- π€ Raunak Gupta a.k.a. B1scuit
- π Freelance Security Researcher & Bug Bounty Hunter
- π― Specializing in: Android β’ Web β’ API β’ Thick-Client Security
- π€ Also into: Open-Source β’ AI β’ LLMs
- π― Bug Bounty Hunter on HackerOne & YesWeHack - featured in 18+ Hall of Fames
- π οΈ Building open-source security tools for the community
- πΉ Running B1scuit Security on YouTube - hacking tutorials & writeups
- βοΈ Writing on Medium - bug bounty tips, resources & POCs
- π Udemy instructor with 8,400+ learners
- π¬ Running an active Discord community for security researchers
| # | Company | Severity | Vulnerability Type |
|---|---|---|---|
| 1 | Com Olho | Critical | RCE - platform program (post) - bounty redacted |
| 2 | Supabase | High | BAC and Insecure API (rate limiting and input flaws) |
| 3 | Zerodha | High | Android, Business Logic and Security Misconfigurations |
| 4 | Cert-wm.nl | High | Stored XSS via Unrestricted File Upload |
| 5 | Thinkst Canary | Medium | Mass PII Leak |
| 6 | Substack | Medium | Race Condition - Atomic Increment Manipulation |
| 7 | GeeksForGeeks | Medium | Mass Assignment Vulnerability |
| 8 | Wibmo.com | Medium | IDOR - Email Disclosure |
| 9 | EC-Council | Medium | Email Verification Bypass |
| 10 | Inflectra.com | Medium | Open Redirect and PII Leak via Input Validation Flaw |
| 11 | Skillmate.ai | Medium | Security Bypass and Insecure API |
| 12 | Samsung | Low | Misconfigured AWS S3 Bucket - Data Leak |
| 13 | Chess.com | Low | CWE-657: Insecure Design Violation |
| 14 | Arcjet.com | Low | CWE-657: Insecure Design Violation |
| 15 | CK Birla Hospital | Low | Security Bypass and Insecure API |
| 16 | Sir Ganga Ram Hospital | Low | Security Bypass and Insecure API |
| 17 | Max Healthcare | Low | Security Bypass and Insecure API |
| 18 | Brandmuscle | Low | Security Bypass and Insecure API |
| 19 | PayU | Acknowledged | Responsible Disclosure |
| 20 | NBC Bearings | Acknowledged | Responsible Disclosure |
| 21 | Yandex | Acknowledged | Bounty (post) |
| 22 | Private Program - First RCE this year | Acknowledged | RCE (post) |
| Project | Description | Stars |
|---|---|---|
| My CyberSecurity Store | Curated collection of infosec tools, resources & references | β |
| Bug Bounty GitBook | Playbook: tools, methodologies, writeups, labs & checklists | β |
| Learn Android Bug Bounty | Complete guide to Android application pentesting & bug bounty | β |
| Learn Beyond Web | Comprehensive guide to Thick-Client security testing | β |
| Elite Google Dorks Search | Smart Google dorks to surface hidden assets & information | β |
| Project | Description |
|---|---|
| APKDig | Deep APK analysis - extracts security-relevant info |
| analyze_manifest | AndroidManifest.xml analyzer - permissions, deep links, exported components |
| AndroidExportViewer | View & analyze exported Android components |
| DecompileAllAPK-s | Batch APK decompiler with analysis features |
| PullAPKFromPure | Extract APKs directly from Android devices |
| PullAllAPKs | Smart CLI to download APKs - wraps apkeep for mobile research |
| AndroBoomer | Automates APK analysis with parallel reverse-engineering tools |
| JAR-Reverse-Engineering-Tool | JAR reverse-engineering helper |
| Project | Description |
|---|---|
| Bruteforce JWT Secret | Brute-force weak JWT secrets to test auth |
| Elite Burp Suite Analyzer | Advanced HTTP history analyzer with enhanced filtering |
| GitHub Recon Tool | GitHub recon & repo analysis tool |
| Tor IP Changer | Auto-rotate IP via Tor network |
| CloneAllRepo | Clone all repos from a GitHub user/org |
| endpointer | Endpoint discovery helper |
| techdetect | Headless-browser tech detection (Wappalyzer-level) - CMS, JS, CDN, bulk JSONL |
| port-monitor | Local open-port inspector with WebUI - macOS/Linux/Windows |
| VirusTotal-Recoon | VT recon - domains, subdomains, IPs, URLs via VT API |
| vibe-coded-ssrf-tool | SSRF-prone endpoint finder + active payload matrix |
| Broken-Link-Hijacker-BB-Tools | Broken-link hijack detector |
| LinkFinder-Web-Version | LinkFinder as web UI - extract JS endpoints & links |
| Extension | Description |
|---|---|
| AutoTabSorter | Auto-organize Burp tabs for workflow efficiency |
| CVSS Calculator | Integrated CVSS scorer inside Burp Suite |
| Atlas-burpsuite-extension | Passive attack-surface mapper - live endpoint table |
| Extr-Real-time-HTTP-Logger | Real-time HTTP logger + JS link finder with tree-view |
| Terminal-In-Burpsuite | Operate terminal directly from Burp Suite |
| burp-suite-history-normalizer | Convert Burp history XML to AI-friendly JSON/JSONL/Markdown/HAR/cURL |
| Project | Description |
|---|---|
| mlx-servers | Bash supervisor for local MLX model servers on Apple Silicon |
| offline-ai-coding-with-pi-dev | Code fully offline with pi.dev - no cloud, no API keys |
| xcode-mcp-server | MCP server - control Xcode builds, sims, tests via AI |
| godot-mcp-server | MCP server for Godot 4.x game engine |
| ws-treasure-hunt | Intentionally vulnerable WebSocket multiplayer lab |
| Spam-Call-Loop-Trap | Self-hosted spam-call trap - FastAPI + React + Asterisk |
Public builds only (private repos and forks excluded). Full list verified via
gh repo list.
| Tool | What it does |
|---|---|
| LinkFinder-Web-Version | LinkFinder CLI as web UI - extract links, endpoints, JS resources |
| Elite-Google-Dorks-Search-by-Biscuit | Smart Google dorks to surface hidden assets & vulns |
| Bug-Bounty-GitBook | Bug bounty playbook - tools, methodology, labs, checklists |
| CustomPayloads-Wordlist.com | Custom fuzz payloads & wordlists - XSS, SQLi, SSRF, LFI, API |
| BurpsuiteCoolExtensions | Curated Burp Suite extensions collection |
| Tool | What it does |
|---|---|
| endpointer | Endpoint discovery helper |
| AutoTabSorter-BurpSuiteExtension | Auto-categorize Burp proxy history by keywords |
| PullAPKFromPure | Fast APK downloader for mobile research |
| Bruteforce-JWT-Secret | Brute-force JWT secrets with wordlist |
| AndroidExportViewer | List exported components + protection levels |
| DecompileAllAPK-s | Batch decompile multiple APKs |
| APKDig | Extract .env/.json/.db etc. from APKs for analysis |
| CloneAllRepo | Clone all public repos from a user/org (up to 500) |
| analyze_manifest | AndroidManifest analyzer - vulns, deeplinks, colorful output |
| Tor-IP-Changer-Script | Auto-rotate IP via Tor |
| CVSS-Calculator-BurpSuiteExtension | CVSS v3.1 scorer inside Burp |
| Elite-Burp-Suite-HTTP-History-Analyzer | Burp history XML β interactive D3.js graphs, 100% client-side |
| GitHub-Repository-Reconnaissance-Tool | Scan Git repos for secrets, deleted files, sensitive data |
| Broken-Link-Hijacker-BB-Tools | Broken-link hijack detector |
| Terminal-In-Burpsuite-BurpSuiteExtension | Terminal inside Burp Suite |
| PullAllAPKs | Smart APK downloader - simpler apkeep wrapper |
| AndroBoomer | Parallel APK reverse-engineering pipeline |
| VirusTotal-Recoon | VT recon - subdomains, IPs, URLs, threat hunt via VT API |
| Tool | What it does |
|---|---|
| ws-treasure-hunt | Vulnerable WebSocket multiplayer game for learning pentesting |
| Nmap-Visualizer-For-Noobs | Visualize Nmap output for beginners |
| RAG-Based-AI-Chatbot-for-Organization-API-Docs | Self-hosted RAG chatbot for API docs + Ollama local LLMs |
| godot-mcp-server | MCP server to control Godot 4.x from Claude/opencode/VS Code |
| xcode-mcp-server | MCP server - AI control for Xcode builds/sims/tests |
| JAR-Reverse-Engineering-Tool | JAR reverse-engineering helper |
| vibe-coded-ssrf-tool | Find SSRF-prone params + active payload testing |
| Extr-Real-time-HTTP-Logger | Burp real-time HTTP logger + JS link finder |
| Atlas-burpsuite-extension | Passive attack-surface mapper for Burp |
| Spam-Call-Loop-Trap | Dockerized spam-call IVR trap - FastAPI + React + Asterisk |
| pi-coding-agent-local-models | pi agent + local models - Ollama/LM Studio/MLX offline |
| offline-ai-coding-with-pi-dev | Fully offline coding with pi.dev, no API keys |
| mlx-servers | One-command MLX server supervisor - OOM guards, speculative decoding |
| burp-suite-history-normalizer | Burp XML β JSON/JSONL/Markdown/HAR/cURL, secret-redacted |
| mlx-Yue-studio | Local YuE2 song gen on Apple Silicon + WebUI |
| port-monitor | Open-port inspector with WebUI, zero deps |
| techdetect | Headless tech detection - CMS/JS/analytics/CDN, bulk JSONL (Sep 2026) |
| Thick-Client-Pentesting-On-MacOS | Thick-client on macOS - dylib hijack, XPC, app structure |
Note: Forked/maintained projects (not counted above): VoiceStudio (local ElevenLabs alt), Task-Ninja, BB-Tools forks (
bbot,SecretFinder,Subdominator,ShodanX, etc.), altdns, artemis, colibri.
- π From JS Recon to HTML Injection - JS recon uncovering HTML injection
- π Hacking Hospital: Mass PII Leak - Healthcare system vulnerability case study
- π The Thousand Dollar Bug - $1000+ bounty writeup via private YesWeHack program
- π 30 Must-Read Books to Learn Hacking - Curated reading list
- π 55 YouTube Channels to Learn Hacking - Best channels for bug bounty
Target Surfaces: Web Apps β’ REST/GraphQL APIs β’ Android Apps β’ iOS Apps β’ Thick-Client Apps Techniques: IDOR β’ BAC β’ Race Conditions β’ Mass Assignment β’ SQLi β’ XSS β’ JWT Attacks β’ SSL Pinning Bypass β’ Root Detection Bypass β’ Business Logic Flaws β’ AWS Misconfigurations
Udemy Instructor - Security Researcher and Bug Bounty Hunter
- π 8,400+ total learners
- π Active courses on cybersecurity, bug bounty & ethical hacking
- π Beginner-friendly content paired with real-world examples
YouTube Courses - B1scuit Security
- π₯ Web Bug Bounty Course - 30k+ views
- π₯ Android Bug Bounty Course - 20k+ views
- π₯ BurpSuite Course - 5k+ views





