭐
Elite Google Dorks Search Smart Google dorks to surface hidden assets & information ⭐

πŸ€– Android Security Tools

Project Description
APKDig Deep APK analysis - extracts security-relevant info
analyze_manifest AndroidManifest.xml analyzer - permissions, deep links, exported components
AndroidExportViewer View & analyze exported Android components
DecompileAllAPK-s Batch APK decompiler with analysis features
PullAPKFromPure Extract APKs directly from Android devices
PullAllAPKs Smart CLI to download APKs - wraps apkeep for mobile research
AndroBoomer Automates APK analysis with parallel reverse-engineering tools
JAR-Reverse-Engineering-Tool JAR reverse-engineering helper

🌐 Web Security Tools

Project Description
Bruteforce JWT Secret Brute-force weak JWT secrets to test auth
Elite Burp Suite Analyzer Advanced HTTP history analyzer with enhanced filtering
GitHub Recon Tool GitHub recon & repo analysis tool
Tor IP Changer Auto-rotate IP via Tor network
CloneAllRepo Clone all repos from a GitHub user/org
endpointer Endpoint discovery helper
techdetect Headless-browser tech detection (Wappalyzer-level) - CMS, JS, CDN, bulk JSONL
port-monitor Local open-port inspector with WebUI - macOS/Linux/Windows
VirusTotal-Recoon VT recon - domains, subdomains, IPs, URLs via VT API
vibe-coded-ssrf-tool SSRF-prone endpoint finder + active payload matrix
Broken-Link-Hijacker-BB-Tools Broken-link hijack detector
LinkFinder-Web-Version LinkFinder as web UI - extract JS endpoints & links

πŸ”§ Burp Suite Extensions

Extension Description
AutoTabSorter Auto-organize Burp tabs for workflow efficiency
CVSS Calculator Integrated CVSS scorer inside Burp Suite
Atlas-burpsuite-extension Passive attack-surface mapper - live endpoint table
Extr-Real-time-HTTP-Logger Real-time HTTP logger + JS link finder with tree-view
Terminal-In-Burpsuite Operate terminal directly from Burp Suite
burp-suite-history-normalizer Convert Burp history XML to AI-friendly JSON/JSONL/Markdown/HAR/cURL

πŸ€– Local AI, MCP & Labs

Project Description
mlx-servers Bash supervisor for local MLX model servers on Apple Silicon
offline-ai-coding-with-pi-dev Code fully offline with pi.dev - no cloud, no API keys
xcode-mcp-server MCP server - control Xcode builds, sims, tests via AI
godot-mcp-server MCP server for Godot 4.x game engine
ws-treasure-hunt Intentionally vulnerable WebSocket multiplayer lab
Spam-Call-Loop-Trap Self-hosted spam-call trap - FastAPI + React + Asterisk

🧰 Tools I Built - By Year

Public builds only (private repos and forks excluded). Full list verified via gh repo list.

2024 - Getting Started (5 builds)

Tool What it does
LinkFinder-Web-Version LinkFinder CLI as web UI - extract links, endpoints, JS resources
Elite-Google-Dorks-Search-by-Biscuit Smart Google dorks to surface hidden assets & vulns
Bug-Bounty-GitBook Bug bounty playbook - tools, methodology, labs, checklists
CustomPayloads-Wordlist.com Custom fuzz payloads & wordlists - XSS, SQLi, SSRF, LFI, API
BurpsuiteCoolExtensions Curated Burp Suite extensions collection

2025 - Bug Bounty Toolkit Era (18 builds)

Tool What it does
endpointer Endpoint discovery helper
AutoTabSorter-BurpSuiteExtension Auto-categorize Burp proxy history by keywords
PullAPKFromPure Fast APK downloader for mobile research
Bruteforce-JWT-Secret Brute-force JWT secrets with wordlist
AndroidExportViewer List exported components + protection levels
DecompileAllAPK-s Batch decompile multiple APKs
APKDig Extract .env/.json/.db etc. from APKs for analysis
CloneAllRepo Clone all public repos from a user/org (up to 500)
analyze_manifest AndroidManifest analyzer - vulns, deeplinks, colorful output
Tor-IP-Changer-Script Auto-rotate IP via Tor
CVSS-Calculator-BurpSuiteExtension CVSS v3.1 scorer inside Burp
Elite-Burp-Suite-HTTP-History-Analyzer Burp history XML β†’ interactive D3.js graphs, 100% client-side
GitHub-Repository-Reconnaissance-Tool Scan Git repos for secrets, deleted files, sensitive data
Broken-Link-Hijacker-BB-Tools Broken-link hijack detector
Terminal-In-Burpsuite-BurpSuiteExtension Terminal inside Burp Suite
PullAllAPKs Smart APK downloader - simpler apkeep wrapper
AndroBoomer Parallel APK reverse-engineering pipeline
VirusTotal-Recoon VT recon - subdomains, IPs, URLs, threat hunt via VT API

2026 - Local AI + Active Building (18 builds, last few months)

Tool What it does
ws-treasure-hunt Vulnerable WebSocket multiplayer game for learning pentesting
Nmap-Visualizer-For-Noobs Visualize Nmap output for beginners
RAG-Based-AI-Chatbot-for-Organization-API-Docs Self-hosted RAG chatbot for API docs + Ollama local LLMs
godot-mcp-server MCP server to control Godot 4.x from Claude/opencode/VS Code
xcode-mcp-server MCP server - AI control for Xcode builds/sims/tests
JAR-Reverse-Engineering-Tool JAR reverse-engineering helper
vibe-coded-ssrf-tool Find SSRF-prone params + active payload testing
Extr-Real-time-HTTP-Logger Burp real-time HTTP logger + JS link finder
Atlas-burpsuite-extension Passive attack-surface mapper for Burp
Spam-Call-Loop-Trap Dockerized spam-call IVR trap - FastAPI + React + Asterisk
pi-coding-agent-local-models pi agent + local models - Ollama/LM Studio/MLX offline
offline-ai-coding-with-pi-dev Fully offline coding with pi.dev, no API keys
mlx-servers One-command MLX server supervisor - OOM guards, speculative decoding
burp-suite-history-normalizer Burp XML β†’ JSON/JSONL/Markdown/HAR/cURL, secret-redacted
mlx-Yue-studio Local YuE2 song gen on Apple Silicon + WebUI
port-monitor Open-port inspector with WebUI, zero deps
techdetect Headless tech detection - CMS/JS/analytics/CDN, bulk JSONL (Sep 2026)
Thick-Client-Pentesting-On-MacOS Thick-client on macOS - dylib hijack, XPC, app structure

Note: Forked/maintained projects (not counted above): VoiceStudio (local ElevenLabs alt), Task-Ninja, BB-Tools forks (bbot, SecretFinder, Subdominator, ShodanX, etc.), altdns, artemis, colibri.


πŸ“ Recent Blogs & POCs


πŸ› οΈ Skills & Stack

Android Burp Suite Python Frida Linux API Security OWASP Git

Target Surfaces: Web Apps β€’ REST/GraphQL APIs β€’ Android Apps β€’ iOS Apps β€’ Thick-Client Apps Techniques: IDOR β€’ BAC β€’ Race Conditions β€’ Mass Assignment β€’ SQLi β€’ XSS β€’ JWT Attacks β€’ SSL Pinning Bypass β€’ Root Detection Bypass β€’ Business Logic Flaws β€’ AWS Misconfigurations


πŸ“Š GitHub Stats

GitHub Stats Top Languages

GitHub Streak


πŸŽ“ Teaching

Udemy Instructor - Security Researcher and Bug Bounty Hunter

  • πŸ“Œ 8,400+ total learners
  • πŸ“Œ Active courses on cybersecurity, bug bounty & ethical hacking
  • πŸ“Œ Beginner-friendly content paired with real-world examples

YouTube Courses - B1scuit Security


πŸ’¬ Let's Connect

Found a bug in my README? That's... ironic. Hit me up on Discord or Twitter.

⭐ If my tools or resources helped you - drop a star. It keeps the grind going.

Profile Views

Pinned Loading

  1. My-CyberSecurity-Store My-CyberSecurity-Store Public

    This repository contains a comprehensive collection of learning resources and notes that I've gathered on various topics, including cybersecurity, bug bounty, API security, cloud security, and more…

    Rust 812 229

  2. Elite-Google-Dorks-Search-by-Biscuit Elite-Google-Dorks-Search-by-Biscuit Public

    Discover hidden information on the web with "Elite Google Dorks Search by Biscuit." This collection offers smart and improved Google search queries to help you find data and vulnerabilities more ea…

    HTML 21 7

  3. Bug-Bounty-GitBook Bug-Bounty-GitBook Public

    Biscuit's Bug Bounty Playbook is a curated hub for cybersecurity learners and bug bounty hunters. It includes tools, methodologies, writeups, vulnerable labs, YouTube channels, checklists, and plat…

    22 10

  4. Learn-android-bug-bounty Learn-android-bug-bounty Public

    Documenting all the sources from where I'm learning Mobile(adnroid/IOS) bug bounty so if another researcher want to start with mobile bug bounty he/she don't struggle for resources

    Shell 67 17